Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-59867HighMicrosoft.OpenApi.Kiota: Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $refCVE-2026-59864CriticalMicrosoft.OpenApi.Kiota: Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensionsGHSA-866W-XMHQ-WJ7XMedium@sveltejs/kit: SvelteKit: Prototype pollution in file input deletion path in remote-function formsGHSA-WQJV-9729-C5Q2Medium@sveltejs/kit: SvelteKit: Big remote form function payloads can cause Node process to crashCVE-2026-13769Mediumawscli: AWS CLI: Overly permissive File PermissionsCVE-2026-63632Lowonnx: ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input ShapeCVE-2026-57516Highray: Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)CVE-2026-59859HighMicrosoft.OpenApi.Kiota: Microsoft Kiota: Code Generation Literal Injection in Kiota PHP GeneratorCVE-2026-59862HighMicrosoft.OpenAPI.Kiota: Microsoft Kiota: Code Generation Literal Injection in Kiota Python GeneratorCVE-2026-59861HighMicrosoft.OpenAPI.Kiota: Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby GeneratorGHSA-QQ9H-G4JM-XGF3Highbetter-auth: Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-inGHSA-H3RM-78G3-J7CPHigh@better-auth/stripe: @better-auth/stripe: cross-organization billing tampering in organization subscription actionsGHSA-RJG6-39JM-RGG4Critical@better-auth/scim: @better-auth/scim: account takeover and stale access via SCIM provider-id collisionGHSA-76Q6-2P6H-XJQRLowMagick.NET-Q16-AnyCPU: ImageMagick: Heap Buffer Over-Write in X11 import with crafted window titleCVE-2026-59860HighMicrosoft.OpenApi.Kiota: Microsoft Kiota: XML Doc-Comment Newline Breakout Code InjectionCVE-2026-59939Highhttplib2: httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response HandlingGHSA-H5R4-W88W-7CCRLowMagick.NET-Q16-AnyCPU: ImageMagick: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specifiedGHSA-H58X-R7F7-RH84LowMagick.NET-Q16-AnyCPU: ImageMagick: Memory Leak in ICON decoder when allocation failsGHSA-M596-67P7-69WHLowMagick.NET-Q16-AnyCPU: ImageMagick: Memory leak in VIFF encoder when allocation failsGHSA-R628-69V2-2F9CLowMagick.NET-Q16-AnyCPU: ImageMagick: Memory Leak in MIFF encoder when allocaton failsGHSA-H7F2-F9CC-H2GVLowMagick.NET-Q16-AnyCPU: ImageMagick: Memory Leak in YUV decoder when opening of blob failsGHSA-JFQ9-Q63X-RC63LowMagick.NET-Q16-AnyCPU: ImageMagick: Memory Leak in TIFF encoder when an allocation failsGHSA-99W9-HV66-RFV7LowMagick.NET-Q16-AnyCPU: ImageMagick: Memory Leak in JNG encoder when a blob could not be openedGHSA-J8RH-V2R8-V94XLowMagick.NET-Q16-AnyCPU: ImageMagick: Memory Leak in hough lines operation when an operation failsGHSA-7C7M-FPJW-GWCQLowMagick.NET-Q16-AnyCPU: ImageMagick: Memory Leak in color transformation to log colorspace when operation fails

Stop the waste.
Protect your environment with Kodem.