Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-75596Mediumio.netty:netty-handler: Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsingCVE-2026-71494Mediumgithub.com/infracost/infracost: Infracost: Terraform Cloud and registry token disclosure via unvalidated hostnameCVE-2026-71493Mediumgithub.com/infracost/infracost: Infracost: Arbitrary file read via config-template readFile symlink traversalCVE-2026-73087Lowgithub.com/amir20/dozzle: Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcherCVE-2026-69222Highliquidjs: LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the processCVE-2026-73262Mediumprowler: Prowler: Stored XSS in HTML reports through unescaped cloud resource tagsCVE-2026-85063Mediumcsv-parse: node-csv: Prototype replacement still reachable via columns pathCVE-2026-72925Medium@swc/html: SWC HTML minifier may allow script element breakout when minifying embedded JSONCVE-2026-73294Criticalgithub.com/semaphoreui/semaphore: Semaphore U: OS Command InjectionCVE-2026-60004Criticalgitea.dev: Gitea: Remote Code Execution via diffpatch Git Hook InstallationCVE-2026-72789Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully…CVE-2026-72790Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by…GHSA-57V5-WQX3-CGJ4Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by…CVE-2026-79674Highnltk: NLTK: Corpus Reader Sandbox BypassCVE-2026-79676Highnltk: NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcementCVE-2026-79657Criticalnltk: NLTK: Allowlisted pickle loaders still permit code execution in current sourceCVE-2026-78681Highnltk: NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parsesCVE-2026-78682Highnltk: NLTK: pathsec SSRF protection can be bypassed when a proxy is configuredCVE-2026-78683Criticalnltk: NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code ExecutionCVE-2026-62383Mediumnltk: NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirelyCVE-2026-62384Highnltk: NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)CVE-2026-62385Highnltk: NLTK: Stable FrameNet and NKJP readers parse outside-root XMLCVE-2026-12259Mediumnltk: NLTK: Missing Post-Download Integrity Verification Allows Malicious Package InjectionCVE-2026-63312Highnltk: NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File ReadCVE-2026-65915Mediumnltk: NLTK: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol

Stop the waste.
Protect your environment with Kodem.