Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-MQHR-6J6H-74P5Critical@budibase/server: Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak CVE-2026-62323Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve WOPI view sessions can write files and WOPI access token secret is ignoredGHSA-HP6V-6JW7-GV2FCritical@budibase/server: Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verifiedGHSA-XG5G-26X8-CVF4High@budibase/server: Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query executionGHSA-XCX6-4F2G-HHGXHigh@budibase/server: Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLsGHSA-PPR4-5F46-J9C6High@budibase/server: Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFileGHSA-Q6X4-V3QX-85QWCritical@budibase/server: Budibase: SQL Injection via `multipleStatements: true`GHSA-C8VC-7PV3-G98PHigh@budibase/server: Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)GHSA-FCRW-F7GG-6G9FMedium@budibase/server: Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role UsersGHSA-4QCJ-M5WP-JMF4Medium@budibase/server: Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappingsGHSA-J9FC-W3MR-X6MVHigh@budibase/server: Budibase: Privilege escalation via public role assignment API missing app-level authorizationCVE-2026-44907Highreact-server-dom-webpack: react-server-dom: Denial of Service in Server FunctionsCVE-2026-62379Criticalorg.openidentityplatform.openam:openam-core: OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallbackCVE-2026-62280Mediumorg.openidentityplatform.openam:openam-oauth2: OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent pageCVE-2026-62263Criticalorg.openidentityplatform.openam:openam-auth-webauthn: OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypassCVE-2026-59221Highopen-webui: open-webui terminal proxy path traversal guard bypass via 9x encoded traversalCVE-2026-59225Mediumopen-webui: Open WebUI: Arena task endpoints can bypass underlying model access controlsCVE-2026-59212Mediumopen-webui: Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/deleteCVE-2026-59224Highopen-webui: Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal…CVE-2026-59223Mediumopen-webui: Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matchingCVE-2026-57497Mediumgithub.com/quic-go/webtransport-go: webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown CapsulesCVE-2026-55502Highgithub.com/cloudreve/Cloudreve/v4: Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentialsCVE-2026-55499Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and…CVE-2026-55497Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the serverCVE-2026-55496Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned…

Stop the waste.
Protect your environment with Kodem.