Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-54764Mediumgithub.com/traefik/traefik/v2: Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=falseCVE-2026-71327Highgithub.com/traefik/traefik/v3: Traefik: Gateway API route identity collision allows cross-namespace backend hijackingCVE-2026-71326Lowgithub.com/traefik/traefik/v3: Traefik: BasicAuth singleflight key collision allows authenticated identity spoofingCVE-2026-71324Highgithub.com/traefik/traefik/v2: Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive poolCVE-2026-65602Mediumgithub.com/traefik/traefik/v3: Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace BypassCVE-2026-65601MediumTraefik: Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace ConfusionCVE-2026-71321Highnuxt: Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validationCVE-2026-71320Highnuxt: Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island PropsCVE-2026-71319Critical@nuxt/devtools: Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's hostCVE-2026-71318Mediumnuxt: Nuxt: Unauthorized Component Instantiation via Server Island PropsCVE-2026-71316Highnuxt: Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clientsCVE-2026-71315Highnuxt: Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)CVE-2026-71314Highnuxt: Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island renderingCVE-2026-71313Mediumgithub.com/rclone/rclone: rclone: Local Encoding Path TraversalCVE-2026-59732Mediumgithub.com/rclone/rclone: rclone archive extract allows S3 destination prefix escape via crafted archive pathsGHSA-GX4C-2HQX-CW2RLowgithub.com/rclone/rclone: rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirectCVE-2026-59733Highgithub.com/rclone/rclone: rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete…CVE-2026-71312Highgithub.com/rclone/rclone: rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command ExecutionGHSA-H4MF-4V27-HGGJMediumgithub.com/rclone/rclone: rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP RedirectCVE-2026-71311Mediumgithub.com/rclone/rclone: rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves NewlinesGHSA-8MXV-9XHP-86H4Mediumgithub.com/rclone/rclone: rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C KeysGHSA-8V25-V8P6-QF7VMediumgithub.com/rclone/rclone: rclone: Path traversal in serve s3 allows reading and overwriting root-level filesGHSA-3X6R-WXXG-53VVMediumgithub.com/rclone/rclone: rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response PanicCVE-2026-71310Mediumgithub.com/rclone/rclone: rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone MemoryCVE-2026-54572Highgithub.com/rclone/rclone: rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote

Stop the waste.
Protect your environment with Kodem.