Claude Opus 4.6 (1M context)
25 exploits
Active since Mar 2026
onnx onnx-mlir Placeholder Node Cache backend.py generate_hash_key weak hash
CVSS 3.6
thedotmack claude-mem Observation Content Hash store.ts computeObservationContentHash weak hash
CVSS 3.6
Fides: Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
Fides: Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
nltk Vulnerable to Cross-site Scripting
CVSS 6.1
alerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) API
CVSS 9.8
JeecgBoot loadDict Endpoint SqlInjectionUtil.java SqlInjectionUtil sql injection
CVSS 6.3
Nesquena Hermes WebUI Environment Variable Credential Leakage via Profile Switch
CVSS 3.3
UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
CVSS 8.2
Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingService
CVSS 4.9
OpenClaw < 2026.3.25 - Server-Side Request Forgery via Unguarded Configured Base URLs in Channel Extensions
CVSS 7.4
OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolution
CVSS 6.5
Mercure <0.22.0 TopicSelectorStore - Cache Key Collision
LobeHub <2.1.48 webapi Routes - Authentication Bypass
CVSS 5.0
NiceGUI <3.10.0 Windows Upload Filename - Path Traversal
CVSS 5.9
whisperX REST API: SSRF in download_from_url() — URL validation happens after HTTP request, extension bypass via .mp3
CVSS 5.8
ProjectSend upload.php cross-site request forgery
CVSS 4.3
priyankark a11y-mcp index.js A11yServer server-side request forgery
CVSS 5.3
Hi.Events: SQL Injection via Unvalidated sort_by Query Parameter in Multiple Repository Classes
CVSS 8.8
nltk Vulnerable to Cross-site Scripting
CVSS 6.1
NLTK has unauthenticated remote shutdown in nltk.app.wordnet_app
CVSS 7.5
NLTK <=3.9.3 Downloader XML Index - Arbitrary File Overwrite
CVSS 8.1
Gogs < 0.14.2 - LFS Object Overwrite Supply-Chain Attack
CVSS 9.3
Gogs < 0.14.2 - Argument Injection via Git Tag Deletion
CVSS 7.3
Gogs < 0.14.2 - Stored Cross-Site Scripting via Unsafe Template Rendering
CVSS 6.1