Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

LOW 3.5
Go

CVE-2025-71424

Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points

LOW 3.7
Go

CVE-2026-100837

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries

LOW 3.7
Maven

CVE-2026-57288

Jenkins Active Directory Plugin has an LDAP injection vulnerability

LOW 3.6
Go

CVE-2026-79783

rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote

LOW 3.1
Go

CVE-2026-79782

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

LOW 2.7
Go

CVE-2026-79777

rclone: Verbose Stack Trace Disclosure in RC API Error Responses

LOW 3.7
NuGet

CVE-2026-56376

ImageMagick has a possible heap Use After Free vulnerability in its meta coder

LOW 3.7
NuGet

GHSA-8g9f-ccmr-vfvg

Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder

LOW 3.8
Go

CVE-2026-77637

Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope

LOW 2.3
PyPI

CVE-2026-62364

wlc may disclose API tokens to project-configured URLs

LOW 3.1
Go

CVE-2026-84298

Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher

LOW 3.8
Go

CVE-2026-8823

Mattermost has an Incorrect Authorization issue

LOW 3.7
Go

CVE-2026-88013

rclone: http backend forwards custom/auth headers to a different host on redirect

LOW 3.3
NuGet

CVE-2026-56370

ImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* artifacts

LOW 3.7
Go

CVE-2025-24978

LF Edge eKuiper: Self-XSS in External Service Creation

LOW 3.7
Maven

CVE-2026-85716

AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses

LOW 3.7
Maven

CVE-2026-61700

MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests

LOW 3.7
Maven

CVE-2026-86071

Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root

LOW 3.8
Go

CVE-2026-8074

Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint

LOW 3.3
npm

CVE-2026-57583

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source

LOW 3.7
Maven

CVE-2026-43514

Apache Tomcat - AJP secret compared in non-constant time

LOW 3.7
PyPI

CVE-2026-12372

CVE-2026-12372

LOW 3.3
PyPI

CVE-2026-54548

kas Persistently Disables SSH Host Key Checking

LOW 3.7
PyPI

CVE-2026-81723

NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

LOW 2.5
PyPI

CVE-2026-71514

NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure

LOW 3.7
npm

GHSA-9wx3-p993-35vp

Duplicate Advisory: Axios: Nested axios option objects can consume polluted prototype values

LOW 3.7
Go

GO-2026-6265

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison

LOW 3.7
npm

CVE-2026-71849

Hono: Proxy Helper does not remove response headers listed in the `Connection` header

LOW 2.6
Go

GO-2026-6262

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers

LOW 3.7
RubyGems

CVE-2026-54696

Ruby json: JSON generator heap buffer overflow when streaming to an IO

LOW 3.1
Go

CVE-2026-54787

sigstore-go fails to check signature timestamps against a signing key's validity period

LOW 3.7
PyPI

CVE-2026-55403

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

LOW 3.1
PyPI

CVE-2026-48588

Django: cache middleware may expose private responses when unrelated request cookies are present

LOW 2.7
RubyGems

CVE-2026-44162

fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`

LOW 3.3
Go

CVE-2026-10722

ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader

LOW 3.3
Go

CVE-2026-41579

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

LOW 3.1
PyPI

CVE-2026-7666

Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake

LOW 3.7
npm

CVE-2026-11525

undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching

LOW 2.6
RubyGems

CVE-2026-57234

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

LOW 3.1
npm

CVE-2026-53663

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

LOW 3.7
PyPI

CVE-2026-53538

python-multipart: Semicolon treated as querystring field separator enables parameter smuggling

LOW 3.5
npm

CVE-2026-48051

Papra HTTP redirect bypass can lead to SSRF via webhook delivery system

LOW 3.7
npm

CVE-2026-6733

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

LOW 3.3
PyPI

CVE-2026-48156

pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams

LOW 3.4
PyPI

CVE-2026-44405

Paramiko rsakey.py allows the SHA-1 algorithm

LOW 3.8
npm

CVE-2026-44459

Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()

LOW 3.7
npm

CVE-2026-44572

Next.js's Middleware / Proxy redirects can be cache-poisoned

LOW 3.5
Go

CVE-2026-45781

MCP Registry: OCI validator skips ownership check on upstream rate limits

LOW 3.1
Maven

CVE-2026-22741

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

LOW 3.7
Maven

CVE-2026-22746

Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider

LOW 3.1
Go

CVE-2026-39396

OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)

LOW 3.7
npm

CVE-2026-34166

LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter

LOW 3.3
npm

CVE-2026-3449

@tootallnate/once vulnerable to Incorrect Control Flow Scoping

LOW 2.6
Maven

CVE-2026-22735

Spring MVC and WebFlux has Server Sent Event stream corruption

LOW 3.3
PyPI

CVE-2026-4539

Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

LOW 3.1
Go

CVE-2026-74797

OpenTofu has High CPU usage in "tofu init" with maliciously-crafted module packages in .zip format

LOW 3.7
npm

CVE-2025-48985

Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files

Ready to move

Start Securing

Free, no credit card | First findings in minutes