Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-70597
Electron: Parent process code-sign check is spoofable
CVE-2026-69207
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
CVE-2026-53949
Ghost Content API filter bypass reveals private fields
CVE-2026-70595
Ghost: Server-Side Request Forgery Mitigation Issue
CVE-2026-70596
Ghost: Cross-Site Scripting in Feature Image Captions
CVE-2026-59817
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
CVE-2026-53947
Ghost: Member existence leak via magic link sign-in response
CVE-2026-70594
Ghost: Session Fixation in Ghost Admin
CVE-2026-70593
Ghost: Theme Upload Path Traversal
CVE-2026-70592
Ghost: Database Backup Path Traversal
CVE-2026-70590
Ghost: Blind Password Hash Disclosure in Ghost Admin API
CVE-2026-70591
Ghost: Server-Side Request Forgery in Image Fetching
CVE-2026-53944
Ghost: Private IP filtering bypass to make server-side requests to internal services
CVE-2026-53946
Ghost: Mobiledoc image-size fetch SSRF
CVE-2026-53945
Ghost: Server-side request forgery via DNS rebinding in external request handling
CVE-2026-16729
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
CVE-2026-16728
undici vulnerable to downstream response desynchronization via retry interceptor
CVE-2026-15157
undici vulnerable to CRLF Injection via blob-like body 'type' property
CVE-2026-14643
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
CVE-2026-70588
Ghost: Cross-Site Scripting in Universal Import
CVE-2026-53948
Ghost: File Upload Content-Type Spoofing
CVE-2026-70589
Ghost: Archived Offers can be Redeemed
GHSA-rwrp-9823-p2xq
Flowise: Incomplete Credential Redaction Exposes Secrets via API
CVE-2026-67332
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
CVE-2026-67335
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
CVE-2023-39522
Withdrawn Advisory: Username enumeration attack in goauthentik
CVE-2026-53606
sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
CVE-2026-53667
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
CVE-2026-53666
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
GHSA-2rp8-mm9q-fp49
TypeORM: migration:generate template-literal code injection
CVE-2026-62324
Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
CVE-2026-68499
re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)
CVE-2026-54753
`nx graph` dev server permissive CORS policy
CVE-2026-67550
re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)
GHSA-xrmj-5g4g-8987
@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
GHSA-pqh8-p93p-2rx7
@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
CVE-2026-54561
mcp-memory-keeper: Arbitrary local file read in context_import via unvalidated filePath
CVE-2026-59876
protobufjs: Text Format string map parsing can mutate returned map object prototype
CVE-2026-59870
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
GHSA-x445-f3h2-j279
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
GHSA-frvp-7c67-39w9
Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
CVE-2026-54705
mathlive's Lack of Escaping of HTML allows for XSS
CVE-2026-10732
decompress: Arbitrary File Write via Archive Extraction (Zip Slip)
CVE-2026-54663
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
CVE-2026-52888
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
GHSA-vg6v-j97m-h5xq
@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
CVE-2026-53781
@steipete/summarize is Vulnerable to Disk Exhaustion via Crafted Media Responses
GHSA-r292-9mhp-454m
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
CVE-2026-5078
morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
GHSA-8q49-2h5h-434x
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
GHSA-3r53-75j5-3g7j
Quasar: Prototype pollution in the extend() utility
GHSA-cr7p-cr3q-h5cm
Budibase: Account Enumeration via Login Lockout Response Differential
GHSA-fcrw-f7gg-6g9f
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
GHSA-gh4h-34gr-87r7
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
GHSA-4qcj-m5wp-jmf4
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
CVE-2026-7120
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
GHSA-53g2-mvcc-q9x3
Trix: Stored XSS via HTMLParser attribute injection on paste
GHSA-664h-wqgq-64gw
Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
GHSA-38hq-7x33-php4
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
GHSA-866w-xmhq-wj7x
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
Ready to move
Start Securing
Free, no credit card | First findings in minutes