Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-64868Highgithub.com/QuantumNous/new-api: New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body loggingCVE-2026-64859Criticalgithub.com/QuantumNous/new-api: New API: User List API Leaks Root User Access Token Leading to Privilege EscalationCVE-2026-53728High@medplum/core: Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code LeakageCVE-2026-55158Criticalwktk/conflibot: conflibot vulnerable to command injection via crafted pull request branch names under pull_request_targetCVE-2026-40345Highdeepmerge-ts: DeepmergeTS has stack exhaustion when merging recursive object graphsCVE-2026-10740Mediums2n-quic: s2n-quic has excessive memory allocationCVE-2026-55156Medium@ooples/token-optimizer-mcp: Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API EndpointsCVE-2026-55157High@ooples/token-optimizer-mcp: Token Optimizer MCP: OS command injection in smart_user via username in get-user-infoCVE-2026-53708Mediummcp-contextforge-gateway: ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)GHSA-8RW6-P7M8-63JPMediumsurrealdb: SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record usersCVE-2026-55153Highcom.mchange:mchange-commons-java: mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"CVE-2026-53660Highorg.openidentityplatform.openam:openam-core: OpenAM Insecure SSO Cookie InitializationCVE-2026-53658Mediumgithub.com/hyperledger/fabric-ca: Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser FilterCVE-2026-53657Highgithub.com/lima-vm/lima/v2: Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socketCVE-2026-53653Highgetgrav/grav: Grav: Unauthenticated denial of service via unbounded image derivative dimensionsCVE-2026-35219High@budibase/server: Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP BlacklistCVE-2026-35511Highgithub.com/authorizerdev/authorizer: Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accountsCVE-2026-73654High@trigger.dev/core: Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoSCVE-2026-12243Highnltk: nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded SequencesCVE-2026-73559Mediumvllm: vLLM: Completion prompt lists fan out into unbounded engine requestsGHSA-RM43-82J9-R4MJHighatomic-agents-stack: atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file readCVE-2026-54249Mediumpydantic-ai-slim: Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentialsCVE-2026-54526Highgithub.com/argoproj/argo-workflows/v4: Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)CVE-2026-55102Mediumhashi-vault-js: hashi-vault-js: Vault token and secret values exposed in thrown errorsCVE-2026-55088Mediumep_etherpad-lite: ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token

Stop the waste.
Protect your environment with Kodem.