Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-76845
adm-zip extraction follows destination symlinks, allowing arbitrary file overwrite
CVE-2026-84369
SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements
CVE-2026-84364
Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion
CVE-2026-84365
Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
CVE-2026-84363
Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
GHSA-8m3c-c648-2xjj
Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
CVE-2026-84373
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
CVE-2026-72925
SWC HTML minifier may allow script element breakout when minifying embedded JSON
CVE-2026-12208
jsonata: Function Binding Prototype Pollution via hasOwnProperty Override
CVE-2026-33244
React Router has stored XSS via unescaped Location header in prerendered redirect HTML
CVE-2026-8769
@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
CVE-2026-53668
React Router: Open redirect leading to XSS
CVE-2026-16629
danger allows local OS command injection through crafted file paths
CVE-2026-63669
ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree
CVE-2026-63670
ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close
CVE-2026-73846
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning
CVE-2026-55855
MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets
CVE-2026-55854
MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
CVE-2026-18504
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
CVE-2026-16732
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
CVE-2026-63667
ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
CVE-2026-73845
CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
GHSA-3q45-2fh7-66cj
Duplicate Advisory: better-auth has an external request basePath modification DoS
CVE-2026-58191
Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
CVE-2026-82864
PDFME Affected by Decompression Bomb in FlateDecode Stream Parsing Causes Memory Exhaustion DoS
CVE-2026-82660
Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
CVE-2024-58379
nodemailer ReDoS when trying to send a specially crafted email
CVE-2026-82662
Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
CVE-2026-82661
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
CVE-2026-82865
PDFME has XSS via Unsanitized i18n Label Injection into innerHTML in multiVariableText propPanel
CVE-2026-82867
Cross-Site Scripting (XSS) via Select Schema Option Value Injection in @pdfme/schemas
CVE-2026-82866
PDFME has SSRF via Unvalidated URL Fetch in `getB64BasePdf` When `basePdf` Is Attacker-Controlled
CVE-2026-82853
Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)
CVE-2026-82868
Cross-Site Scripting (XSS) via SVG Schema innerHTML Injection in @pdfme/schemas
CVE-2026-81888
@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
CVE-2026-56326
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
CVE-2026-82256
SvelteKit: Big remote form function payloads can cause Node process to crash
CVE-2026-82257
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
CVE-2026-54732
libreoffice-convert vulnerable to path traversal / arbitrary file write
CVE-2026-55605
@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint
CVE-2026-55663
mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
CVE-2026-53830
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
GHSA-p68j-q8j9-jwf5
Duplicate Advisory: OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
CVE-2026-54285
OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
CVE-2026-53509
@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)
CVE-2026-33060
SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks
CVE-2026-63466
Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
CVE-2026-63004
Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
CVE-2026-59992
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)
CVE-2026-63123
Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root
CVE-2026-69146
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
CVE-2026-55410
NocoBase backup restore schema name allows command injection
CVE-2026-70609
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
CVE-2026-76233
Renovate vulnerable to arbitrary command injection via gleam manager and malicious gleam.toml file
CVE-2026-76230
Renovate vulnerable to arbitrary command injection via npm manager and malicious Renovate configuration
CVE-2026-76229
Renovate vulnerable to arbitrary command injection via kustomize manager and malicious helm repository
CVE-2026-76231
Renovate vulnerable to arbitrary command injection via hermit manager and maliciously named dependencies
CVE-2026-76227
Child processes spawned by Renovate incorrectly have full access to environment variables
CVE-2026-76232
Renovate vulnerable to arbitrary command injection via helmv3 manager and malicious Chart.yaml file
CVE-2026-76228
Renovate vulnerable to arbitrary command injection via Gradle Wrapper and malicious `distributionUrl`
Ready to move
Start Securing
Free, no credit card | First findings in minutes