Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-45591
Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability
CVE-2026-48526
PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
CVE-2020-29367
CVE-2020-29367
CVE-2026-46373
SQLFluff: Recursive Stack Overflow in Parser
CVE-2026-46374
SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser
CVE-2026-53441
Jenkins: Stored XSS vulnerability in node offline cause description
CVE-2026-45013
Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation
CVE-2026-45011
Apostrophe has stored XSS via javascript: URL in Image Widget Link
CVE-2026-42306
Docker: Race condition in docker cp allows bind mount redirection to host path
CVE-2026-45012
Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget
CVE-2026-41731
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
CVE-2026-54091
File Browser has incorrect access control for public directory shares via rule path rebasing
CVE-2026-53999
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
GHSA-gv7w-rqvm-qjhr
esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
CVE-2026-45416
Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
CVE-2026-44893
Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
CVE-2026-44894
Netty's Default QUIC token handler accepts any client-supplied token
CVE-2026-46340
Netty: SCTP reassembly nests buffers without bound
CVE-2026-45674
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
CVE-2026-47691
Netty has Insufficient Bailiwick Validation for NS Records
CVE-2026-46475
FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover
CVE-2026-47209
vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain
CVE-2026-47135
vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks
CVE-2026-47139
NodeVM network builtin exclusions bypass via internal _http_client and _http_server
CVE-2026-46519
MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement
CVE-2026-44495
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
CVE-2026-44494
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
CVE-2026-32936
CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
CVE-2026-44486
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
CVE-2026-44892
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
CVE-2026-44250
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
CVE-2026-44890
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
CVE-2026-44249
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
CVE-2026-44488
Allocation of Resources Without Limits or Throttling in Axios
GHSA-j9gf-vw2f-9hrw
Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
GHSA-9wcp-79g5-5c3c
Appsmith Super User Creation Race Condition Allows Multiple Instance Administrators
CVE-2026-48151
Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
CVE-2026-48152
Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
CVE-2025-52465
GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
CVE-2026-48146
Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
CVE-2026-25087
Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
CVE-2026-47701
OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth
CVE-2026-48069
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
CVE-2026-48068
@grpc/grpc-js: A malformed request can cause a server crash
CVE-2026-48099
WsgiDAV encoded dot segments can escape filesystem share roots
CVE-2026-11401
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-48109
MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
CVE-2025-27511
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
CVE-2026-40981
Spring Cloud Config has an Authorization Bypass Through User-Controlled Key
CVE-2020-13935
Infinite Loop in Apache Tomcat
CVE-2020-11996
Uncontrolled Resource Consumption in Apache Tomcat
CVE-2023-2968
proxy denial of service vulnerability
CVE-2026-46520
ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions
CVE-2026-46679
js-libp2p: Memory DoS via subscription flood of unique topics
CVE-2026-46522
ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
CVE-2026-42305
Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows
CVE-2026-46625
JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
CVE-2026-46444
FlowiseAI: Vector Store No Permission Checks
Ready to move
Start Securing
Free, no credit card | First findings in minutes