Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-53666Mediumreact-router: React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR HydrationCVE-2026-53467MediumMagick.NET-Q16-AnyCPU: ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchangedCVE-2026-47219Highfind-my-way: find-my-way: DDoS with HTTP2CVE-2026-59935Highpypdf: pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)CVE-2026-59936Highpypdf: pypdf: Possible infinite loop for not terminated inline imagesCVE-2026-59937Mediumpypdf: pypdf: Possible long runtimes for repeated malformed cross-reference entries CVE-2026-59938Mediumpypdf: pypdf: Possible large memory usage for wrong image dimensionsCVE-2026-45623Highpostcss: PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentsCVE-2026-59933Highphpoffice/phpspreadsheet: PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustionCVE-2026-59932Highphpoffice/phpspreadsheet: PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustionCVE-2026-59931Highphpoffice/phpspreadsheet: PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelistGHSA-8FPG-XM3F-6CX3Criticalnext-auth: Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)GHSA-XMF8-CVQR-RFGJHigh@auth/core: Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headersGHSA-7RQJ-J65F-68WHCritical@auth/core: Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypassGHSA-X445-F3H2-J279Medium@auth/core: Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created themGHSA-652Q-GVQ3-74QVMediumn8n: n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression InterpolationGHSA-JQWR-VX3P-R266Mediumn8n: n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL InstancesGHSA-9CMH-XCQM-5HQRMediumn8n: n8n: Cross-Tenant Module-Cache Poisoning in the JS Task RunnerGHSA-PPPJ-HQ3G-57PJHighjupyterlab: JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)GHSA-GX64-GJ6P-PC4CHighjupyterlab: JupyterLab: Image viewer allows XSS when opening malicious image in new browser tabGHSA-89VP-JRXV-24W8Mediumjupyterlab: JupyterLab: PyPI extension blocklist package-name canonicalization bypassGHSA-H5V5-8746-G7MMMediumjupyterlab: JupyterLab PluginManager lock-rule enforcement bypassGHSA-WHVH-WF3X-G77JLowjupyterlab: JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)CVE-2026-64649Highnext: Next.js: Server-Side Request Forgery in Server Actions on custom serversCVE-2026-64648Mediumnext: Next.js: Cache confusion of response bodies for requests with bodies

Stop the waste.
Protect your environment with Kodem.