Claude
35 exploits
Active since May 2025
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
CVSS 9.8
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
CVSS 5.9
crypto: algif_aead - Revert to operating out-of-place
CVSS 7.8
Leantime all versions prior to and 3.6.2 Broken Access Control via tickets.getMilestone JSON-RPC
CVSS 6.5
Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets
CVSS 5.4
Apify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
CVSS 6.1
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
CVSS 9.3
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
CVSS 9.3
Wekan < 9.37 Cards/Lists/Swimlanes - Cross-Board Write Access Control Bypass
CVSS 8.5
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
CVSS 9.3
Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instances
CVSS 5.9
Actual: CSV Formula Injection in `@actual-app/cli` `--format csv` Output via Custom `escapeCsv` Helper
CVSS 4.6
Actual < 26.6.0 - Bank-Sync Secret Enumeration via GET /secret/:name
CVSS 4.3
Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields
CVSS 4.2
Sentry: Improper authentication on SAML SSO process allows user identity linking
CVSS 9.1
mcp-maigret < 1.0.13 - Command Injection via Username Argument
CVSS 6.3
filelock < 3.20.3 - TOCTOU Race Condition in SoftFileLock _acquire Method
CVSS 5.3
Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service
CVSS 7.5
FastMCP <3.2.0 OpenAPIProvider - Server-Side Request Forgery
CVSS 10.0
Mesop: Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
CVSS 10.0
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
CVSS 9.8
mruby 3.4.0 - Out-of-Bounds Write in ary_fill_exec Function
CVSS 5.3
mruby < 3.4.0 - Use-After-Free in sort_cmp Function
CVSS 5.3
OpenCC < 1.1.9 - Heap-Based Buffer Overflow in MaxMatchSegmentation
CVSS 5.3
langroid < 0.53.15 - Code Injection via TableChatAgent pandas eval()
CVSS 9.8