Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

10,247 vulnerabilities

HIGH 7.1
Go

CVE-2025-71426

Contrast's unauthenticated recovery allows Coordinator impersonation

HIGH 7.3
Go

CVE-2025-71423

Contrast leaks workload secrets to logs on INFO level

HIGH 7.3
Go

CVE-2025-71425

Contrast workload secrets leak to logs on INFO level

HIGH 8.1
Go

CVE-2026-100838

Contras Affected by CopyFile Policy Subversion via Symlinks

HIGH 8.4
Go

CVE-2026-100839

Contrast BadAML injection allows arbitrary code execution

HIGH 8.4
NuGet

CVE-2026-100368

CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers

HIGH 8.4
NuGet

CVE-2026-100369

CliInvoke: Argument Injection in Extensibility Runner Factory

HIGH 7.1
Maven

CVE-2026-57303

Jenkins Assembla Plugin has an XXE vulnerability

HIGH 7.5
RubyGems

CVE-2026-85396

rubyzip path traversal vulnerability

HIGH 8.8
Maven

CVE-2026-57301

Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE

HIGH 8.8
Maven

CVE-2026-57296

Jenkins External Workspace Manager Plugin has a path traversal vulnerability

HIGH 7.5
Maven

CVE-2026-57281

Jenkins Script Security Plugin has a script security bypass vulnerability

HIGH 8.8
Maven

CVE-2026-57280

Jenkins Script Security Plugin sandbox bypass vulnerability

HIGH 8.2
Go

CVE-2026-65838

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies

HIGH 7.7
Go

CVE-2026-84195

Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak)

HIGH 7.7
Go

CVE-2026-84196

Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF

HIGH 7.5
Go

CVE-2026-57231

Podman: Malformed Image can trick podman run into leaking host environment variables into the container

HIGH 8.8
Maven

CVE-2026-41862

Spring Statemachine's Kryo-based persistence backends deserialize persisted state-machine contexts without enforcing a class allowlist

HIGH 8.1
Maven

GHSA-vjr9-f93j-mjr7

Duplicate Advisory: OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

HIGH 8.7
Go

CVE-2026-85057

ZITADEL: Actions V1 sandbox escape: host file read via require()

HIGH 8.2
Go

CVE-2026-85056

ZITADEL: MFA bypass via session reuse in Login V2

HIGH 7.7
Go

CVE-2026-58314

Gitea: Two SSRF findings

HIGH 7.5
Go

CVE-2026-34966

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

HIGH 7.5
Maven

CVE-2025-14813

Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks

HIGH 8.1
Maven

CVE-2026-54148

http4k: `DigestAuthProvider.verify` did not bind to request URI

HIGH 7.5
Maven

CVE-2026-61814

Jawn: Quadratic parsing effort in AsyncParser

HIGH 7.5
Maven

CVE-2026-59990

Jawn: Uncontrolled nesting depth in JSON parser

HIGH 7.5
Go

CVE-2026-86065

Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)

HIGH 8.6
Go

CVE-2026-86064

Klever-Go: /log controls global node logging

HIGH 8.8
RubyGems

CVE-2026-77601

OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting

HIGH 7.5
Maven

CVE-2026-77422

JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping

HIGH 8.1
PyPI

GHSA-x36p-c636-788x

Duplicate Advisory: Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

HIGH 8.1
PyPI

GHSA-q8qp-8jq6-78mc

Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

HIGH 8.1
PyPI

GHSA-mg57-j93w-g3c7

Duplicate Advisory: Picklescan has a missing detection when calling built-in python profile.Profile.runctx

HIGH 8.1
PyPI

GHSA-gq8p-2329-gh3x

Duplicate Advisory: Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

HIGH 8.1
PyPI

CVE-2025-71365

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

HIGH 8.1
PyPI

CVE-2025-71370

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

HIGH 8.1
PyPI

CVE-2025-71341

Picklescan has a missing detection when calling built-in python profile.Profile.runctx

HIGH 8.1
PyPI

CVE-2025-71376

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

HIGH 8.8
PyPI

CVE-2026-67325

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

HIGH 8.4
PyPI

CVE-2026-78675

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

HIGH 7.1
Go

CVE-2026-77633

Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service

HIGH 8.6
PyPI

CVE-2026-77262

MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)

HIGH 7.1
PyPI

CVE-2026-85740

lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard

HIGH 8.6
Go

CVE-2026-76819

Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability

HIGH 7.4
PyPI

CVE-2026-77246

MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path

HIGH 7.1
PyPI

CVE-2026-77253

MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files

HIGH 8.8
Go

CVE-2026-62182

KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes

HIGH 7.5
Maven

CVE-2026-61570

MPXJ: XXE Vulnerability in MerlinReader

HIGH 8.1
Go

CVE-2026-62369

KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join

HIGH 8.8
PyPI

CVE-2026-77243

MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass

HIGH 7.7
PyPI

CVE-2026-77258

MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()

HIGH 8.8
Go

CVE-2026-62371

KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API

HIGH 8.1
Go

CVE-2026-77560

Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for

HIGH 8.6
PyPI

CVE-2026-77255

MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue

HIGH 7.1
RubyGems

CVE-2026-94462

Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)

HIGH 7.7
PyPI

CVE-2026-77259

MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials

HIGH 8.6
PyPI

CVE-2026-77248

MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport

HIGH 7.1
PyPI

CVE-2026-77261

MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches

HIGH 7.5
Go

CVE-2026-77322

SIPGO: DoS via unvalidated WebSocket frame length

Ready to move

Start Securing

Free, no credit card | First findings in minutes