Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-50284Highcraftcms/cms: Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assetsCVE-2026-50283Mediumcraftcms/cms: Craft CMS: Unauthorized Deletion of Source Assets During File ReplacementCVE-2026-50280Mediumcraftcms/cms: Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save checkCVE-2026-50279Highcraftcms/cms: Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gapCVE-2026-44454Highgithub.com/coder/coder/v2: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consentCVE-2026-52854Highmediawiki/maps: mediawiki/maps has stored XSS through the overlays parameter in the display_map parser functionCVE-2026-52726Highdulwich: Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped…CVE-2026-50180Highlangroid: Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file readCVE-2026-50181Highlangroid: Langroid: Path traversal in the file tools allows read/write outside configured current directoryCVE-2026-50192Mediumgithub.com/kerberos-io/agent/machinery: Kerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without…GHSA-P73F-W79W-JQR5Highopenclaw: OpenClaw: Native command authorization could skip owner-command enforcementGHSA-J472-GF56-X589Highopenclaw: OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checksGHSA-77Q5-RR5V-X43QHighopenclaw: OpenClaw: Trusted retry endpoint checks could match hostname prefixesGHSA-W5WW-7CHG-MXCQHighopenclaw: OpenClaw: Telegram interactive callbacks could skip commands.allowFromCVE-2026-50185Mediumcmov: Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set CVE-2026-50149Mediumgithub.com/projectcontour/contour: Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate EnabledCVE-2026-53811Highopenclaw: OpenClaw: Matrix allowFrom could bind to mutable display namesGHSA-4M3V-Q747-PC6HMediumopenclaw: OpenClaw: Mattermost slash token revocation could lag until monitor refreshCVE-2026-53816Highopenclaw: OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenanceCVE-2026-53806Highopenclaw: OpenClaw: Combined POSIX shell options could confuse exec revalidationCVE-2026-53818Mediumopenclaw: OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callersGHSA-275C-XPVC-JGFWMediumopenclaw: OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reloadGHSA-3WQP-PRF6-2M72Lowopenclaw: OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcementGHSA-6C4R-G249-WV3CMediumopenclaw: OpenClaw: Sandboxed session spawn could expose the real workspace path to child promptsCVE-2026-53809Mediumopenclaw: OpenClaw: Embedded runner policy could be confused by provider aliases

Stop the waste.
Protect your environment with Kodem.