Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-16221Highfast-uri: fast-uri vulnerable to host confusion via literal backslash authority delimiterGHSA-F88M-G3JW-G9CJHighsharp: sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591GHSA-8R6M-32JQ-JX6QHighfast-xml-parser: fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limitsGHSA-RWJ8-PGH3-R573Highgitpython: GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URLGHSA-CJ75-F6XR-R4G7Mediumrails-html-sanitizer: Rails HTML Sanitizers: Possible XSS vulnerability with certain configurationsGHSA-9MQV-5HH9-4CGGMedium@hono/node-server: Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshakeGHSA-HRXH-6V49-42GFHighgoogle.golang.org/grpc: gRPC-Go: xDS RBAC and HTTP/2 VulnerabilitiesGHSA-5QHF-9PHG-95M2Lowloofah: Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolonsGHSA-9WJQ-CP2P-HRGFMediumloofah: Loofah: SVG `href` attribute bypasses local-reference restrictionCVE-2026-59889Mediumcom.fasterxml.jackson.core:jackson-databind: jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserializationGHSA-2RP8-MM9Q-FP49Mediumtypeorm: TypeORM: migration:generate template-literal code injectionGHSA-R7WM-3CXJ-WFF9Highcom.fasterxml.jackson.core:jackson-core: jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)CVE-2026-20779Highcode.gitea.io/gitea: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surfaceCVE-2026-58429Mediumcode.gitea.io/gitea: Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission EndpointsCVE-2026-59765Mediumcode.gitea.io/gitea: Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud MetadataCVE-2026-58511Lowcode.gitea.io/gitea: Gitea: Webhook Authorization Header Returned in Plaintext via APICVE-2026-57897Mediumcode.gitea.io/gitea: Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIsCVE-2026-58510Mediumcode.gitea.io/gitea: Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->privateCVE-2026-58431Mediumgitea.dev: Gitea: Public-only API token restriction is not enforced on team API routesCVE-2026-58427Mediumgitea.dev: Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145CVE-2026-58422Highcode.gitea.io/gitea: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accountsCVE-2026-58419Highcode.gitea.io/gitea: Gitea: Notification API leaks private issue metadata after access revocationCVE-2026-25038Highcode.gitea.io/gitea: Gitea: Unauthorized Access to Labels of Private OrganizationsCVE-2026-27775Highcode.gitea.io/gitea: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository WriteCVE-2026-24451Highcode.gitea.io/gitea: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private

Stop the waste.
Protect your environment with Kodem.