Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-47303HighMicrosoft.AspNetCore.Authentication.Negotiate: Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege VulnerabilityCVE-2026-50527HighSystem.Security.Cryptography.Xml: Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service VulnerabilityCVE-2026-50650HighMicrosoft.WindowsDesktop.App.Runtime.win-x64: Microsoft Security Advisory CVE-2026-50650 – .NET Elevation of Privilege VulnerabilityGHSA-8WHX-365G-H9VVLowloofah: Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character referencesGHSA-H95V-H523-3MW8Mediumguzzlehttp/guzzle: Guzzle: URI fragments disclosed in redirect Referer headersGHSA-WM3W-8RRP-J577Mediumguzzlehttp/guzzle: Guzzle: Host-only cookie scope is not preservedGHSA-F283-GHQC-FG79Mediumguzzlehttp/guzzle: Guzzle: Unbounded response cookies risk denial of serviceGHSA-8MV7-9C27-98VCMediumastro: Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misorderedGHSA-HP3V-MFQW-H74CLow@astrojs/netlify: @astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escapedCVE-2026-12590Lowbody-parser: body-parser vulnerable to denial of service when invalid limit value silently disables size enforcementCVE-2026-59730Low@astrojs/node: @astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirectCVE-2026-59729Mediumastro: Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)CVE-2026-59728Medium@astrojs/rss: @astrojs/rss: XML Injection via Unescaped RSS Feed FieldsCVE-2026-59727Lowastro: Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islandsCVE-2026-59205Highpillow: Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatchCVE-2026-59204Highpillow: Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of serviceCVE-2026-59203Mediumpillow: Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of serviceCVE-2026-59200HighPillow: Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()CVE-2026-59199HighPillow: Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflowCVE-2026-59198MediumPillow: Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated imagesCVE-2026-59197HighPillow: Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`CVE-2026-50651HighMicrosoft.NetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service VulnerabilityCVE-2026-50659MediumMicrosoft.NetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing VulnerabilityCVE-2026-50525HighSystem.Security.Cryptography.Xml: Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service VulnerabilityCVE-2026-50528HighMicrosoft.NetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability

Stop the waste.
Protect your environment with Kodem.