Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55086Mediumep_etherpad-lite: ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwriteCVE-2026-55087Mediumep_etherpad-lite: ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path HeaderCVE-2026-55072Highpimcore/pimcore: Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table nameCVE-2026-55074Highansible-jailexec: Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)GHSA-PFVM-W89X-94JWHighSIPSorcery: SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)GHSA-JWJP-4649-V8JPHighSIPSorcery: SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsingCVE-2026-55071Highstata-mcp: MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`CVE-2026-54917Highgithub.com/seaweedfs/seaweedfs: SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket accessCVE-2026-52776Highcompliance-trestle: compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0CVE-2026-48798HighSSH.NET: SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP FilenamesCVE-2026-48786Mediumgithub.com/fleetdm/fleet/v4: Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpointCVE-2026-47132Mediumthorsten/phpmyfaq: phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User EnumerationCVE-2026-46369Highnimiq-blockchain: nimiq-blockchain: Validity store off by one errorCVE-2026-45694Mediumlibrenms/librenms: LibreNMS: Reflected XSS via Proxmox instance/vmid GET parameters injected into document.title JavaScript assignmentCVE-2026-35445Highwinter/wn-backend-module: Winter: Authenticated backend users can bypass Users controller permission checksCVE-2026-32639Mediumwinter/wn-cms-module: Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploadsCVE-2026-32593Mediumwinter/wn-backend-module: Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjaxCVE-2026-32258Highwinter/wn-backend-module: Winter: Stored XSS through Editor Settings custom stylesCVE-2026-32257Highwinter/wn-backend-module: Winter: Stored XSS through Brand Settings custom stylesCVE-2026-9318Mediumtablib: tablib: Stored XSS in the HTML export via unescaped dataset titleCVE-2026-62902MediumMicrosoft.WindowsDesktop.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure VulnerabilityCVE-2026-62871HighMicrosoft.WindowsDesktop.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege VulnerabilityCVE-2026-62897HighMicrosoft.WindowsDesktop.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution VulnerabilityCVE-2026-70354HighMicrosoft.WindowsDesktop.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution VulnerabilityCVE-2026-62909MediumMicrosoft.NETCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability

Stop the waste.
Protect your environment with Kodem.