Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-2Q7J-2VHX-56G8High@openclaw/feishu: OpenClaw Feishu tools could ignore per-account disablementCVE-2026-56743Mediumgithub.com/cilium/cilium: Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock matchCVE-2026-71428Criticalunstructured: unstructured: Server-Side Request Forgery in the URL-based partitioningGHSA-GW25-M53R-QH88Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)GHSA-99RQ-75J6-5J9FHighgithub.com/siyuan-note/siyuan/kernel: SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypassCVE-2026-73846Medium@aborruso/ckan-mcp-server: CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoningCVE-2026-73844Low@aborruso/ckan-mcp-server: CKAN MCP Server: Information disclosure via verbose error reflectionCVE-2026-73667Highgithub.com/openchoreo/openchoreo: OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged podsCVE-2026-73840Mediumgithub.com/openchoreo/openchoreo: OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)CVE-2026-73841Highgithub.com/openchoreo/openchoreo: OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpointsCVE-2026-73843Criticalgithub.com/openchoreo/openchoreo: OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIsCVE-2026-67445Highgithub.com/axllent/mailpit: Mailpit: SMTP command parser buffers unbounded command lines before syntax rejectionCVE-2026-72921Highgithub.com/seaweedfs/seaweedfs: SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling pathsCVE-2026-67446Highgithub.com/axllent/mailpit: Mailpit: Thumbnail generation decodes unbounded image dimensions before scalingCVE-2026-84366Highscrapy: Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by defaultCVE-2026-68921Medium@dicebear/core: DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)CVE-2026-62676Highomnigent: Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.pyCVE-2026-65842High@platejs/docx-io: Plate: SSRF with response disclosure in DOCX image embeddingCVE-2026-63490Highcom.github.jknack:handlebars-springmvc: Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypassCVE-2026-63481Mediumhurl: Hurl: Cookies in Cookies section leak when redirecting to a different hostCVE-2026-63435Mediummail: Mail: Email address spoofing via malformed RFC 2047 encoded-wordsCVE-2026-62669Highgetgrav/grav: Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending ChallengeCVE-2026-62677Highomnigent: Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACECVE-2026-62674Criticalomnigent: Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCECVE-2026-62675Highomnigent: Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools

Stop the waste.
Protect your environment with Kodem.