Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-VX52-2968-3VC6Highpnpm: pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yamlGHSA-2RX9-3G3H-C2JVHighpnpm: pnpm: pacquet trust-lockfile install can create dependency symlinks outside the projectCVE-2026-58191Medium@appium/base-driver: Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routesGHSA-GQVG-GMMX-X4HMHighmlflow: MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifactCVE-2026-73089Highbrowserslist: Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOMCVE-2026-73088Highbrowserslist: Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)GHSA-3F6P-5WW8-9RCRHighmysql2: MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext CredentialsCVE-2026-62993Mediumsmarty/smarty: Smarty: SSRF via redirect bypass of trusted_uri using {fetch}CVE-2026-69127Mediumgetkirby/cms: Kirby: System path exposure from error messages in the REST APIGHSA-RGWJ-5XJ2-C3M3Mediummysql2: MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoSCVE-2026-71415Highgetkirby/cms: Kirby: File upload permissions are not checked during processing of chunk dataCVE-2026-75594Highgetkirby/cms: Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handlingCVE-2026-45822Mediumdecode-uri-component: decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded inputCVE-2026-59724Highengine.io: Socket.IO: Engine.IO WebTransport SID DoSCVE-2026-81888Medium@hono/oauth-providers: @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linkingCVE-2026-81889Highstudio-42/elfinder: elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallbackCVE-2026-15305Mediumtypo3/cms-form: TYPO3 CMS - Unrestricted File Upload in Form FrameworkCVE-2026-55855Mediummariadb: MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsetsCVE-2026-55830HighRestrictedPython: RestrictedPython guard hooks can be shadowed via positional-only argumentsCVE-2026-55860Mediumorg.mariadb:r2dbc-mariadb: org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a…CVE-2026-55859Mediumorg.mariadb:r2dbc-mariadb: org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of OutputCVE-2026-55858Mediumorg.mariadb.jdbc:mariadb-java-client: org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output ContextCVE-2026-55857Mediumorg.mariadb.jdbc:mariadb-java-client: org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected CredentialsCVE-2026-55856Mediumorg.mariadb.jdbc:mariadb-java-client: MariaDB has cleartext password disclosure to a MITM on the initial-handshakeCVE-2026-55843Highsnipe/snipe-it: Snipe-IT has an Improper Privilege Management issue

Stop the waste.
Protect your environment with Kodem.