Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-61842Mediumgetgrav/grav: Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)CVE-2026-61690Mediumgetgrav/grav: Grav: Decompression Bomb via ZipArchiver - Missing Extraction LimitsCVE-2026-61704Highlink-preview-js: link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897CVE-2026-75931Highfast-uri: fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative referencesCVE-2026-75975Highfast-uri: fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizationCVE-2026-75899Highfast-uri: fast-uri vulnerable to server-side request forgery via repeated hostname percent-decodingCVE-2026-76172Highfast-uri: fast-uri vulnerable to host confusion via percent-encoded scheme normalizationCVE-2026-62388Highnltk: NLTK: Default ENFORCE=False Disables All pathsec Security ControlsCVE-2026-63311Mediumnltk: NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution FailureCVE-2026-83610Medium@xmldom/xmldom: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serializationCVE-2026-76098Highmistune: Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in MarkdownCVE-2026-16732Mediumfastify: fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-countCVE-2026-18504Mediumfastify: fastify vulnerable to schema validation bypass via root primitive coercion mismatchCVE-2026-71553Highapostrophe: ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoSCVE-2026-82396Mediumsulu/sulu: Sulu: Stored XSS via media download inline-disposition overrideCVE-2026-82394Mediumsulu/sulu: Sulu: Fix authorization bypass when creating preview linksCVE-2026-82395Mediumsulu/sulu: Sulu: Media move/update authorization bypass (IDOR)CVE-2026-63667Medium@apostrophecms/import-export: ApostropheCMS: Arbitrary file read via import-export attachment-name path traversalCVE-2026-75592Mediumgetkirby/cms: Kirby: Access to image files outside of the site root via path traversal in the media handlingCVE-2026-62680Highorval: Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $refCVE-2026-72716Criticalorval: Orval: Import-time RCE via query-parameter default -> zod module-level template literalCVE-2026-71866Criticalorval: Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod clientCVE-2026-73845Medium@aborruso/ckan-mcp-server: CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)CVE-2026-72920Criticalgithub.com/seaweedfs/seaweedfs: SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative controlCVE-2026-64850Highgetgrav/grav: Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()

Stop the waste.
Protect your environment with Kodem.