Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-84363Mediumhono: Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentialsCVE-2026-84445Highgoogle.golang.org/grpc: gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headersGHSA-2XP9-VWFH-VXW4Criticalnext: Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are usedCVE-2026-84370Highsvgo: SVGO: removeScripts allows executable links through namespace and control-character bypassesCVE-2026-84369Mediumsvgo: SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elementsGHSA-8M3C-C648-2XJJMediumnodemailer: Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signatureCVE-2026-83616High@xmldom/xmldom: xmldom: Processing Instruction Target Injection Bypasses requireWellFormedCVE-2026-83617High@xmldom/xmldom: xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminatorCVE-2026-83608High@xmldom/xmldom: xmldom: DocType `name` Injection Bypasses requireWellFormedCVE-2026-83609High@xmldom/xmldom: xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default…CVE-2026-83618High@xmldom/xmldom: xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminatorCVE-2026-83611Medium@xmldom/xmldom: xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing contentCVE-2026-83613High@xmldom/xmldom: xmldom: Quadratic-time attribute deduplicationCVE-2026-83619High@xmldom/xmldom: xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parserCVE-2026-83615High@xmldom/xmldom: xmldom: Quadratic-memory consumptionCVE-2026-83614High@xmldom/xmldom: xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text mergeCVE-2026-83612High@xmldom/xmldom: xmldom: HTML raw-text closing-tag case mismatch causes output amplificationCVE-2026-84372Criticalpredis/predis: Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connectionsCVE-2026-77635Criticalcakephp/cakephp: CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriverCVE-2026-77634Highcakephp/cakephp: CakePHP: SmtpTransport vulnerable to CRLF header injectionCVE-2026-84368Lowjoi: joi: Prototype pollution via a `__proto__` language key in custom messagesCVE-2026-85062Mediumcolord: Colord: Slow rejection of oversized malformed color stringsCVE-2026-75604Criticalnext: Next.js: Unauthenticated Remote Code Execution on windows-hosted serversCVE-2026-84367Lowjoi: joi: object().rename() with a template target can set the validated object's prototypeCVE-2026-85061Criticalmaplibre-gl: MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip

Stop the waste.
Protect your environment with Kodem.