Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

LOW 3.8
npm

CVE-2026-67334

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

LOW 3.7
npm

CVE-2026-53607

@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header

LOW 3.7
npm

GHSA-pc2w-4mq8-32qw

@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate

LOW 3.3
npm

GHSA-464c-974j-9xm6

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion

LOW 3.7
npm

CVE-2026-12590

body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement

LOW 3.7
npm

GHSA-hp3v-mfqw-h74c

@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped

LOW 2.6
npm

CVE-2022-24719

Forwarding of confidentials headers to third parties in fluture-node

LOW 2.2
npm

CVE-2026-54327

Pi Agent: Race condition in Pi auth.json writes could expose stored credentials

LOW 2.0
npm

CVE-2026-46549

NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation

LOW 2.5
npm

CVE-2026-54326

Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass

LOW 3.6
npm

CVE-2026-11330

claude-mem: The computeObservationContentHash Function is Vulnerable to Hash Collision

LOW 3.7
npm

CVE-2026-56349

n8n has a Guardrail Node Bypass

LOW 3.7
npm

CVE-2026-56764

Hono added timing comparison hardening in basicAuth and bearerAuth

LOW 3.2
npm

CVE-2026-49356

@babel/core: Arbitrary File Read via sourceMappingURL Comment

LOW 3.7
npm

CVE-2026-54335

Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__

LOW 3.1
npm

CVE-2026-49456

Waku has an Open Redirect via `unstable_redirect` Helper

LOW 3.7
NuGet

CVE-2026-56378

ImageMagick: Malicious PCD files trigger 1‑byte heap Out-of-bounds Read and DoS

LOW 2.6
RubyGems

CVE-2026-57234

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

LOW 3.7
NuGet

CVE-2026-56365

ImageMagick has a memory leak in PNG encoder when writing a MNG image

LOW 3.7
NuGet

CVE-2026-56376

ImageMagick has a possible heap Use After Free vulnerability in its meta coder

LOW 3.7
NuGet

CVE-2026-56369

ImageMagick: Information Disclosure in PasskeyEncipherImage via AES-CTR nonce reuse

LOW 3.3
NuGet

CVE-2026-56363

ImageMagick: Division by Zero in binomial kernel

LOW 3.7
NuGet

CVE-2026-25984

ImageMagick: Integer Overflow in PSB (PSD v2) RLE decoding path causes heap Out of Bounds reads for 32-bit builds

LOW 3.1
npm

CVE-2026-41361

OpenClaw SSRF guard misses four IPv6 special-use ranges

LOW 3.1
npm

CVE-2026-53835

OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement

LOW 3.3
NuGet

CVE-2026-56361

ImageMagick has has an off-by-one origin validation in allows out-of-bounds read in morphology processing

LOW 3.2
RubyGems

CVE-2025-27221

URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+

LOW 3.7
npm

CVE-2026-2391

qs's arrayLimit bypass in comma parsing allows denial of service

LOW 3.1
RubyGems

CVE-2024-22047

Race Condition leading to logging errors

LOW 2.7
Go

CVE-2024-22261

SQL Injection in Harbor scan log API

LOW 3.3
Maven

CVE-2024-23686

nvdApiKey is logged in debug mode

LOW 3.3
Maven

CVE-2020-8908

Information Disclosure in Guava

LOW 3.0
Go

CVE-2021-41190

Clarify Content-Type handling

LOW 3.5
Maven

CVE-2021-34428

SessionListener can prevent a session from being invalidated breaking logout

LOW 3.1
Go

CVE-2020-5303

Denial of service in Tendermint

LOW 2.7
Maven

CVE-2021-28163

Directory exposure in jetty

LOW 2.0
Maven

CVE-2021-32729

A user without PR can reset user authentication failures information

LOW 3.7
Go

CVE-2020-15184

Aliases are never checked in helm

LOW 3.0
Maven

CVE-2021-21331

Local Information Disclosure Vulnerability

LOW 3.4
Go

CVE-2020-15186

Improper Sanitizing of plugin names in helm

LOW 2.6
npm

CVE-2021-21320

User content sandbox can be confused into opening arbitrary documents

LOW 3.7
RubyGems

CVE-2021-41136

Puma with proxy which forwards LF characters as line endings could allow HTTP request smuggling

LOW 3.7
npm

CVE-2020-15262

Unprotected dynamically loaded chunks

LOW 3.7
npm

CVE-2021-43862

jquery.terminal self XSS on user input

LOW 3.7
npm

CVE-2021-32696

Passing in a non-string 'html' argument can lead to unsanitized output

LOW 2.2
Go

CVE-2020-15185

Repository index file allows for duplicates of the same chart entry in helm

LOW 2.8
Go

CVE-2021-41089

`docker cp` allows unexpected chmod of host files in Moby Docker Engine

LOW 2.7
Maven

CVE-2022-2047

Jetty invalid URI parsing may produce invalid HttpURI.authority

LOW 3.7
npm

CVE-2021-43838

Regular Expression Denial of Service (ReDoS) in jsx-slack

LOW 3.0
Go

CVE-2020-15187

plugin.yaml file allows for duplicate entries in helm

LOW 3.1
npm

CVE-2019-16772

Cross-Site Scripting in serialize-to-js

LOW 2.6
npm

CVE-2020-15168

The `size` option isn't honored after following a redirect in node-fetch

LOW 3.7
Go

CVE-2020-4053

Plugin archive directory traversal in Helm

LOW 3.7
npm

CVE-2020-4051

Cross-site Scripting in dijit editor's LinkDialog plugin

LOW 3.7
Go

CVE-2020-15106

Panic due to malformed WALs in go.etcd.io/etcd

LOW 3.3
Go

CVE-2026-41579

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

LOW 3.9
Maven

CVE-2023-41329

Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes

LOW 3.7
Go

GO-2026-5865

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries

LOW 3.7
Go

CVE-2026-49245

SFTPGo has stored XSS via inline parameter on public shares and user file download

LOW 3.7
Go

GO-2024-3059

CosmWasm wasmd has large address count in ValidateBasic

Ready to move

Start Securing

Free, no credit card | First findings in minutes