Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-53950
XSS in Ghost's ActivityPub client
CVE-2026-69152
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
GHSA-2p49-hgcm-8545
SVGO removeScripts plugin leaves some executable scripts intact
CVE-2026-18446
fast-uri vulnerable to host confusion via backslash authority introducer
CVE-2026-13697
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
CVE-2026-54609
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
CVE-2022-21680
Inefficient Regular Expression Complexity in marked
CVE-2022-21681
Inefficient Regular Expression Complexity in marked
CVE-2026-52746
jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
CVE-2026-69185
Socket.IO: Zero-attachment Memory Exhaustion
CVE-2025-71400
Better Auth Passkey Plugin allows passkey deletion through IDOR
CVE-2025-71399
Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits
CVE-2026-67331
@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
CVE-2026-67336
Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
CVE-2026-67333
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
CVE-2026-67327
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
CVE-2025-71403
Better Auth allows bypassing the trustedOrigins Protection which leads to ATO
CVE-2026-67329
@better-auth/stripe: cross-organization billing tampering in organization subscription actions
CVE-2026-53608
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
CVE-2026-59725
Socket.IO: Engine.IO Polling Transport Connection Exhaustion
CVE-2026-14257
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
CVE-2026-58263
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
CVE-2026-54737
@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
GHSA-p7w7-4929-vpj5
`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
CVE-2026-53598
Prompty: Arbitrary file read via file reference expansion
CVE-2026-11572
degit has a Command Injection issue
GHSA-xmf8-cvqr-rfgj
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
CVE-2026-54666
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
CVE-2026-54661
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
CVE-2026-54664
swagger-typescript-api vulnerable to code injection via unescaped enum string values
CVE-2026-54660
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
CVE-2026-54662
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
CVE-2026-50272
dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-54639
Style Dictionary - Prototype Pollution in convertTokenData utility function
CVE-2026-13311
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
CVE-2026-54545
@wakaru/cli arbitrary file write during bundle unpack
CVE-2026-50131
Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
CVE-2026-42342
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
GHSA-pm4m-ph32-ghv5
js-yaml: Exponential parsing time in flow collections leads to denial of service
GHSA-r28c-9q8g-f849
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
CVE-2026-45623
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
CVE-2026-59887
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
GHSA-v42f-v8xc-j435
Budibase: SSRF via DNS rebinding in the REST datasource integration
GHSA-g5vv-q72c-7j78
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
GHSA-pmpg-2mxq-6xwr
Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
GHSA-pvcr-8mvp-w8qr
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
GHSA-xg5g-26x8-cvf4
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
GHSA-qw6m-8fw2-2v64
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
GHSA-xcx6-4f2g-hhgx
Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
GHSA-hr66-5mqr-8mpx
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
GHSA-2xgg-r2wc-c5r2
Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
GHSA-j9fc-w3mr-x6mv
Budibase: Privilege escalation via public role assignment API missing app-level authorization
CVE-2026-44907
react-server-dom: Denial of Service in Server Functions
CVE-2026-59892
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
CVE-2026-15074
@fastify/static vulnerable to route guard bypass via path traversal
CVE-2026-54672
electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
CVE-2026-47219
find-my-way: DDoS with HTTP2
CVE-2026-59879
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
CVE-2026-16221
fast-uri vulnerable to host confusion via literal backslash authority delimiter
GHSA-2qp2-6frj-p9pq
Duplicate Advisory: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
Ready to move
Start Securing
Free, no credit card | First findings in minutes