Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-77634Highcakephp/cakephp: CakePHP: SmtpTransport vulnerable to CRLF header injectionCVE-2026-84368Lowjoi: joi: Prototype pollution via a `__proto__` language key in custom messagesCVE-2026-85062Mediumcolord: Colord: Slow rejection of oversized malformed color stringsCVE-2026-75604Criticalnext: Next.js: Unauthenticated Remote Code Execution on windows-hosted serversCVE-2026-84367Lowjoi: joi: object().rename() with a template target can set the validated object's prototypeCVE-2026-85061Criticalmaplibre-gl: MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal SkipCVE-2026-84303Mediumgoogle.golang.org/grpc: gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasionCVE-2026-84382Highhttpx2: HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)CVE-2026-84373Medium@vitest/mocker: Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect MockCVE-2026-84380Mediumhttpx2: HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generatedCVE-2026-84379Mediumhttpx2: HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headersCVE-2026-84378Mediumhttpx2: HTTPX2: Quadratic SSE line buffering can cause CPU denial of serviceCVE-2026-84381Highhttpcore2: HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxiesCVE-2026-73560Mediumvllm: vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protectionsCVE-2026-84374Highmaatwebsite/excel: Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled pathCVE-2026-83606High@xmldom/xmldom: xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructionsCVE-2026-83607High@xmldom/xmldom: xmldom: Element name injection via createElement() bypasses requireWellFormedCVE-2026-83605High@xmldom/xmldom: xmldom: Attribute name injection via setAttribute() bypasses requireWellFormedCVE-2026-50646HighMicrosoft.WindowsDesktop.App.Runtime.win-x64: Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution VulnerabilityCVE-2026-81725Mediumnltk: NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocksCVE-2026-80206Highnltk: NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressionsCVE-2026-80205Highnltk: NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressionsCVE-2026-62815CriticalMicrosoft.Native.Quic.MsQuic.OpenSSL: Microsoft QUIC: Remote Code Execution VulnerabilityCVE-2026-62900MediumMicrosoft.Build.Tasks.Git: Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure VulnerabilityCVE-2026-73558Mediumvllm: vLLM: Cross-User Data Leak Vulnerability

Stop the waste.
Protect your environment with Kodem.