Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55495Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner AccountCVE-2026-55404Highyt-dlp: yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link outputCVE-2026-59222Mediumopen-webui: Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentialsCVE-2026-59215Lowopen-webui: Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id bindingCVE-2026-59213Lowopen-webui: Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)CVE-2026-59217Mediumopen-webui: Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)CVE-2026-59216Highopen-webui: Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_idCVE-2026-59714Highopen-webui: Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)CVE-2026-59219Highopen-webui: Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logoutCVE-2026-59715Lowopen-webui: Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)CVE-2026-59227Mediumopen-webui: Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permissionCVE-2026-59220Mediumopen-webui: Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default configCVE-2026-59226Lowopen-webui: Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocationCVE-2026-59218Mediumopen-webui: Open WebUI: Account enumeration via observable login timing discrepancyCVE-2026-59214Highopen-webui: Open WebUI: Stored web worker XSS via PyodideCVE-2026-55607High@anthropic-ai/claude-code: Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code ExecutionGHSA-V74W-7MR3-4QG3Highio.netty:netty-codec-xml: Netty: Denial of Service in XmlFrameDecoder via CPU ExhaustionGHSA-MFG7-5GFP-C4W3Mediumio.netty:netty-codec-dns: Netty: Memory Leak in DNS Record Decoder via Malformed Domain NamesGHSA-R277-6W6Q-XMQWCriticalgithub.com/getkin/kin-openapi: kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc DefaultGHSA-GCJH-H69Q-9W9GMediumgithub.com/google/cel-go: cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTagGHSA-PM4M-PH32-GHV5Highjs-yaml: js-yaml: Exponential parsing time in flow collections leads to denial of serviceGHSA-G9HV-X236-4QP3Mediumrussh: Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)GHSA-CQJC-RMPQ-XPRQMediumrussh: Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode recordsGHSA-5XVQ-CP9X-6P6RMediumrussh: Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)GHSA-QWWW-VCR4-C8H2Highreact-router: React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response

Stop the waste.
Protect your environment with Kodem.