Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-53603Highgithub.com/forgekeep/nebula-mesh: nebula-mesh: Operator session tokens stored in plaintext in the databaseCVE-2026-44891Highio.netty:netty-codec-stomp: Netty: Denial of Service via Unbounded Headers in StompSubframeDecoderCVE-2026-53604Highgithub.com/forgekeep/nebula-mesh: nebula-mesh: CA private key not zeroized on web mobile-bundle error pathsCVE-2026-54628Highgithub.com/julien040/anyquery: Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server ModeGHSA-Q3V2-XJ35-9GRXMediumUmbraco.AI: Umbraco.AI discloses sensitive application configuration valuesGHSA-MQXV-9RM6-W8QCHighgithub.com/lin-snow/ech0: Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.MiddlewareGHSA-9HC2-HJX8-Q6PVCriticaltidgi: TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-ExecutionCVE-2026-54448Highgithub.com/aquasecurity/trivy: Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parserCVE-2026-54087Higheasycorp/easyadmin-bundle: EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageFieldGHSA-PQG7-V6WH-3PFPHighgithub.com/almeidapaulopt/tsdproxy: TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend servicesCVE-2026-54335Low@feathersjs/commons: Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__CVE-2026-50158Highgithub.com/eat-pray-ai/yutu: yutu: Arbitrary File Write via MCP `caption-download` ToolCVE-2026-50157Mediumauth0/symfony: Auth0 Symfony SDK Accepted Bearer Tokens via URL Query ParameterCVE-2026-54052Criticaln8n-mcp: n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deploymentsCVE-2026-50141Highgo.woodpecker-ci.org/woodpecker/v3: Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonationCVE-2026-50006Criticalgithub.com/julien040/anyquery: Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server ModeCVE-2026-50131High@fedify/fedify: Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 rangesCVE-2026-50125Highgithub.com/StacklokLabs/mkp: MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory ExhaustionCVE-2026-50018Mediumgithub.com/SpectoLabs/hoverfly: Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve ActionsCVE-2026-50013Highgithub.com/SpectoLabs/hoverfly: Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff ModeCVE-2026-54250Mediumgithub.com/k3s-io/k3s: K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot DecompressionCVE-2025-61670Lowwasmtime-c-api-impl: Wasmtime: Memory leak in C API with `externref` and `anyref` typesCVE-2026-45710Lowfacturascripts/facturascripts: FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes…CVE-2026-45263Highfacturascripts/facturascripts: FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens…CVE-2026-45693Highfacturascripts/facturascripts: FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents

Stop the waste.
Protect your environment with Kodem.