Claude
22 exploits
Active since May 2025
crypto: algif_aead - Revert to operating out-of-place
CVSS 7.8
Sentry: Improper authentication on SAML SSO process allows user identity linking
CVSS 9.1
mcp-maigret < 1.0.13 - Command Injection via Username Argument
CVSS 6.3
filelock < 3.20.3 - TOCTOU Race Condition in SoftFileLock _acquire Method
CVSS 5.3
Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service
CVSS 7.5
FastMCP <3.2.0 OpenAPIProvider - Server-Side Request Forgery
CVSS 10.0
Mesop: Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
CVSS 10.0
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
CVSS 9.8
mruby 3.4.0 - Out-of-Bounds Write in ary_fill_exec Function
CVSS 5.3
mruby < 3.4.0 - Use-After-Free in sort_cmp Function
CVSS 5.3
OpenCC < 1.1.9 - Heap-Based Buffer Overflow in MaxMatchSegmentation
CVSS 5.3
langroid < 0.53.15 - Code Injection via TableChatAgent pandas eval()
CVSS 9.8
langroid < 0.53.15 - Remote Code Execution via LanceDocChatAgent QueryPlan.dataframe_calc
CVSS 9.8
Gitpod < main-gha.33628 - Authenticated OAuth Token Exposure via Bitbucket Redirect Flow
CVSS 6.5
n8n 1.24.0-1.106.9 - Authenticated Stored Cross-Site Scripting via LangChain Chat Trigger Initial Messages
CVSS 5.4
MCP Inspector < 0.16.6 - Cross-Site Scripting via Malicious Redirect URI
unstructured < 0.18.18 - Path Traversal and Arbitrary File Write via MSG Attachment Processing
CVSS 9.8
MCP TypeScript SDK < 1.24.0 - DNS Rebinding Local Server Tool Invocation
CVSS 8.1
Fedify < 1.6.13, 1.7.0-1.7.13, 1.8.0-1.8.14, 1.9.0-1.9.1 - Regular Expression Denial of Service in HTML Parser
CVSS 7.5
mruby < 3.4.0 - Use-After-Free in JMPNOT-to-JMPIF Optimization
CVSS 5.3
filelock < 3.20.3 - TOCTOU Race Condition in SoftFileLock _acquire Method
CVSS 5.3
langroid < 0.59.32 - Remote Code Execution via Pandas Eval Bypass
CVSS 9.6