Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-67334
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
CVE-2026-53607
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
GHSA-pc2w-4mq8-32qw
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
GHSA-464c-974j-9xm6
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
CVE-2026-12590
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
GHSA-hp3v-mfqw-h74c
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
CVE-2022-24719
Forwarding of confidentials headers to third parties in fluture-node
CVE-2026-54327
Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
CVE-2026-46549
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
CVE-2026-54326
Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
CVE-2026-11330
claude-mem: The computeObservationContentHash Function is Vulnerable to Hash Collision
CVE-2026-56349
n8n has a Guardrail Node Bypass
CVE-2026-56764
Hono added timing comparison hardening in basicAuth and bearerAuth
CVE-2026-49356
@babel/core: Arbitrary File Read via sourceMappingURL Comment
CVE-2026-54335
Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__
CVE-2026-49456
Waku has an Open Redirect via `unstable_redirect` Helper
CVE-2026-56378
ImageMagick: Malicious PCD files trigger 1‑byte heap Out-of-bounds Read and DoS
CVE-2026-57234
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
CVE-2026-56365
ImageMagick has a memory leak in PNG encoder when writing a MNG image
CVE-2026-56376
ImageMagick has a possible heap Use After Free vulnerability in its meta coder
CVE-2026-56369
ImageMagick: Information Disclosure in PasskeyEncipherImage via AES-CTR nonce reuse
CVE-2026-56363
ImageMagick: Division by Zero in binomial kernel
CVE-2026-25984
ImageMagick: Integer Overflow in PSB (PSD v2) RLE decoding path causes heap Out of Bounds reads for 32-bit builds
CVE-2026-41361
OpenClaw SSRF guard misses four IPv6 special-use ranges
CVE-2026-53835
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
CVE-2026-56361
ImageMagick has has an off-by-one origin validation in allows out-of-bounds read in morphology processing
CVE-2025-27221
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
CVE-2026-2391
qs's arrayLimit bypass in comma parsing allows denial of service
CVE-2024-22047
Race Condition leading to logging errors
CVE-2024-22261
SQL Injection in Harbor scan log API
CVE-2024-23686
nvdApiKey is logged in debug mode
CVE-2020-8908
Information Disclosure in Guava
CVE-2021-41190
Clarify Content-Type handling
CVE-2021-34428
SessionListener can prevent a session from being invalidated breaking logout
CVE-2020-5303
Denial of service in Tendermint
CVE-2021-28163
Directory exposure in jetty
CVE-2021-32729
A user without PR can reset user authentication failures information
CVE-2020-15184
Aliases are never checked in helm
CVE-2021-21331
Local Information Disclosure Vulnerability
CVE-2020-15186
Improper Sanitizing of plugin names in helm
CVE-2021-21320
User content sandbox can be confused into opening arbitrary documents
CVE-2021-41136
Puma with proxy which forwards LF characters as line endings could allow HTTP request smuggling
CVE-2020-15262
Unprotected dynamically loaded chunks
CVE-2021-43862
jquery.terminal self XSS on user input
CVE-2021-32696
Passing in a non-string 'html' argument can lead to unsanitized output
CVE-2020-15185
Repository index file allows for duplicates of the same chart entry in helm
CVE-2021-41089
`docker cp` allows unexpected chmod of host files in Moby Docker Engine
CVE-2022-2047
Jetty invalid URI parsing may produce invalid HttpURI.authority
CVE-2021-43838
Regular Expression Denial of Service (ReDoS) in jsx-slack
CVE-2020-15187
plugin.yaml file allows for duplicate entries in helm
CVE-2019-16772
Cross-Site Scripting in serialize-to-js
CVE-2020-15168
The `size` option isn't honored after following a redirect in node-fetch
CVE-2020-4053
Plugin archive directory traversal in Helm
CVE-2020-4051
Cross-site Scripting in dijit editor's LinkDialog plugin
CVE-2020-15106
Panic due to malformed WALs in go.etcd.io/etcd
CVE-2026-41579
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
CVE-2023-41329
Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes
GO-2026-5865
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries
CVE-2026-49245
SFTPGo has stored XSS via inline parameter on public shares and user file download
GO-2024-3059
CosmWasm wasmd has large address count in ValidateBasic
Ready to move
Start Securing
Free, no credit card | First findings in minutes