Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-48118Highnukeviet/nukeviet: NukeViet: Unauthenticated Reflected XSS in Comment ModuleCVE-2026-45579CriticalDIRAC: DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted inputCVE-2026-45573Mediumdecidim-core: Decidim: Push subscriptions can be abused for server-side requestsCVE-2026-45572Mediumdecidim-core: Decidim: HTML content blocks allow stored script executionCVE-2026-45415Mediumdecidim-verifications: Decidim: CSV census record endpoints improper authorizationCVE-2026-45414Highdecidim: Decidim: JWT-backed authentication can be replayed across organizationsCVE-2026-45378Highdecidim-verifications: Decidim: Verification documents can be downloaded through reusable linksCVE-2026-45377Mediumdecidim-core: Decidim: Private exports can be downloaded through reusable linksCVE-2026-45376Mediumdecidim-admin: Decidim: Admin user search allows SQL injection through similarity-based sortingCVE-2026-45330Mediumdecidim-verifications: Decidim: Verification admins can access supplied IDs from other organizationsCVE-2026-45086Mediumdecidim-demographics: Decidim: Forms admin question editor lacks authorizationCVE-2025-32781Mediumcom.ctrip.framework.apollo:apollo: Apollo Portal: There is a risk of unauthorized access to the Apollo configuration centerCVE-2024-27091Mediumgeonode: GeoNode: Stored XSS to full account takeoverGHSA-G936-7JQJ-MWV8Criticalgithub.com/almeidapaulopt/tsdproxy: TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalationCVE-2026-54174Highchainguard.dev/apko: melange: Incomplete package integrity verification allows data section substitutionCVE-2026-54171Mediumexcon: Excon does not redact additional sensitive/risky headers when following redirectsGHSA-H4G2-XFMW-Q2C9Highclauster: Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unsetCVE-2026-54163Mediumsecure_headers: Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted inputCVE-2026-50551Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell ContentCVE-2026-54159Criticalprestashop/ps_facetedsearch: prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCECVE-2026-54158Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()GHSA-G5R6-GV6M-F5JVHighmcp-atlassian: mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachmentGHSA-WM45-QH3G-V83FHighmcp-atlassian: mcp-atlassian: Arbitrary server-side file read via attachment uploadGHSA-XRMC-C5CG-RV7XHighsafeinstall-cli: SafeInstall agent guard shell parsing can miss raw package executionGHSA-QV4M-M73M-8HJ7Highnotrinos/notrinos-erp: NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)

Stop the waste.
Protect your environment with Kodem.