Exploited CVEs

Vulnerabilities with confirmed exploitation — sourced from threat intelligence reports with associated IoCs and actor attribution.

CVE-2026-60004

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

CVE
CVE-2024-45811

server.fs.deny bypassed when using ?import&raw in vite

CVE
CVE-2026-39364

Vite has a `server.fs.deny` bypass with queries

CVE
CVE-2025-30208

Vite bypasses server.fs.deny when using `?raw??`

CVE
CVE-2025-31125

Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query

CVE
CVE-2026-59821

LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks

CVE
CVE-2026-82533

DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing

CVE
CVE-2026-85046

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE
CVE-2026-27944

Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure

CVE
CVE-2026-33032

Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover

CVE
CVE-2026-26220

LightLLM <= 1.1.0 PD Mode Unsafe Deserialization RCE

CVE
CVE-2023-48022

Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment. (Also, within that environment, customers at version 2.52.0 and later can choose to use token authentication.)

CVE
CVE-2022-27925

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

CVE
CVE-2021-23758

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

CVE
CVE-2021-29442

Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While the /data/remove endpoint is properly protected with the @Secured annotation, the /derby endpoint is not protected and can be openly accessed by unauthenticated users. These endpoints are only valid when using embedded storage (derby DB) so thi

CVE
CVE-2022-0995

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

CVE
CVE-2021-3156

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

CVE
CVE-2015-3246

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

CVE
CVE-2026-2441

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE
CVE-2026-3909

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE
CVE-2026-3910

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE
CVE-2026-14894

Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)

CVE
CVE-2026-49869

Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`

CVE
CVE-2026-72718

goose: Arbitrary command execution in goose CLI via `goose review` via git core.fsmonitor

CVE
CVE-2021-43891

Visual Studio Code Remote Code Execution Vulnerability

CVE
CVE-2026-55607

Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution

CVE
CVE-2026-37281

An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.

CVE
CVE-2021-22555

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

CVE
CVE-2023-32233

In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.

CVE
CVE-2023-46604

Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

CVE
← Previous Next →