BiiTts
15 exploits
Active since Mar 2025
Roundcube Webmail < 1.5.10 and 1.6.x < 1.6.11 - Authenticated Remote Code Execution via PHP Object Deserialization
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
CVSS 10.0
Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints
CVSS 9.8
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
CVSS 10.0
MISP Core Bulk Deletion - Unauthorized Event Report and Sharing Group Deletion
CVSS 8.8
Apache APISIX: Authentication bypass in jwe-decrypt
CVSS 9.1
Budibase: Anonymous NoSQL operator injection via published-app query templates
CVSS 10.0
LiteLLM: Authentication Bypass via Host Header Injection
CVSS 9.8
samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
CVSS 8.8
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
CVSS 9.8
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
CVSS 9.8
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
CVSS 9.9
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
CVSS 9.8
Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints
CVSS 9.8
Kubernetes ingress-nginx - Pod Network Remote Code Execution
CVSS 9.8