Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

11,200 vulnerabilities

MEDIUM 4.3
Go

CVE-2026-100836

Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts

MEDIUM 5.7
Go

CVE-2025-71422

Contrast has insecure LUKS2 persistent storage partitions may be opened and used

MEDIUM 5.4
Maven

CVE-2026-57305

Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability

MEDIUM 4.2
Maven

CVE-2026-57306

Jenkins Zowe zDevOps Plugin has a CSRF vulnerability

MEDIUM 4.2
Maven

CVE-2026-57307

Jenkins Zowe zDevOps Plugin has a missing permission check

MEDIUM 5.4
Maven

CVE-2026-57304

Jenkins Assembla Plugin has a missing permission check

MEDIUM 4.3
Maven

CVE-2026-57302

Jenkins FitNesse Plugin stores passwords unencrypted

MEDIUM 4.3
Maven

CVE-2026-57299

Jenkins Contrast Continuous Application Security Plugin missing permission checks

MEDIUM 4.3
Maven

CVE-2026-57300

Jenkins MCP Server Plugin missing a permission check

MEDIUM 5.4
Maven

CVE-2026-57298

Jenkins Contrast Continuous Application Security Plugin has a CSRF vulnerability

MEDIUM 5.4
Maven

CVE-2026-57291

Jenkins Gitee Plugin missing permission checks

MEDIUM 5.4
Maven

CVE-2026-57292

Jenkins Gitee Plugin has a cross-site request forgery vulnerability

MEDIUM 4.8
Maven

CVE-2026-57289

Jenkins Bitbucket Push and Pull Request Plugin unconditionally disables SSL/TLS certificate validation

MEDIUM 4.3
Maven

CVE-2026-57290

Jenkins Priority Sorter Plugin has a CSRF vulnerability

MEDIUM 4.3
Maven

CVE-2026-57297

Jenkins Contrast Continuous Application Security Plugin has a missing permission check

MEDIUM 5.4
Maven

CVE-2026-57294

Jenkins EC2 Fleet Plugin has a missing permission check

MEDIUM 5.4
Maven

CVE-2026-57295

Jenkins EC2 Fleet Plugin has a cross-site request forgery (CSRF) vulnerability

MEDIUM 4.3
Maven

CVE-2026-57293

Jenkins Gitee Plugin has an incorrect permission check that allows enumerating credentials IDs

MEDIUM 5.0
Maven

CVE-2026-57282

Jenkins Git client Plugin has an OS command injection vulnerability on agents

MEDIUM 4.3
Maven

CVE-2026-57285

Jenkins GitHub Branch Source Plugin has missing permission check that allows enumerating GitHub Enterprise server URLs

MEDIUM 4.3
Maven

CVE-2026-57284

Jenkins Pipeline: Groovy Plugin vulnerable to unrestricted instantiation of types

MEDIUM 4.3
Maven

CVE-2026-57286

Jenkins Git Parameter Plugin has a missing permission check that allows listing SCM branch and tag names

MEDIUM 4.3
Maven

CVE-2026-57287

Jenkins Job Configuration History Plugin doesn't redact encrypted values of secrets in job and agent configurations

MEDIUM 4.3
Maven

CVE-2026-57283

Jenkins Pipeline: Groovy Plugin has a CSRF vulnerability

MEDIUM 6.8
Maven

CVE-2025-37731

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

MEDIUM 6.5
Maven

CVE-2024-52980

Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

MEDIUM 5.3
Go

CVE-2026-79778

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

MEDIUM 5.3
Go

CVE-2026-79779

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

MEDIUM 6.8
Go

CVE-2026-55770

OpenBao: LDAPi ldaputil (wrong escape func)

MEDIUM 6.5
Go

CVE-2026-79781

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

MEDIUM 6.5
Go

CVE-2026-55776

OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types

MEDIUM 5.3
Go

CVE-2026-79780

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

MEDIUM 6.5
Go

CVE-2026-88016

rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination

MEDIUM 5.9
Go

CVE-2026-56742

Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces

MEDIUM 6.8
Go

CVE-2026-10609

OpenShift Cluster Logging Operator missing authorization flaw

MEDIUM 4.3
Go

CVE-2026-62286

Dozzle label filters do not restrict container event and statistics streams

MEDIUM 4.2
Go

CVE-2026-19730

podman quadlet install --replace does not fully replace the old file

MEDIUM 4.3
Go

CVE-2026-56443

Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118

MEDIUM 6.2
Go

CVE-2026-56657

Gitea SSH Key Parser Denial of Service

MEDIUM 6.5
Go

CVE-2026-77281

Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass

MEDIUM 6.5
PyPI

GHSA-8pcw-h6w9-h46g

plone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length

MEDIUM 6.5
PyPI

CVE-2026-57576

plone.app.dexterity has a Denial of Service due to excessive title or description length

MEDIUM 6.5
Maven

CVE-2026-77421

JLine: ReDoS in Nano Editor Regex Search Mode

MEDIUM 5.5
Maven

CVE-2026-77420

JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable

MEDIUM 6.5
PyPI

CVE-2026-78679

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

MEDIUM 5.7
npm

CVE-2026-33060

SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks

MEDIUM 5.7
npm

CVE-2026-53509

@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)

MEDIUM 5.7
npm

CVE-2026-61612

@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509

MEDIUM 5.3
PyPI

CVE-2026-77249

MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup

MEDIUM 6.5
Go

CVE-2026-79913

Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses

MEDIUM 5.5
Go

CVE-2026-76804

Nuclei: Local File Read via Workflow File-Protocol Gate Bypass

MEDIUM 5.3
Go

CVE-2026-76805

Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode

MEDIUM 5.3
Go

CVE-2026-76803

Nuclei: Local File Read via MySQL Client Sandbox Bypass

MEDIUM 6.3
Maven

CVE-2026-69190

Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards

MEDIUM 6.1
PyPI

CVE-2026-86062

lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content

MEDIUM 6.4
PyPI

CVE-2026-83805

Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs

MEDIUM 6.5
PyPI

CVE-2026-77266

MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call

MEDIUM 4.7
Go

CVE-2026-76802

Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass

MEDIUM 5.3
NuGet

CVE-2026-65829

MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers

MEDIUM 5.8
Go

CVE-2026-62987

Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header

Ready to move

Start Securing

Free, no credit card | First findings in minutes