Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-49456Lowwaku: Waku has an Open Redirect via `unstable_redirect` HelperCVE-2026-49455Mediumwaku: Waku: Cross-Origin CSRF on RSC Server Action DispatchCVE-2026-53649Criticalgithub.com/BishopFox/joro: Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCEGHSA-Q95X-7G78-RCCVMediumoneringbuf: OneRingBuf has a Use After Free VulnerabilityCVE-2026-49833Mediumorg.dspace:dspace-api: DSpace: Path Traversal is possible through LDN message generationCVE-2026-49830Mediumorg.dspace:dspace-api: DSpace: ORE resource URI does not validate scheme for non-web resourcesCVE-2026-49831Mediumorg.dspace:dspace-api: DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output pathCVE-2026-49832Highorg.dspace:dspace-api: DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDNGHSA-MXWC-WH95-PW4GMediumtrapster: Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handlerCVE-2026-53634Mediumcode16/sharp: Sharp Missing Authorization Check in Quick Creation Command EndpointsCVE-2026-52831Criticalgithub.com/nuclio/nuclio: Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCECVE-2026-53600Mediumasync-tar: async-tar PAX extension-header desync enables tar entry/content smugglingCVE-2026-50197Highgithub.com/zalando/skipper: Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requestsCVE-2026-49825Highlxml_html_clean: `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributesCVE-2026-50127Mediumweblate: Weblate SSRF: outbound URL guard misses some private rangesCVE-2026-53508Mediumgithub.com/oasdiff/oasdiff: oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)CVE-2026-53572Mediumgithub.com/kedacore/keda/v2: KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escapingGHSA-F66Q-9RF6-8795MediumFlask-Security-Too: Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertionCVE-2026-53553Highgithub.com/zhenorzz/goploy: Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server CompromiseCVE-2026-53552Criticalgithub.com/zhenorzz/goploy: Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlersGHSA-Q855-8RH5-JFGQMediumha-mcp: ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root pathGHSA-CWV4-H3J5-W3CFLowrama: rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI pathCVE-2026-53533Mediumaiosmtplib: aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient addressCVE-2026-53487Mediumgithub.com/zxh326/kite: Kite has an authenticated cluster RBAC bypass in /api/v1/overviewGHSA-GQ4G-FPC9-VJFQLowweb-auth/webauthn-lib: Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration…

Stop the waste.
Protect your environment with Kodem.