Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-F25V-X6VR-962GCriticalpheditor/pheditor: Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current PasswordCVE-2026-14257Highbrace-expansion: brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashCVE-2026-64785Mediumswift-nio-http2: swift-nio-http2: Missing CR/LF/NUL validation in header valuesGHSA-VH45-F885-3848Criticalsm-crypto: sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clockGHSA-V6W6-358X-2433Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve Admin.Read OAuth tokens can trigger server-side node test requestsGHSA-47W6-GWP4-W6VCHighvantage6: vantage6: Algorithm developer can edit another developer's algorithm that is pending / under reviewGHSA-2625-RW7M-5Q5XLowhubuum_client: Hubuum client library (Rust): Sensitive data may be exposed through default diagnosticsGHSA-QQC3-94QV-7FW3Mediumhubuum_client: Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network trafficGHSA-F45Q-W629-WR25Mediumhubuum_client: Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirectsGHSA-26GQ-P25F-99CPHighgithub.com/fatedier/frp: frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer OverflowGHSA-G5VV-Q72C-7J78High@anephenix/hub: @anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource ExhaustionGHSA-C534-2W9C-X7FMMediumgithub.com/zxh326/kite: Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resourcesGHSA-P279-2CQP-84JGCriticalorg.openidentityplatform.opendj:opendj-server-legacy: OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope checkGHSA-68R5-9HPG-7QW9Criticalorg.openidentityplatform.opendj:opendj-dsml-servlet: OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gatewayGHSA-G3HQ-HPHG-8FHHHighpheditor/pheditor: Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization…GHSA-94P4-4CQ8-9G67HighGitPython: GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)GHSA-HFHX-W8P8-4HC7Medium@budibase/server: Budibase: SSRF via bare fetch() in uploadUrl during AI table generationGHSA-V42F-V8XC-J435High@budibase/server: Budibase: SSRF via DNS rebinding in the REST datasource integrationGHSA-PMPG-2MXQ-6XWRHigh@budibase/server: Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/deleteGHSA-CR7P-CR3Q-H5CMMedium@budibase/server: Budibase: Account Enumeration via Login Lockout Response DifferentialGHSA-PVCR-8MVP-W8QRHigh@budibase/server: Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)GHSA-2XGG-R2WC-C5R2High@budibase/server: Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database ConnectorGHSA-QW6M-8FW2-2V64High@budibase/server: Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query ExecutionGHSA-GH4H-34GR-87R7Medium@budibase/server: Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other BuildersGHSA-HR66-5MQR-8MPXHigh@budibase/server: Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint

Stop the waste.
Protect your environment with Kodem.