Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-52766Criticalyeswiki/yeswiki: YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` actionCVE-2026-52763Mediumyeswiki/yeswiki: YesWiki: SQL injection via the `recentchanges` action `period` argument leads to arbitrary DB readCVE-2026-52762Highyeswiki/yeswiki: YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic TemplatesCVE-2026-53769Mediumavo: Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policyCVE-2026-53932Highwnx/laravel-backup-restore: laravel-backup-restore has an OS Command Injection during database restoreCVE-2026-53602Mediumgithub.com/forgekeep/nebula-mesh: nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificateGHSA-382C-VX95-W3P5Medium@jsonbored/gittensory-mcp: Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial dataCVE-2026-53760Mediumadmidio/admidio: Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET RequestsGHSA-86VW-X4WW-X467Highcraftcms/cms: Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreviewGHSA-C43V-4CR8-6MVPLowcraftcms/cms: Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file readCVE-2026-53727Highcss_parser: Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`CVE-2026-49485Highca.uhn.hapi.fhir:org.hl7.fhir.dstu2: org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP EndpointCVE-2026-53720Mediumpymonocypher: pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too smallCVE-2026-50553Highgithub.com/enchant97/note-mark/backend: Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)CVE-2026-50554Mediumgithub.com/enchant97/note-mark/backend: Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public booksCVE-2026-49477Highsoupsieve: Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector ParserCVE-2026-49476Highsoupsieve: Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector ListsGHSA-52VM-MXX8-F227Highphantom-audio: Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool pathsGHSA-Q6GH-6V2R-HJV3Mediumio.micronaut:micronaut-http-client: Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headersGHSA-387M-935M-C4VWHighio.micronaut:micronaut-http-client: Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoSCVE-2026-48987Mediumpyload-ng: pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManagerCVE-2026-48737Mediumpyload-ng: pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPsCVE-2026-49471Highserena-agent: Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCECVE-2026-49464Highnl.nl-portal:taak: NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taakCVE-2026-49463Mediumnl.nl-portal:documenten-api: NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries

Stop the waste.
Protect your environment with Kodem.