Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-82562Mediumqs: qs array-limit bypass via bracket-key comma parsingCVE-2026-82417Mediumqs: qs: Denial of Service via Attacker Controlled isBufferGHSA-CP6Q-959Q-F8RHMedium@tiptap/core: Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributesCVE-2026-81892Higheasycorp/easyadmin-bundle: EasyAdmin custom-action dispatcher bypasses access_control on other routesCVE-2026-81887Mediumlivewire/livewire: Livewire DOM-based cross-site scripting during client-side state handlingCVE-2026-82397Hightornado: Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loopCVE-2026-71492Mediumbanks: Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry rootCVE-2026-82398Mediumpypdf: pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespaceCVE-2026-81891HighStudio-42/elFinder: elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)CVE-2026-81890Mediumstudio-42/elfinder: elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connectionsCVE-2026-82392Highpnpm: pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraphCVE-2026-82393Highpnpm: pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on installCVE-2026-81722Mediumnltk: NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y'CVE-2026-81727Mediumnltk: NLTK: Downloader.download follows hardlinks and overwrites outside-root filesCVE-2026-81726Highnltk: NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed rootsCVE-2026-81723Mediumnltk: NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`CVE-2026-12876Mediumnltk: NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammarsCVE-2026-81724Mediumnltk: NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure…GHSA-CVHV-G4RQ-3HMWLowMagick.NET-Q16-AnyCPU: ImageMagick: Memory Leak when providing invalid options to the cliGHSA-P498-V437-472GMedium@humanfs/node: humanfs: Recursive copy follows symlinked files and copies data from outside the source treeCVE-2026-73231High@faker-js/faker: Faker: helpers.fake exploitable into arbritary code executionCVE-2026-59832Highgithub.com/siyuan-note/siyuan/kernel: Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.dbCVE-2026-59834Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: SQL Query in Block Search Exposes Hidden Published Document ContentCVE-2026-84304Highgoogle.golang.org/grpc: gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame FragmentationCVE-2026-19418Hightypo3/cms-backend: TYPO3 CMS - Broken Access Control in Backend and Install Tool

Stop the waste.
Protect your environment with Kodem.