Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-50196HighSteeltoe.Discovery.Eureka: Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetchCVE-2026-50194HighSteeltoe.Management.Endpoint: Steeltoe vulnerable to management-port isolation bypass via spoofed Host headerCVE-2026-49289Highsimplesamlphp/saml2: SimpleSAMLphp has Possible DoS via XPath TransformCVE-2026-52829Highzebra-network: Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior UpdateCVE-2026-49283Highsimplesamlphp/saml2: SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypassCVE-2026-52817Highlinuxfabrik-lib: Linuxfabrik Monitoring Plugins: Sudoers may be able to obtain privilege escalation via /usr/bin/apt-get argumentsGHSA-X4HG-HFWF-P9MWMedium@asymmetric-effort/nogginlessdom: @asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validationGHSA-322X-V876-G883High@asymmetric-effort/nogginlessdom: @asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file writeCVE-2026-59800Critical9router: 9router: Missing Authorization and OS Command InjectionGHSA-GJ2H-2FPW-FHV9Medium@nuxt/ui: @nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydrationCVE-2026-52746Highjsonata: jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustionCVE-2026-52734Mediumzebrad: zebrad has unbounded memory leak in mempool download pipeline via timeout path cancel_handles retentionCVE-2026-52733Mediumzebra-state: zebrad has persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tipCVE-2026-50282Highcraftcms/cms: Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced MovesCVE-2026-50281Highcraftcms/cms: Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elementsCVE-2026-9811Mediummautic/core: Mautic has Stored Cross-Site Scripting (XSS) in Project Option SelectorCVE-2026-9809Highmautic/core: Mautic has Stored Cross-Site Scripting (XSS) in Projects ComponentCVE-2026-9808Highmautic/core: Mautic has an Authorization Bypass in API v2 EndpointsCVE-2026-9559Criticalmautic/core: Mautic vulnerable to Path Traversal via Campaign ImportCVE-2026-9558Criticalmautic/core: Mautic has Server-Side Template Injection (SSTI) in Theme TemplatesCVE-2026-9557Mediummautic/core: Mautic Focus component Vulnerable to SSRFCVE-2026-52739Mediumzebra-state: Zebra: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier RejectionCVE-2026-52738Mediumzebra-state: Zebra: Finalized address balance credit-first overflow on consensus-valid blocksCVE-2026-52737Mediumzebra-consensus: Zebra has sync restart poisoning from single unauthenticated peer via above-lookahead blockCVE-2026-52735Criticalzebra-script: zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser

Stop the waste.
Protect your environment with Kodem.