Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2025-71424
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points
CVE-2026-100837
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries
CVE-2026-57288
Jenkins Active Directory Plugin has an LDAP injection vulnerability
CVE-2026-79783
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
CVE-2026-79782
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
CVE-2026-79777
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
CVE-2026-56376
ImageMagick has a possible heap Use After Free vulnerability in its meta coder
GHSA-8g9f-ccmr-vfvg
Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder
CVE-2026-77637
Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope
CVE-2026-62364
wlc may disclose API tokens to project-configured URLs
CVE-2026-84298
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher
CVE-2026-8823
Mattermost has an Incorrect Authorization issue
CVE-2026-88013
rclone: http backend forwards custom/auth headers to a different host on redirect
CVE-2026-56370
ImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* artifacts
CVE-2025-24978
LF Edge eKuiper: Self-XSS in External Service Creation
CVE-2026-85716
AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses
CVE-2026-61700
MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests
CVE-2026-86071
Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root
CVE-2026-8074
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
CVE-2026-57583
OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
CVE-2026-43514
Apache Tomcat - AJP secret compared in non-constant time
CVE-2026-12372
CVE-2026-12372
CVE-2026-54548
kas Persistently Disables SSH Host Key Checking
CVE-2026-81723
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
CVE-2026-71514
NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure
GHSA-9wx3-p993-35vp
Duplicate Advisory: Axios: Nested axios option objects can consume polluted prototype values
GO-2026-6265
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
CVE-2026-71849
Hono: Proxy Helper does not remove response headers listed in the `Connection` header
GO-2026-6262
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
CVE-2026-54696
Ruby json: JSON generator heap buffer overflow when streaming to an IO
CVE-2026-54787
sigstore-go fails to check signature timestamps against a signing key's validity period
CVE-2026-55403
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
CVE-2026-48588
Django: cache middleware may expose private responses when unrelated request cookies are present
CVE-2026-44162
fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`
CVE-2026-10722
ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader
CVE-2026-41579
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
CVE-2026-7666
Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
CVE-2026-11525
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
CVE-2026-57234
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
CVE-2026-53663
React Router: Potential CSRF via PUT/PATCH/DELETE document requests
CVE-2026-53538
python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
CVE-2026-48051
Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
CVE-2026-6733
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
CVE-2026-48156
pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
CVE-2026-44405
Paramiko rsakey.py allows the SHA-1 algorithm
CVE-2026-44459
Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
CVE-2026-44572
Next.js's Middleware / Proxy redirects can be cache-poisoned
CVE-2026-45781
MCP Registry: OCI validator skips ownership check on upstream rate limits
CVE-2026-22741
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
CVE-2026-22746
Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
CVE-2026-39396
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVE-2026-34166
LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter
CVE-2026-3449
@tootallnate/once vulnerable to Incorrect Control Flow Scoping
CVE-2026-22735
Spring MVC and WebFlux has Server Sent Event stream corruption
CVE-2026-4539
Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
CVE-2026-74797
OpenTofu has High CPU usage in "tofu init" with maliciously-crafted module packages in .zip format
CVE-2025-48985
Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
Ready to move
Start Securing
Free, no credit card | First findings in minutes