Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-45262Criticalfacturascripts/facturascripts: FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`CVE-2026-44300Highgithub.com/opencost/opencost: OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/InjectionCVE-2026-52828Mediumkimai/kimai: Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD AccessCVE-2026-52827Highkimai/kimai: Kimai: Pre-2FA KIMAI_SESSION cookie grants full authenticated REST API access, bypassing TOTPCVE-2026-52826Mediumkimai/kimai: Kimai: Improper Authorization in Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate ManipulationCVE-2026-52825Mediumkimai/kimai: Kimai has Improper Authorization in Team Member and Team Activity Assignment APIs Which Allows Expansion of Team Scope Beyond Authorized…CVE-2026-52824Criticalkimai/kimai: Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account TakeoverCVE-2026-52823Mediumkimai/kimai: Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State ChangesCVE-2026-52822Mediumkimai/kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access RevocationCVE-2026-52821Mediumkimai/kimai: Kimai: Improper Authorization Through Activity Creation with Preset Project Allows Creation Under Unauthorized ProjectsCVE-2026-52820Mediumkimai/kimai: Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypassCVE-2026-52819Mediumkimai/kimai: Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the…CVE-2026-49992Mediumkimai/kimai: Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure ChangesGHSA-8F6J-263M-G72XMediumapp-store-server-library: Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checksGHSA-XF7X-X43H-RPQHHighjson-repair: json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoSCVE-2026-47677Criticalfacturascripts/facturascripts: FacturaScripts: Account takeover of any 2FA-enabled userGHSA-7XW9-549R-8JRCHighDIRAC: DIRAC: SQL injection and lack of access control in PilotManager serviceCVE-2026-61668HighDIRAC: DIRAC: Pilot code downloaded over unverified HTTPS connectionCVE-2026-61667CriticalDIRAC: DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + evalCVE-2026-59955Highcom.ctrip.framework.apollo:apollo: Apollo ConfigService access key authentication bypass via raw config file appId parsingCVE-2026-59954Highcom.ctrip.framework.apollo:apollo: Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matchingCVE-2026-55372Highnukeviet/nukeviet: NukeViet: Pre-authentication SSRF via X-Forwarded-HostCVE-2026-54065Highnukeviet/nukeviet: NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment FunctionCVE-2026-54064Highnukeviet/nukeviet: NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News ModuleCVE-2026-49259Highnukeviet/nukeviet: NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Stop the waste.
Protect your environment with Kodem.