Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-50648HighSystem.Security.Cryptography.Xml: Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service VulnerabilityCVE-2026-50524HighMicrosoft.NetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service VulnerabilityCVE-2026-47304HighSystem.Security.Cryptography.Xml: Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass VulnerabilityCVE-2026-47302HighSystem.Security.Cryptography.Xml: Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service VulnerabilityCVE-2026-57108HighMicrosoft.NetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service VulnerabilityGHSA-GCFJ-64VW-6MP9Highaxios: Axios Node HTTP adapter can use an inherited proxy after interceptor config cloningGHSA-HCPX-6FM6-WX23Mediumaxios: Axios form serializer maxDepth bypass via {} metatokenGHSA-7Q8Q-RJ6J-MHJQMediumaxios: Axios: Nested axios option objects can consume polluted prototype valuesGHSA-MWF2-3PR3-8698Mediumaxios: Axios: HTTP/2 streamed uploads bypass `maxBodyLength`GHSA-JQH4-M9W3-8HP9Mediumaxios: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`GHSA-MMX7-HFXF-JPPXMediumaxios: Axios: Prototype pollution gadgets can alter axios request constructionGHSA-F4GW-2P7V-4548Mediumaxios: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axiosCVE-2026-62685Highgithub.com/filebrowser/filebrowser/v2: File Browser: Colliding username normalization gives two users the same home directoryCVE-2026-62684Lowgithub.com/filebrowser/filebrowser/v2: File Browser: Share API exposes the password hash and bypass tokenCVE-2026-62843Mediumgithub.com/filebrowser/filebrowser/v2: File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)CVE-2026-59876Mediumprotobufjs: protobufjs: Text Format string map parsing can mutate returned map object prototypeCVE-2026-59877Mediumprotobufjs: protobufjs: Denial of Service via infinite loop in .proto option parsingCVE-2026-14631Mediumwebpack-dev-server: webpack-dev-server vulnerable to denial of service via a malformed Host or Origin headerCVE-2026-14620Mediumwebpack-dev-server: webpack-dev-server vulnerable to cross-site request forgery via internal developer endpointsCVE-2026-59883Mediumguzzlehttp/guzzle: Guzzle: Cookie Disclosure and Injection via IP-Address DomainsCVE-2026-59731Highastro: Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization MismatchCVE-2026-59946Mediumcomposer/composer: Composer: Path traversal in package bin field lets dependencies chmod arbitrary host filesCVE-2026-59947Mediumcomposer/composer: Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)CVE-2026-59871Mediumtar: node-tar: Process crash via PAX numeric path type confusionCVE-2026-59873Criticaltar: node-tar: Decompression/parse DoS via unlimited input

Stop the waste.
Protect your environment with Kodem.