Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-H72H-PPCX-998PLowzebra-network: Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body lengthCVE-2026-52732Mediumzebrad: zebrad has mempool transaction admission denial via single-peer inbound queue saturationGHSA-C8W6-X74F-VMG3Mediumzebra-rpc: zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceiversGHSA-F9FF-5X35-7GFWHigh@grackle-ai/mcp: Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)GHSA-443G-GWGP-49X4Lowzebrad: zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector lengthCVE-2026-52731Mediumzebra-rpc: zebrad has full node denial of service via non-ASCII LongPollId in getblocktemplateCVE-2026-4776Highmautic/core: Mautic has SQL Injection in API Contact FilteringGHSA-Q4RM-M6XH-5PV7Mediumfroxlor/froxlor: Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add APIGHSA-MR9H-45P9-FG8HMediumfroxlor/froxlor: Froxlor: Authenticated customers can read other customers' allowed sender aliasesCVE-2026-49255Highelecterm: electerm has Command Injection in File System Operations (rmrf, mv, cp)CVE-2026-49254Lowd7y.io/dragonfly/v2: Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauthCVE-2026-49253Highelecterm: electerm has Path Traversal in Zmodem and Trzsz Download Filename HandlingCVE-2026-49250High@conform-to/dom: @conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fieldsGHSA-VV65-F55V-XM6GHigh@grackle-ai/runtime-sdk: Grackle has command/argument injection in the git worktree executor that enables RCE on provisioned hosts via an unsanitized task branch…CVE-2026-49852Highjoserfc: joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)CVE-2026-49245Lowgithub.com/drakkan/sftpgo/v2: SFTPGo has stored XSS via inline parameter on public shares and user file downloadCVE-2026-49244Mediumgithub.com/drakkan/sftpgo/v2: SFTPGo has path confinement bypass in public browsable share partial ZIP downloadCVE-2026-50290Medium@asymmetric-effort/specifyjs: @asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToStringGHSA-J5QP-P44G-2M49Medium@asymmetric-effort/specifyjs: @asymmetric-effort/specifyjs: No redirect target validation in secureFetchGHSA-2944-57XV-2682Medium@asymmetric-effort/specifyjs: @asymmetric-effort/specifyjs: `data:` URI allowed without size restrictionGHSA-XW57-23P8-9WC5Medium@asymmetric-effort/specifyjs: @asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)GHSA-QCR8-X557-7CP3Medium@asymmetric-effort/specifyjs: @asymmetric-effort/specifyjs: Production console warnings may leak internal framework stateGHSA-5C7W-4WM3-85VWMedium@asymmetric-effort/specifyjs: @asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injectionCVE-2026-50288High@asymmetric-effort/specifyjs: @asymmetric-effort/specifyjs: URL parse failure silently allows requestCVE-2026-50284Highcraftcms/cms: Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets

Stop the waste.
Protect your environment with Kodem.