Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-100836
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts
CVE-2025-71422
Contrast has insecure LUKS2 persistent storage partitions may be opened and used
CVE-2026-57305
Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability
CVE-2026-57306
Jenkins Zowe zDevOps Plugin has a CSRF vulnerability
CVE-2026-57307
Jenkins Zowe zDevOps Plugin has a missing permission check
CVE-2026-57304
Jenkins Assembla Plugin has a missing permission check
CVE-2026-57302
Jenkins FitNesse Plugin stores passwords unencrypted
CVE-2026-57299
Jenkins Contrast Continuous Application Security Plugin missing permission checks
CVE-2026-57300
Jenkins MCP Server Plugin missing a permission check
CVE-2026-57298
Jenkins Contrast Continuous Application Security Plugin has a CSRF vulnerability
CVE-2026-57291
Jenkins Gitee Plugin missing permission checks
CVE-2026-57292
Jenkins Gitee Plugin has a cross-site request forgery vulnerability
CVE-2026-57289
Jenkins Bitbucket Push and Pull Request Plugin unconditionally disables SSL/TLS certificate validation
CVE-2026-57290
Jenkins Priority Sorter Plugin has a CSRF vulnerability
CVE-2026-57297
Jenkins Contrast Continuous Application Security Plugin has a missing permission check
CVE-2026-57294
Jenkins EC2 Fleet Plugin has a missing permission check
CVE-2026-57295
Jenkins EC2 Fleet Plugin has a cross-site request forgery (CSRF) vulnerability
CVE-2026-57293
Jenkins Gitee Plugin has an incorrect permission check that allows enumerating credentials IDs
CVE-2026-57282
Jenkins Git client Plugin has an OS command injection vulnerability on agents
CVE-2026-57285
Jenkins GitHub Branch Source Plugin has missing permission check that allows enumerating GitHub Enterprise server URLs
CVE-2026-57284
Jenkins Pipeline: Groovy Plugin vulnerable to unrestricted instantiation of types
CVE-2026-57286
Jenkins Git Parameter Plugin has a missing permission check that allows listing SCM branch and tag names
CVE-2026-57287
Jenkins Job Configuration History Plugin doesn't redact encrypted values of secrets in job and agent configurations
CVE-2026-57283
Jenkins Pipeline: Groovy Plugin has a CSRF vulnerability
CVE-2025-37731
Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
CVE-2024-52980
Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
CVE-2026-79778
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
CVE-2026-79779
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
CVE-2026-55770
OpenBao: LDAPi ldaputil (wrong escape func)
CVE-2026-79781
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
CVE-2026-55776
OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types
CVE-2026-79780
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
CVE-2026-88016
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
CVE-2026-56742
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
CVE-2026-10609
OpenShift Cluster Logging Operator missing authorization flaw
CVE-2026-62286
Dozzle label filters do not restrict container event and statistics streams
CVE-2026-19730
podman quadlet install --replace does not fully replace the old file
CVE-2026-56443
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
CVE-2026-56657
Gitea SSH Key Parser Denial of Service
CVE-2026-77281
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass
GHSA-8pcw-h6w9-h46g
plone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length
CVE-2026-57576
plone.app.dexterity has a Denial of Service due to excessive title or description length
CVE-2026-77421
JLine: ReDoS in Nano Editor Regex Search Mode
CVE-2026-77420
JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable
CVE-2026-78679
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
CVE-2026-33060
SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks
CVE-2026-53509
@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)
CVE-2026-61612
@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509
CVE-2026-77249
MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup
CVE-2026-79913
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses
CVE-2026-76804
Nuclei: Local File Read via Workflow File-Protocol Gate Bypass
CVE-2026-76805
Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode
CVE-2026-76803
Nuclei: Local File Read via MySQL Client Sandbox Bypass
CVE-2026-69190
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards
CVE-2026-86062
lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content
CVE-2026-83805
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs
CVE-2026-77266
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call
CVE-2026-76802
Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass
CVE-2026-65829
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
CVE-2026-62987
Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header
Ready to move
Start Securing
Free, no credit card | First findings in minutes