Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55579Criticalpheditor/pheditor: Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromiseCVE-2026-55578Highpheditor/pheditor: Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injectionCVE-2026-52724Mediumgithub.com/kumahq/kuma/v2: kuma-dp connects to control plane without verifying TLS certificate when no CA is configuredCVE-2026-54076Highcom.arcadedb:arcadedb-engine: ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)CVE-2026-54077Highcom.arcadedb:arcadedb-engine: ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated usersCVE-2026-54542Lownimiq-primitives: nimiq-primitives: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in a deserialized proofCVE-2026-54541Lownimiq-primitives: nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keysCVE-2026-54540Highpheditor/pheditor: Pheditor has an authenticated terminal command whitelist bypassCVE-2026-52869Highmcp: MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principalCVE-2026-52870Highmcp: MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasksCVE-2026-52832Mediumgithub.com/nuclio/nuclio: Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard containerCVE-2026-52833Highgithub.com/nuclio/nuclio: Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCECVE-2026-53714Highgithub.com/envoyproxy/gateway: Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode GHSA-GGXF-9F6J-W742Mediumdiesel: Diesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`CVE-2026-53713Criticalgithub.com/envoyproxy/gateway: Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret DisclosureCVE-2026-53715Mediumgithub.com/envoyproxy/gateway: Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lockCVE-2026-53717Mediumgithub.com/envoyproxy/gateway: Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar headerCVE-2026-53719Mediumgithub.com/envoyproxy/gateway: Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorizationCVE-2026-53716Mediumgithub.com/envoyproxy/gateway: Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limitCVE-2026-53718Mediumgithub.com/envoyproxy/gateway: Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypassCVE-2026-50166Mediumgithub.com/kumahq/kuma/v2: kumactl connects to control plane without verifying TLS certificate when no CA is configuredCVE-2026-58196Lowgithub.com/stacklok/toolhive: ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)GHSA-XG43-5579-QW6VMediumadawolfa/isdoc: adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF filesCVE-2026-54504High@andrea9293/mcp-documentation-server: @andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by defaultCVE-2026-50289Highsysteminformation: systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux

Stop the waste.
Protect your environment with Kodem.