Search
76 results- CRITICAL9.6CVE-2026-45321⚠ KEVEPSS 17.1%Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
- CRITICAL9.8CVE-2026-42208⚠ KEVEPSS 56.9%LiteLLM has SQL Injection in Proxy API key verification
- CRITICAL9.8CVE-2026-39987⚠ KEVEPSS 82.2%Marimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
- HIGH8.8CVE-2026-34197⚠ KEVEPSS 83.5%Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
- —CVE-2026-33634⚠ KEVEPSS 29.4%Trivy ecosystem supply chain was briefly compromised
- CRITICAL9.8CVE-2026-33017⚠ KEVEPSS 24.0%Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
- CRITICAL9.9CVE-2025-68613⚠ KEVEPSS 65.8%n8n Vulnerable to Remote Code Execution via Expression Injection
- HIGH8.8CVE-2025-34291⚠ KEVEPSS 32.7%Langflow CORS misconfiguration enables Account Takeover and RCE
- CRITICAL10.0CVE-2025-55182⚠ KEVEPSS 82.0%React Server Components are Vulnerable to RCE
- HIGH8.2CVE-2025-58360⚠ KEVEPSS 81.4%GeoServer is vulnerable to Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
- CRITICAL9.8CVE-2025-11953⚠ KEVEPSS 20.1%@react-native-community/cli has arbitrary OS command injection
- HIGH7.5CVE-2025-54313⚠ KEVEPSS 14.7%eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall have embedded malicious code
- CRITICAL9.8CVE-2025-3248⚠ KEVEPSS 92.7%Langflow Unauth RCE
- MEDIUM5.3CVE-2025-31125⚠ KEVEPSS 83.2%Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
- CRITICAL9.8CVE-2025-24813⚠ KEVEPSS 94.1%Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
- CRITICAL9.8CVE-2025-24893⚠ KEVEPSS 93.7%XWiki Platform allows remote code execution as guest via SolrSearchMacros request
- CRITICAL9.8CVE-2024-36401⚠ KEVEPSS 94.4%Remote Code Execution (RCE) vulnerability in geoserver
- CRITICAL9.8CVE-2024-27348⚠ KEVEPSS 94.3%Apache HugeGraph-Server: Command execution in gremlin
- CRITICAL9.8CVE-2024-23897⚠ KEVEPSS 94.5%Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE
- CRITICAL10.0CVE-2023-46604⚠ KEVEPSS 94.4%Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
- MEDIUM5.3CVE-2023-44487⚠ KEVEPSS 94.4%nghttp2 - security update
- HIGH8.8CVE-2023-5217⚠ KEVEPSS 5.0%Electron affected by libvpx's heap buffer overflow in vp8 encoding
- CRITICAL9.8CVE-2022-24816⚠ KEVEPSS 94.0%Improper Control of Generation of Code ('Code Injection') in jai-ext
- HIGH8.8CVE-2023-4863⚠ KEVEPSS 93.3%libwebp: OOB write in BuildHuffmanTable
- CRITICAL9.8CVE-2023-33246⚠ KEVEPSS 94.4%Apache RocketMQ may have remote code execution vulnerability when using update configuration function
Page 1 of 4Next →