Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-8QQM-FP2Q-V734Highgithub.com/zalando/skipper: Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policiesCVE-2026-54246Mediumgithub.com/zalando/skipper: Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack AuthenticationCVE-2026-55177High@tak-ps/cloudtak: CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guardCVE-2026-54559Mediumpocketsphinx: PocketSphinx: Buffer overflows in language and acoustic model loading codeCVE-2026-54570MediumAngleSharp: AngleSharp HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point BypassGHSA-MFR4-MQ8W-VMG6Mediumproot-distro: PRoot-Distro has Path Traversal in proot-distro copy — Arbitrary Read, Write, and Persistent Code Execution Outside Container RootfsCVE-2026-53496Mediumexifreader: ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxesCVE-2026-54567HighFlask-Reuploaded: Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)CVE-2026-53597High@prompty/core: Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loaderCVE-2026-53598Highprompty: Prompty: Arbitrary file read via file reference expansionCVE-2026-54561Mediummcp-memory-keeper: mcp-memory-keeper: Arbitrary local file read in context_import via unvalidated filePathGHSA-CVPC-HCCG-WMW4Mediumverbb/formie: Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configurationCVE-2026-27771Highcode.gitea.io/gitea: Gitea has insufficient permission checks for Composer package source linksCVE-2026-54546Medium@tak-ps/cloudtak: TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guardGHSA-RJWR-M7QX-3FJRLowgithub.com/oapi-codegen/oapi-codegen/v2: oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable CodeCVE-2026-54547Highmeta-ads-mcp: meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta TokenCVE-2026-54549Highmeta-ads-mcp: meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` FetchCVE-2026-54552Highsh: sh _uid does not drop supplementary groups (incomplete privilege drop)CVE-2026-11400Highsoftware.amazon.jdbc:aws-advanced-jdbc-wrapper: AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instanceGHSA-8RQH-VXPR-X77PMediumplone.restapi: plone.restapi: Stored XSS by spoofing mime typeCVE-2026-54503Mediumplone.app.textfield: plone.app.textfield: Stored XSS by spoofing mime type CVE-2026-54247Mediumgithub.com/zalando/skipper: Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoSCVE-2026-55646Mediumvllm: vLLM: Speech-to-text upload size limit is enforced after full UploadFile readCVE-2026-55574Highvllm: vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backendsCVE-2026-54234Highvllm: vLLM has Remote DoS via Invalid Recovered Token Reinjection

Stop the waste.
Protect your environment with Kodem.