Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-49851Highmistune: Mistune: Potential DoS via quadratic-time parsing in parse_link_textCVE-2026-49838Mediumgithub.com/osrg/gobgp/v4: GoBGP confederation validation panics on empty AS_PATH attributeCVE-2026-49837Mediumgithub.com/osrg/gobgp/v4: GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundariesCVE-2026-49836Mediumpsd-tools: psd-tools vulnerable to arbitrary file write via smart-object filenameCVE-2026-49834Mediumgithub.com/sigstore/sigstore-go: sigstore-go has a multi-log threshold bypass via single compromised logCVE-2026-53956Mediumrattler_cache: Rattler vulnerable to package cache path traversal via conda package build stringCVE-2026-55252Mediumgithub.com/openrundev/openrun: OpenRun: Redirect URL validation bypass using  //host  paths leads to Open RedirectCVE-2026-54651Mediumpypdf: pypdf: Possible infinite loop when processing threads/articles in writerCVE-2026-53639Mediumsylius/sylius: Sylius: IDOR on Shop Payment Request API endpointsCVE-2026-53638Mediumsylius/sylius: Sylius: Channel-based payment method restriction bypass on shop account orders API endpointCVE-2026-53637Mediumsylius/sylius: Sylius: Cart FormComponent allows modification or deletion of an already-completed orderCVE-2026-52778Criticalyeswiki/yeswiki: YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of ServiceCVE-2026-52777Criticalyeswiki/yeswiki: YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserializeCVE-2026-52775Highyeswiki/yeswiki: YesWiki has Authenticated SQL Injection via ReactionManager CVE-2026-52774Mediumyeswiki/yeswiki: YesWiki Vulnerable to Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML AttributesCVE-2026-52773Mediumyeswiki/yeswiki: YesWiki Vulnerable to Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php`CVE-2026-52772Mediumyeswiki/yeswiki: YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html'))CVE-2026-52771Highyeswiki/yeswiki: YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)CVE-2026-52770Highyeswiki/yeswiki: YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`/`queries` filtersCVE-2026-52769Highyeswiki/yeswiki: YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`CVE-2026-52767Highyeswiki/yeswiki: YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`

Stop the waste.
Protect your environment with Kodem.