Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-52882Mediummantisbt/mantisbt: MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From UpdatersCVE-2026-52881Criticalmantisbt/mantisbt: MantisBT: Reflected XSS in admin/install.php via unescaped printf CVE-2026-52847Criticalmantisbt/mantisbt: MantisBT: Reflected XSS in admin/install.phpCVE-2026-54494Mediumphanan/koel: Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16)…CVE-2026-50552Mediumphanan/koel: Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bailCVE-2026-54491Highphanan/koel: Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch pathsCVE-2026-54449Highlangbot: LangBot: Authenticated RCE Via MCP ConfigurationCVE-2026-54447Highgarminconnect: garminconnect Has Insecure Permission Assignment for Garmin OAuth Token StoreGHSA-8Q6Q-M837-FV64Mediumphanan/koel: Koel has SSRF through Authenticated Subsonic podcast feed URLsCVE-2026-54493Highphanan/koel: Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio StationsCVE-2026-54492Mediumphanan/koel: Koel: Authenticated Blind SSRF via Subsonic Podcast Channel CreationCVE-2026-49280Mediummantisbt/mantisbt: MantisBT: REST API unauthorized Issue status changeCVE-2026-49273Highmantisbt/mantisbt: MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.phpCVE-2026-47156Criticalmantisbt/mantisbt: MantisBT: SOAP API Authentication Bypass with Privilege Escalation to AdministratorCVE-2026-47142Highmantisbt/mantisbt: MantisBT: SQL Injection via history_order Configuration ValueGHSA-HGJX-R89M-M7V4Criticalfacturascripts/facturascripts: FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCECVE-2026-54446Highnetlicensing-mcp: NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP ModeCVE-2026-61549Highgo.woodpecker-ci.org/woodpecker/v3: Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backendGHSA-7RX3-5WX3-5V76Highgithub.com/forgekeep/nebula-mesh: Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`CVE-2026-61699Highgithub.com/forgekeep/nebula-mesh: nebula-mesh: Certificate revocation is never enforced at the meshCVE-2026-55608Mediumn8n-mcp: n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP modeCVE-2026-55513Mediumgithub.com/forgekeep/nebula-mesh: nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokensCVE-2026-55512Mediumgithub.com/forgekeep/nebula-mesh: nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limitingCVE-2026-54629Highgithub.com/julien040/anyquery: Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode

Stop the waste.
Protect your environment with Kodem.