Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-44342Mediumgithub.com/QuantumNous/new-api: New API is vulnerable to CSRF through user email bindingCVE-2026-40187Highegroupware/egroupware: EGroupware has Authenticated RCE via Malicious eTemplate UploadCVE-2026-34151Highorg.xwiki.platform:xwiki-platform-oldcore: XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+CVE-2026-33655Highgithub.com/QuantumNous/new-api: New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLsCVE-2026-27823Criticalegroupware/egroupware: EGroupware has a Remote Code Execution VulnerabilityCVE-2026-35381Lowuu_cut: cut: -s ignored in -z -d '' newline-delimiter modeCVE-2026-35361Lowuu_mknod: mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)CVE-2026-35341Highuu_mkfifo: mkfifo: permissions of an existing file are changed after FIFO creation failsGHSA-QRWJ-VH9X-GW5VHighgithub.com/coder/coder/v2: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and writeGHSA-CGFV-JRFP-2R7VHighio.openremote:openremote-manager: OpenRemote has Authenticated SQL Injection via Datapoint Crosstab ExportCVE-2026-55630Lowkiwitcms: Kiwi TCMS vulnerable to stored XSS via JavaScript: URI in extra_link field (TestPlan & TestCase)CVE-2026-55501High9router: 9router: Login brute-force protection bypass via spoofed X-Forwarded-For headerCVE-2026-55500Critical9router: 9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database…CVE-2026-55794Highcraftcms/cms: Craft CMS: Potential authenticated Remote Code Execution via referrer redirectCVE-2026-55793Mediumcraftcms/cms: Craft CMS: Stored XSS via Structure entry title in table viewCVE-2026-55792Mediumcraftcms/cms: Craft CMS: Sensitive File Disclosure / Server-Side File ReadCVE-2026-55790Highcraftcms/cms: Craft CMS: DOM XSS via GitHub issue title in CraftSupport widgetCVE-2026-54724Mediumkiwitcms: Kiwi TCMS has an Open Redirect via unvalidated next parameter in account confirmation endpointCVE-2026-54496Criticalzebrad: Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action…CVE-2026-55615Criticallangroid: Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring…GHSA-VJC7-JRH9-9J86Critical9router: 9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/statsCVE-2026-55438Mediumgithub.com/coder/coder/v2: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofingCVE-2026-55426Highlinuxfabrik-lib: Linuxfabrik Monitoring Plugins have local privilege escalation using embedded commandCVE-2026-55437Mediumgithub.com/coder/coder/v2: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine componentCVE-2026-55436Highgithub.com/coder/coder/v2: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration

Stop the waste.
Protect your environment with Kodem.