Vulnerability search
Batch lookup →1,889,670 matches
- CVE-2026-60004Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook…criticalKEVPoCEPSS 87%238.89.899.7%2026-08-28 14:42 UTC
- CVE-2026-42208LiteLLM has SQL Injection in Proxy API key verification2 sources· osv_advisorycriticalKEVPoCEPSS 89%238.89.899.8%2026-06-29 11:50 UTC
- CVE-2026-9082Drupal core - Highly critical - SQL injection - SA-CORE-2026-0043 sources· osv_advisorycriticalKEVPoCEPSS 88%238.89.899.8%2026-05-29 08:41 UTC
- CVE-2026-33017Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint2 sources· osv_advisorycriticalKEVPoCEPSS 96%236.40.099.9%2026-06-29 11:50 UTC
- CVE-2026-39987Marimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass2 sources· osv_advisorycriticalKEVPoCEPSS 99%236.40.099.9%2026-06-29 11:50 UTC
- CVE-2026-63030WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code…2 sources· osv_advisorycriticalKEVPoCEPSS 97%236.09.899.9%2026-07-27 05:55 UTC
- CVE-2026-64849MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via…3 sources· osv_advisorycriticalKEVPoCEPSS 16%234.69.396.8%2026-08-21 05:51 UTC
- CVE-2023-4863libwebp: OOB write in BuildHuffmanTable4 sources· osv_advisorycriticalKEVPoCEPSS 100%234.08.8100.0%2026-07-07 11:45 UTC
- CVE-2026-42271LiteLLM: Authenticated command execution via MCP stdio test endpoints2 sources· osv_advisorycriticalKEVPoCEPSS 84%233.78.899.7%2026-07-13 15:02 UTC
- CVE-2025-3248Langflow Unauth RCE3 sources· osv_advisorycriticalRansomwareKEVPoCEPSS 100%232.99.8100.0%2026-06-29 11:50 UTC
- CVE-2023-27524Apache superset missing check for default SECRET_KEY2 sources· osv_advisorycriticalKEVPoCEPSS 97%229.68.999.9%2026-07-07 11:45 UTC
- CVE-2020-1938Improper Privilege Management in Tomcat2 sources· osv_advisorycriticalKEVPoCEPSS 99%229.29.899.9%2026-05-18 08:56 UTC
- CVE-2026-33634Trivy ecosystem supply chain was briefly compromised in github.com/aquasecurity/trivy2 sources· osv_advisorycriticalKEVPoCEPSS 59%229.00.099.1%2026-04-01 16:33 UTC
- CVE-2025-68613n8n Vulnerable to Remote Code Execution via Expression InjectioncriticalKEVPoCEPSS 99%226.110.099.9%2025-12-22 16:19 UTC
- CVE-2025-55182React Server Components are Vulnerable to RCEcriticalRansomwareKEVPoCEPSS 100%225.610.0100.0%2025-12-03 19:07 UTC
- CVE-2023-46604Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ…2 sources· osv_advisorycriticalRansomwareKEVPoCEPSS 100%225.09.8100.0%2025-12-03 14:35 UTC
- CVE-2026-45321Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keyscriticalRansomwareKEVPoCEPSS 2.3%224.29.682.4%2026-05-12 00:12 UTC
- CVE-2025-58360GeoServer is vulnerable to Unauthenticated XML External Entities (XXE) attack via WMS GetMap featurecriticalKEVPoCEPSS 65%223.89.899.2%2025-11-25 19:07 UTC
- CVE-2026-0770Langflow affected by Remote Code Execution via validate_code() exec()criticalKEVPoCEPSS 63%223.69.899.2%2026-01-23 06:31 UTC
- CVE-2025-11953@react-native-community/cli has arbitrary OS command injectioncriticalKEVPoCEPSS 94%223.19.899.8%2025-11-03 18:31 UTC
- CVE-2025-34291Langflow CORS misconfiguration enables Account Takeover and RCE2 sources· osv_advisorycriticalKEVPoCEPSS 84%222.68.899.7%2025-12-06 00:31 UTC
- CVE-2023-41993The issue was addressed with improved checks.3 sources· osv_advisorycriticalKEVPoCEPSS 29%222.48.898.0%2026-05-08 05:45 UTC
- CVE-2026-34197Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE…2 sources· osv_advisorycriticalKEVPoCEPSS 98%221.98.899.9%2026-04-09 08:36 UTC
- CVE-2023-42917A memory corruption vulnerability was addressed with improved locking.3 sources· osv_advisorycriticalKEVPoCEPSS 9.4%220.68.895.1%2026-05-08 05:45 UTC
- CVE-2025-49113Roundcube Webmail Vulnerable to Authenticated RCE via PHP Object DeserializationcriticalKEVPoCEPSS 99%220.49.999.9%2025-06-02 06:30 UTC