Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-56812Mediumphoenix: Phoenix: Presence keys colliding with `Object.prototype` members break existence checksCVE-2026-71429Mediumstream-json: stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for…CVE-2026-69084Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle,…CVE-2026-79921Highgithub.com/rabbitmq/amqp091-go: amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized PayloadCVE-2026-63670Mediumsanitize-html: ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus closeCVE-2026-63669Mediumapostrophe: ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a…CVE-2026-73295Mediummkdocs-material: Material for MkDocs: DOM XSS in search suggestions via query parameterCVE-2026-82404High@toon-format/toon: TOON: Prototype pollution when decoding untrusted TOON inputCVE-2026-73222Highclaude-code-templates: Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)CVE-2026-73293Highgithub.com/semaphoreui/semaphore: Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collisionCVE-2026-73292Highgithub.com/semaphoreui/semaphore: Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmationCVE-2026-62681Criticalorval: Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)CVE-2026-62682Criticalorval: Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)CVE-2026-72717Criticalorval: Orval: Import-time RCE via schema default -> zod module-level template literalCVE-2026-71869Criticalorval: Orval: Import-time RCE via array-items default -> zod module-level template literalCVE-2026-71871Criticalorval: Orval: Import-time RCE via header-parameter default -> zod module-level template literalCVE-2026-71867Criticalorval: Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generatorCVE-2026-71868Criticalorval: Orval: Import-time RCE via enum-typed default -> zod module-level template literalCVE-2026-71865Criticalorval: Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cliCVE-2026-71864Criticalorval: Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod clientCVE-2026-73232Highgithub.com/ffuf/ffuf/v2: ffuf denial of service (OOM) via HTTP response decompression bombCVE-2026-61625Mediumgithub.com/VictoriaMetrics/VictoriaMetrics: VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore rootCVE-2026-61556Highliquidjs: LiquidJS has an infinite loop vulnerability in its `strip_html` filterCVE-2026-75602Mediumgithub.com/OpenListTeam/OpenList: OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download toolGHSA-W8WF-3QVJ-6XQFHigh@openclaw/feishu: OpenClaw Feishu permission tools could ignore per-account disablement

Stop the waste.
Protect your environment with Kodem.