Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-59817Mediumghost: Ghost: Paid gift memberships obtainable at minimal cost via the donations featureCVE-2026-53947Mediumghost: Ghost: Member existence leak via magic link sign-in responseCVE-2026-53950High@tryghost/activitypub: XSS in Ghost's ActivityPub clientCVE-2026-70594Mediumghost: Ghost: Session Fixation in Ghost AdminCVE-2026-70593Mediumghost: Ghost: Theme Upload Path TraversalCVE-2026-70592Mediumghost: Ghost: Database Backup Path TraversalCVE-2026-70591Mediumghost: Ghost: Server-Side Request Forgery in Image FetchingCVE-2026-70590Mediumghost: Ghost: Blind Password Hash Disclosure in Ghost Admin APICVE-2026-53946Mediumghost: Ghost: Mobiledoc image-size fetch SSRFCVE-2026-53945Mediumghost: Ghost: Server-side request forgery via DNS rebinding in external request handlingCVE-2026-53944Mediumghost: Ghost: Private IP filtering bypass to make server-side requests to internal servicesCVE-2026-70589Mediumghost: Ghost: Archived Offers can be RedeemedCVE-2026-53948Mediumghost: Ghost: File Upload Content-Type SpoofingCVE-2026-70588Mediumghost: Ghost: Cross-Site Scripting in Universal ImportCVE-2026-70494Highopen-webui: Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolderCVE-2026-70493Mediumopen-webui: Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophicallyCVE-2026-70492Highopen-webui: Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messagesCVE-2026-70491Mediumopen-webui: Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpointsCVE-2026-70490Mediumopen-webui: Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role checkCVE-2026-70489Mediumopen-webui: Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsingCVE-2026-54020Mediumopen-webui: Open WebUI: DNS Rebinding SSRF BypassCVE-2026-70487Mediumopen-webui: Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadataCVE-2026-70488Mediumopen-webui: Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanupCVE-2026-70486Highopen-webui: Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-originCVE-2026-70485Highopen-webui: Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs

Stop the waste.
Protect your environment with Kodem.