Exploited CVEs
Vulnerabilities with confirmed exploitation — sourced from threat intelligence reports with associated IoCs and actor attribution.
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.
sctp: don't free the ASCONF's own transport in DEL-IP processing
Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file.
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
Google-ADK Continuation Forgery
AI SDK Codex Harness Tool Relay Authorization Bypass
AI SDK OpenCode Harness Tool Relay Authorization Bypass
Paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass
Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user
terraform-mcp-server vulnerable to server side request forgery leading to token exposure
terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
net: openvswitch: reject oversized nested action attrs
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
Gitea Composer package source links use insufficient permission checks
Ghost has a SQL Injection in its Content API
Diffusers: None.py Trust Remote Code Bypass
Diffusers: TOCTOU Trust Remote Code Bypass
Diffusers: `trust_remote_code` bypass via `custom_pipeline` and local custom components
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI
OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download
net/sched: act_api: use RCU with deferred freeing for action lifecycle