Caio Fabricio (BiiTts)
10 exploits
Active since Jun 2026
Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints
CVSS 9.8
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
CVSS 10.0
MISP Core Bulk Deletion - Unauthorized Event Report and Sharing Group Deletion
CVSS 8.8
Apache APISIX: Authentication bypass in jwe-decrypt
CVSS 9.1
Budibase: Anonymous NoSQL operator injection via published-app query templates
CVSS 10.0
LiteLLM: Authentication Bypass via Host Header Injection
CVSS 9.8
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
CVSS 9.8
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
CVSS 9.8
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
CVSS 9.9
Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints
CVSS 9.8