Claude Opus 4.6
28 exploits
Active since Apr 2024
Authentication Bypass in prefecthq/prefect
CVSS 7.5
PrefectHQ prefect Health Check API health endswith improper authentication
CVSS 5.3
OpenC3 COSMOS: Arbitrary write to plugins directory via path-traversed config filenames
CVSS 4.3
OpenC3 COSMOS: Arbitrary write to plugins directory via path-traversed config filenames
CVSS 4.3
wzy Media Recencio Book Reviews <1.66.0 - XSS
CVSS 6.5
OpenClaw < 2026.3.2 - Filesystem Boundary Bypass in Image Tool
CVSS 6.5
n8n <2.10.1/2.9.3/1.123.22 - XSS
CVSS 5.4
n8n <2.10.1/2.9.3/1.123.22 - Command Injection
CVSS 9.9
n8n <2.10.1/2.9.3/1.123.22 - XSS
CVSS 5.4
web-auth/webauthn-lib <5.2.4 - Auth Bypass
CVSS 5.4
MyTube <1.8.69 Database Import - Application Takeover
CVSS 8.8
dubydu sqlite-mcp entry.py extract_to_json sql injection
CVSS 7.3
lm-sys fastchat Worker API Endpoint api_generate resource consumption
CVSS 5.3
OpenViking <=0.1.18 - Privilege Escalation
CVSS 9.8
NiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustion
CVSS 7.5
web-auth/webauthn-lib <5.2.4 - Auth Bypass
CVSS 5.4
mcp-memory-service <10.21.0 - Info Disclosure
CVSS 5.3
locutus < 3.0.0 - Remote Code Execution via call_user_func_array Eval Injection
CVSS 8.1
Vito <3.20.3 - Privilege Escalation
CVSS 9.9
pjsip < 2.17 - Use-After-Free in Event Subscription Framework
CVSS 7.5
pjsip < 2.17 - Stack-based Buffer Overflow in pjmedia-codec RTP Payload Parser
CVSS 7.5
Gogs < 0.14.2 - Authenticated Stored Cross-Site Scripting via Data URI in Comments and Issues
CVSS 8.7
kaniko 1.25.4-1.25.10 - Path Traversal
CVSS 8.2
n8n <2.10.1/2.9.3/1.123.22 - Code Injection
CVSS 9.0
n8n <2.10.1/2.9.3/1.123.22 - Command Injection
CVSS 9.9