Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2025-71426
Contrast's unauthenticated recovery allows Coordinator impersonation
CVE-2025-71423
Contrast leaks workload secrets to logs on INFO level
CVE-2025-71425
Contrast workload secrets leak to logs on INFO level
CVE-2026-100838
Contras Affected by CopyFile Policy Subversion via Symlinks
CVE-2026-100839
Contrast BadAML injection allows arbitrary code execution
CVE-2026-100368
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers
CVE-2026-100369
CliInvoke: Argument Injection in Extensibility Runner Factory
CVE-2026-57303
Jenkins Assembla Plugin has an XXE vulnerability
CVE-2026-85396
rubyzip path traversal vulnerability
CVE-2026-57301
Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE
CVE-2026-57296
Jenkins External Workspace Manager Plugin has a path traversal vulnerability
CVE-2026-57281
Jenkins Script Security Plugin has a script security bypass vulnerability
CVE-2026-57280
Jenkins Script Security Plugin sandbox bypass vulnerability
CVE-2026-65838
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
CVE-2026-84195
Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak)
CVE-2026-84196
Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF
CVE-2026-57231
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
CVE-2026-41862
Spring Statemachine's Kryo-based persistence backends deserialize persisted state-machine contexts without enforcing a class allowlist
GHSA-vjr9-f93j-mjr7
Duplicate Advisory: OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
CVE-2026-85057
ZITADEL: Actions V1 sandbox escape: host file read via require()
CVE-2026-85056
ZITADEL: MFA bypass via session reuse in Login V2
CVE-2026-58314
Gitea: Two SSRF findings
CVE-2026-34966
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2025-14813
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks
CVE-2026-54148
http4k: `DigestAuthProvider.verify` did not bind to request URI
CVE-2026-61814
Jawn: Quadratic parsing effort in AsyncParser
CVE-2026-59990
Jawn: Uncontrolled nesting depth in JSON parser
CVE-2026-86065
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)
CVE-2026-86064
Klever-Go: /log controls global node logging
CVE-2026-77601
OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting
CVE-2026-77422
JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping
GHSA-x36p-c636-788x
Duplicate Advisory: Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
GHSA-q8qp-8jq6-78mc
Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
GHSA-mg57-j93w-g3c7
Duplicate Advisory: Picklescan has a missing detection when calling built-in python profile.Profile.runctx
GHSA-gq8p-2329-gh3x
Duplicate Advisory: Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
CVE-2025-71365
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
CVE-2025-71370
Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
CVE-2025-71341
Picklescan has a missing detection when calling built-in python profile.Profile.runctx
CVE-2025-71376
Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
CVE-2026-67325
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
CVE-2026-78675
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
CVE-2026-77633
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service
CVE-2026-77262
MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)
CVE-2026-85740
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
CVE-2026-76819
Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability
CVE-2026-77246
MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path
CVE-2026-77253
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files
CVE-2026-62182
KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes
CVE-2026-61570
MPXJ: XXE Vulnerability in MerlinReader
CVE-2026-62369
KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join
CVE-2026-77243
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass
CVE-2026-77258
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()
CVE-2026-62371
KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API
CVE-2026-77560
Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for
CVE-2026-77255
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue
CVE-2026-94462
Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)
CVE-2026-77259
MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials
CVE-2026-77248
MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport
CVE-2026-77261
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches
CVE-2026-77322
SIPGO: DoS via unvalidated WebSocket frame length
Ready to move
Start Securing
Free, no credit card | First findings in minutes