Exploited CVEs

Vulnerabilities with confirmed exploitation — sourced from threat intelligence reports with associated IoCs and actor attribution.

CVE-2026-72718

goose: Arbitrary command execution in goose CLI via `goose review` via git core.fsmonitor

CVE
CVE-2021-43891

Visual Studio Code Remote Code Execution Vulnerability

CVE
CVE-2026-55607

Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution

CVE
CVE-2026-37281

An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.

CVE
CVE-2021-22555

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

CVE
CVE-2023-32233

In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.

CVE
CVE-2023-46604

Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

CVE
CVE-2019-13272

In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is i

CVE
CVE-2026-46300

net: skbuff: preserve shared-frag marker during coalescing

CVE
CVE-2026-31635

rxrpc: fix oversized RESPONSE authenticator length check

CVE
CVE-2026-43494

net/rds: reset op_nents when zerocopy page pin fails

CVE
CVE-2022-0847

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

CVE
CVE-2026-45386

Open WebUI: An IDOR vulnerability exists in the pin_channel_message API endpoint

CVE
CVE-2026-25253

OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.

CVE
CVE-2026-41948

Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access

CVE
CVE-2026-59822

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

CVE
CVE-2026-42271

LiteLLM: Authenticated command execution via MCP stdio test endpoints

CVE
CVE-2026-48710

Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks

CVE
CVE-2025-31277

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciously crafted web content may lead to memory corruption.

CVE
CVE-2025-43529

A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 26.2, Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, tvOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also

CVE
CVE-2025-8217

Inert Malicious script injected into Amazon Q Developer Visual Studio Code (VS Code) Extension

CVE
CVE-2024-3094

Xz: malicious code in distributed source

CVE
CVE-2026-5027

Langflow - Path Traversal Arbitrary File Write via upload_user_file

CVE
CVE-2026-0769

Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability

CVE
CVE-2026-0768

Langflow code Code Injection Remote Code Execution Vulnerability

CVE
CVE-2020-1472

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is ad

CVE
CVE-2022-29464

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up

CVE
CVE-2024-4577

Argument Injection in PHP-CGI

CVE
CVE-2026-22732

Under Some Conditions Spring Security HTTP Headers Are not Written

CVE
CVE-2023-37679

A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.

CVE
Next →