Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-54071HighBabelDOC: BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.pyCVE-2026-54088Criticalgithub.com/filebrowser/filebrowser/v2: File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)GHSA-99J7-FHR2-XFJ4Criticalexploration: `exploration` was removed from crates.io for malicious codeCVE-2026-54136Mediumwindmill-api: Windmill: Resource-scoped API tokens can read script contents outside their allowed path via scripts/list_searchCVE-2026-54070Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Stored XSS in Bazaar marketplace via package README event handlersCVE-2026-54089Criticalgithub.com/filebrowser/filebrowser/v2: File Browser: Authentication Bypass via Proxy Auth Header ForgeryCVE-2026-54069Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin AllowlistCVE-2026-54068Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIconGHSA-9MQM-QCWF-5QHGMediumcredsweeper: CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resourcesCVE-2026-54063Highgithub.com/xuri/excelize/v2: Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)CVE-2026-54072Criticalgithub.com/authorizerdev/authorizer: Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URLCVE-2026-54067Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()CVE-2026-54066Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894 CVE-2026-39244Highadm-zip: adm-zip: Crafted ZIP file triggers 4GB memory allocationGHSA-489G-7RXV-6C8QMediummcp-atlassian: MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)CVE-2026-49977Mediumtarteaucitronjs: tarteaucitron: data-cookie attribute can be used to delete arbitrary cookiesCVE-2026-49866High@libp2p/gossipsub: libp2p: CPU DoS via oversized IHAVE and IWANT control message arraysCVE-2026-49865Mediumkimai/kimai: Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLsCVE-2026-5078Mediummorgan: morgan vulnerable to Log Forging via unneutralized control characters in :remote-userCVE-2026-49858Mediumapi-platform/core: API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate

Stop the waste.
Protect your environment with Kodem.