HORKimhab
260 exploits
Active since Oct 1988
Cisco Secure Workload Unauthorized API Access Vulnerability
CVSS 10.0
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
CVSS 9.8
sealed-env: TOTP secret embedded in unseal token payload (enterprise mode)
CVSS 9.1
Camel-infinispan: camel-infinispan: remote code execution via unsafe deserialization
CVSS 7.5
User Language Switch <1.6.10 - SSRF
CVSS 5.5
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
CVSS 7.3
JeecgBoot mLogin Endpoint LoginController.java authorization
CVSS 3.7
Spring Framework 5.3.x-5.3.43 6.1.x-6.1.21 6.2.x-6.2.9 - Path Traversal via Static Resource Handling
CVSS 5.9
VM2 Sandbox Breakout Through __lookupGetter__
CVSS 9.8
LiteLLM < 2026-04-08 - Remote Code Execution via Guardrails Test Custom Code Endpoint
CVSS 8.8