Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55798MediumPillow: Pillow: WindowsViewer.get_command() OS command injection via unescaped shell pathCVE-2026-55380Highpillow: Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`CVE-2026-55379Highpillow: Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loadingCVE-2026-54060Highpillow: Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`CVE-2026-54059Highpillow: Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF…GHSA-4G3V-8H47-V7G6Mediumastro: Astro: Reflected XSS via unescaped View Transition animation propertiesCVE-2026-54058Highpillow: Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)CVE-2026-53515High@better-auth/sso: @better-auth/sso: SSO provider may allow registration for any org member without a checking their roleCVE-2026-13149Highbrace-expansion: brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsCVE-2026-59948Highcomposer/composer: Composer: Arbitrary file write outside vendor via malicious transitive package nameCVE-2026-55514Highvllm: vLLM denial of service via prompt embeds on M-RoPE modelsCVE-2026-28231Mediumpi-heif: pillow-heif: Integer Overflow in Encode Path Buffer Validation Leads to Heap Out-of-Bounds ReadCVE-2026-25527Mediumchangedetection.io: changedetection.io is vulnerable to unauthenticated static path traversalCVE-2025-67726Hightornado: Tornado: Quadratic DoS via Crafted Multipart ParametersCVE-2025-67725Hightornado: Tornado: Quadratic DoS via Repeated Header CoalescingCVE-2025-67724Mediumtornado: Tornado vulnerable to Header Injection and XSS via reason argumentGHSA-42H9-826W-CGV3Mediumaxios: Axios: Excessive recursion in formDataToJSON can cause denial of serviceGHSA-XJ6Q-8X83-JV6GMediumaxios: Axios: Prototype pollution auth subfields can inject Basic authGHSA-PMV8-RQ9R-6J72Mediumaxios: Axios: Deep formToJSON Key Recursion Can Cause Denial of ServiceGHSA-8QQM-FP2Q-V734Highgithub.com/zalando/skipper: Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policiesCVE-2026-54246Mediumgithub.com/zalando/skipper: Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack AuthenticationCVE-2026-55177High@tak-ps/cloudtak: CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guardCVE-2026-54559Mediumpocketsphinx: PocketSphinx: Buffer overflows in language and acoustic model loading codeCVE-2026-54570MediumAngleSharp: AngleSharp HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point BypassGHSA-MFR4-MQ8W-VMG6Mediumproot-distro: PRoot-Distro has Path Traversal in proot-distro copy — Arbitrary Read, Write, and Persistent Code Execution Outside Container Rootfs

Stop the waste.
Protect your environment with Kodem.