Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 6.5
npm

CVE-2026-76845

adm-zip extraction follows destination symlinks, allowing arbitrary file overwrite

MEDIUM 6.1
npm

CVE-2026-84369

SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements

MEDIUM 5.3
npm

CVE-2026-84364

Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion

MEDIUM 6.5
npm

CVE-2026-84365

Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory

MEDIUM 5.9
npm

CVE-2026-84363

Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

MEDIUM 5.9
npm

GHSA-8m3c-c648-2xjj

Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature

MEDIUM 5.9
npm

CVE-2026-84373

Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock

MEDIUM 6.1
npm

CVE-2026-72925

SWC HTML minifier may allow script element breakout when minifying embedded JSON

MEDIUM 5.3
npm

CVE-2026-12208

jsonata: Function Binding Prototype Pollution via hasOwnProperty Override

MEDIUM 5.4
npm

CVE-2026-33244

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

MEDIUM 4.3
npm

CVE-2026-8769

@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue

MEDIUM 6.9
npm

CVE-2026-53668

React Router: Open redirect leading to XSS

MEDIUM 5.3
npm

CVE-2026-16629

danger allows local OS command injection through crafted file paths

MEDIUM 6.5
npm

CVE-2026-63669

ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree

MEDIUM 6.1
npm

CVE-2026-63670

ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close

MEDIUM 6.5
npm

CVE-2026-73846

CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning

MEDIUM 6.5
npm

CVE-2026-55855

MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets

MEDIUM 5.9
npm

CVE-2026-55854

MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials

MEDIUM 5.4
npm

CVE-2026-18504

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

MEDIUM 6.1
npm

CVE-2026-16732

fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count

MEDIUM 6.5
npm

CVE-2026-63667

ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal

MEDIUM 5.3
npm

CVE-2026-73845

CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)

MEDIUM 5.9
npm

GHSA-3q45-2fh7-66cj

Duplicate Advisory: better-auth has an external request basePath modification DoS

MEDIUM 6.5
npm

CVE-2026-58191

Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

MEDIUM 6.5
npm

CVE-2026-82864

PDFME Affected by Decompression Bomb in FlateDecode Stream Parsing Causes Memory Exhaustion DoS

MEDIUM 5.4
npm

CVE-2026-82660

Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization

MEDIUM 5.3
npm

CVE-2024-58379

nodemailer ReDoS when trying to send a specially crafted email

MEDIUM 6.5
npm

CVE-2026-82662

Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception

MEDIUM 5.4
npm

CVE-2026-82661

Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection

MEDIUM 4.4
npm

CVE-2026-82865

PDFME has XSS via Unsanitized i18n Label Injection into innerHTML in multiVariableText propPanel

MEDIUM 6.1
npm

CVE-2026-82867

Cross-Site Scripting (XSS) via Select Schema Option Value Injection in @pdfme/schemas

MEDIUM 6.8
npm

CVE-2026-82866

PDFME has SSRF via Unvalidated URL Fetch in `getB64BasePdf` When `basePdf` Is Attacker-Controlled

MEDIUM 4.9
npm

CVE-2026-82853

Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)

MEDIUM 6.1
npm

CVE-2026-82868

Cross-Site Scripting (XSS) via SVG Schema innerHTML Injection in @pdfme/schemas

MEDIUM 5.4
npm

CVE-2026-81888

@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking

MEDIUM 6.1
npm

CVE-2026-56326

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

MEDIUM 5.3
npm

CVE-2026-82256

SvelteKit: Big remote form function payloads can cause Node process to crash

MEDIUM 4.3
npm

CVE-2026-82257

SvelteKit: Prototype pollution in file input deletion path in remote-function forms

MEDIUM 6.5
npm

CVE-2026-54732

libreoffice-convert vulnerable to path traversal / arbitrary file write

MEDIUM 5.3
npm

CVE-2026-55605

@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint

MEDIUM 5.6
npm

CVE-2026-55663

mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)

MEDIUM 6.5
npm

CVE-2026-53830

OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload

MEDIUM 6.5
npm

GHSA-p68j-q8j9-jwf5

Duplicate Advisory: OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload

MEDIUM 5.3
npm

CVE-2026-54285

OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation

MEDIUM 5.7
npm

CVE-2026-53509

@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)

MEDIUM 5.7
npm

CVE-2026-33060

SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks

MEDIUM 4.1
npm

CVE-2026-63466

Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username

MEDIUM 5.5
npm

CVE-2026-63004

Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers

MEDIUM 5.4
npm

CVE-2026-59992

Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)

MEDIUM 6.5
npm

CVE-2026-63123

Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root

MEDIUM 6.5
npm

CVE-2026-69146

MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth

MEDIUM 6.7
npm

CVE-2026-55410

NocoBase backup restore schema name allows command injection

MEDIUM 5.7
npm

CVE-2026-70609

Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter

MEDIUM 6.7
npm

CVE-2026-76233

Renovate vulnerable to arbitrary command injection via gleam manager and malicious gleam.toml file

MEDIUM 6.7
npm

CVE-2026-76230

Renovate vulnerable to arbitrary command injection via npm manager and malicious Renovate configuration

MEDIUM 6.7
npm

CVE-2026-76229

Renovate vulnerable to arbitrary command injection via kustomize manager and malicious helm repository

MEDIUM 6.7
npm

CVE-2026-76231

Renovate vulnerable to arbitrary command injection via hermit manager and maliciously named dependencies

MEDIUM 5.5
npm

CVE-2026-76227

Child processes spawned by Renovate incorrectly have full access to environment variables

MEDIUM 6.7
npm

CVE-2026-76232

Renovate vulnerable to arbitrary command injection via helmv3 manager and malicious Chart.yaml file

MEDIUM 6.7
npm

CVE-2026-76228

Renovate vulnerable to arbitrary command injection via Gradle Wrapper and malicious `distributionUrl`

Ready to move

Start Securing

Free, no credit card | First findings in minutes