Exploited CVEs
Vulnerabilities with confirmed exploitation — sourced from threat intelligence reports with associated IoCs and actor attribution.
xfrm: esp: avoid in-place decrypt on shared skb frags
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
SSRF in berriai/litellm
LiteLLM affected by privilege escalation via unrestricted proxy configuration endpoint
A cross-site scripting (XSS) vulnerability in Alinto SOGo, version 5.12.7
RedisBloom RESTORE invalid memory access may allow remote code execution
redis-server RESTORE invalid memory access may allow remote code execution
NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local User
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.
net/sched: fix pedit partial COW leading to page cache corruption
A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private mount namespace and causing snap-confine to execute arbitrary code and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
Race condition in snap-confine's must_mkdir_and_open_with_perms()
Local Privilege Escalation in snapd
Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly
Zlib compressed protocol header length confusion may allow memory read
Forge has signature forgery in Ed25519 due to missing S > L check
CVE-2026-14890
Apache Tomcat: EncryptInterceptor requirements not clearly documented
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file.
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buf
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. This can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.