Exploited CVEs

Vulnerabilities with confirmed exploitation — sourced from threat intelligence reports with associated IoCs and actor attribution.

CVE-2022-29464

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up

CVE
CVE-2024-4577

Argument Injection in PHP-CGI

CVE
CVE-2026-22732

Under Some Conditions Spring Security HTTP Headers Are not Written

CVE
CVE-2023-37679

A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.

CVE
CVE-2023-43208

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

CVE
CVE-2023-38646

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

CVE
CVE-2026-64564

sctp: don't free the ASCONF's own transport in DEL-IP processing

CVE
CVE-2026-12537

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file.

CVE
CVE-2026-54316

Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch

CVE
CVE-2026-63913

netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check

CVE
CVE-2023-20569

A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.

CVE
CVE-2026-64561

KVM: x86: Check for invalid/obsolete root *after* making MMU pages available

CVE
CVE-2026-18236

Google-ADK Continuation Forgery

CVE
CVE-2026-64650

AI SDK Codex Harness Tool Relay Authorization Bypass

CVE
CVE-2026-64651

AI SDK OpenCode Harness Tool Relay Authorization Bypass

CVE
CVE-2026-41679

Paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass

CVE
CVE-2026-29146

Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default

CVE
CVE-2026-16496

terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user

CVE
CVE-2026-14869

terraform-mcp-server vulnerable to server side request forgery leading to token exposure

CVE
CVE-2026-16498

terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode

CVE
CVE-2026-64531

net: openvswitch: reject oversized nested action attrs

CVE
CVE-2026-9198

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

CVE
CVE-2026-27771

Gitea Composer package source links use insufficient permission checks

CVE
CVE-2026-26980

Ghost has a SQL Injection in its Content API

CVE
CVE-2026-44827

Diffusers: None.py Trust Remote Code Bypass

CVE
CVE-2026-45804

Diffusers: TOCTOU Trust Remote Code Bypass

CVE
CVE-2026-44513

Diffusers: `trust_remote_code` bypass via `custom_pipeline` and local custom components

CVE
CVE-2026-66066

Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing

CVE
CVE-2026-3545

Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE
CVE-2026-21858

n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling

CVE
Next →