SecureWithUmer
74 exploits
Active since Jan 2026
OpenCode <1.0.216 - Command Injection
CVSS 8.8
Linux - Denial of Service via NULL Pointer Dereference in icmp_tag_validation
CVSS 5.5
MCPJam inspector < 1.4.3 - Remote Code Execution via HTTP Request
CVSS 9.8
Apache HTTP Server: http2: double free and possible RCE on early reset
CVSS 8.8
Apache Superset <6.0.0 - SQL Injection
CVSS 6.5
GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
CVSS 9.8
pypdf < 6.6.2 - Denial of Service via Infinite Loop in Outline Processing
CVSS 4.3
OpenClaw <2026.1.29 - Info Disclosure
CVSS 8.8
Wazuh Cluster vulnerable to Remote Code Execution via Insecure Deserialization
CVSS 9.1
Azure MCP Server - Authenticated Server-Side Request Forgery
CVSS 8.8
Ghost 3.24.0-6.19.0 - Info Disclosure
CVSS 9.4
Apache Camel: Unsafe Java deserialization in camel-consul ConsulRegistry allows arbitrary code execution via malicious values read from the Consul KV store
CVSS 8.8
ZoneMinder <=1.36.37, 1.37.61-1.38.0 - SQL Injection
CVSS 8.8
karnop realtime-collaboration-platform - Origin Validation Error in CORS Configuration
CVSS 7.4
RustFS 1.0.0-alpha.56-82 - Auth Bypass
CVSS 8.1
MCP Atlassian <0.17.0 - Path Traversal
CVSS 9.0
pac4j-jwt <4.5.9/5.7.9/6.3.3 - Auth Bypass
CVSS 9.1
MRCMS 3.1.2 - Unauthenticated Directory Enumeration via File Management Module
CVSS 5.3
EnTech Taiwan PowerStrip <=3.90.736 - Privilege Escalation
CVSS 7.8
Insufficient input validation leading to memory overread
CVSS 9.8
esiclivre/esiclivre <=0.2.2 - SQL Injection
CVSS 6.5
crypto: algif_aead - Revert to operating out-of-place
CVSS 7.8
tar < 7.5.11 - Path Traversal via Drive-Relative Symlink Target
CVSS 5.5
OpenClaw < 2026.2.25 - Symlink Traversal in agents.files Methods
CVSS 8.8
Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
CVSS 9.8