Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-52889Criticalverbb/formie: Formie Hidden field defaults vulnerable to Server-Side Template InjectionCVE-2022-46292Highopenbabel: Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION)CVE-2026-53913Criticalorg.apache.camel:camel-keycloak: Apache Camel: KeycloakSecurityPolicy has Improper Authentication, Missing Authentication for Critical Function and Failing Open…CVE-2026-48205Criticalorg.apache.camel:camel-dns: Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF) CVE-2026-48204Criticalorg.apache.camel:camel-mongodb-gridfs: Apache Camel: camel-mongodb-gridfs producer allows GridFS operation override and NoSQL operator injection via unfiltered  gridfs.*  HTTP…CVE-2026-49360Highrecce: Recce server has unauthenticated SQL execution that allows local file read/write through DuckDBCVE-2026-49353High9router: 9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofINGCVE-2026-46599Highgolang.org/x/image: golang.org/x/image/tiff has excessive resource consumption in PackBits decompressionCVE-2026-49352Critical9router: 9router's Hardcoded Default fallback JWT Secret Allows Authentication BypassCVE-2026-49292Lowkiwitcms: Kiwi TCMS's /init-db/ page renders and responds to requests after first useCVE-2026-54617Criticalpro.gravit.launcher:launchserver-api: LaunchServer FileServerHandler has an unauthenticated path traversal issueCVE-2026-49284Highsimplesamlphp/simplesamlphp: SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion…CVE-2026-52792Highgithub.com/xyproto/algernon: Algernon vulnerable to server-side script source disclosure on Windows via NTFS filenameCVE-2026-52834Highjxl-grid: jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflowGHSA-66M8-C62J-H6V5Mediumjxl-oxide: jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflowGHSA-2V8P-FQPX-2Q3WMediumjxl-modular: jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS)GHSA-J5MC-P8QG-39J7Lowkimai/kimai: Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark ManipulationCVE-2026-2092Highorg.keycloak:keycloak-services: Keycloak: Unauthorized access via improper validation of encrypted SAML assertionsCVE-2026-52830Criticalfast-mcp-telegram: fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protectionCVE-2026-50268LowSteeltoe.Configuration.Encryption: Steeltoe: OAEP setting silently selects PKCS#1 v1.5 paddingCVE-2026-50267MediumSteeltoe.Configuration.Abstractions: Steeltoe: TLS private keys written to /tmp with default permissions, never deletedCVE-2026-50202MediumSteeltoe.Security.Authentication.JwtBearer: Steeltoe's static JWKS cache shared across schemes and never invalidatedCVE-2026-50201MediumSteeltoe.Management.Endpoint: Steeltoe's sensitive actuators (heapdump/env) only require Restricted permissionCVE-2026-50200HighSteeltoe.Management.Endpoint: Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwordsCVE-2026-50196HighSteeltoe.Discovery.Eureka: Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

Stop the waste.
Protect your environment with Kodem.