SecureWithUmer
74 exploits
Active since Jan 2026
Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
CVSS 9.8
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
CVSS 7.5
Fortinet FortiClientEMS 7.4.5-7.4.6 - Command Injection
CVSS 9.8
GitHub Enterprise Server RCE via Git Push Option Injection
CVSS 8.8
Local Privilege Escalation in snapd
CVSS 7.8
Pix for WooCommerce <=1.5.0 - Arbitrary File Upload
CVSS 9.8
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVSS 4.8
Microsoft Defender Elevation of Privilege Vulnerability
CVSS 7.8
PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
CVSS 8.8
LiteLLM: SQL injection in Proxy API key verification
CVSS 9.8
LiteLLM: Authenticated command execution via MCP stdio test endpoints
CVSS 8.8
NGINX Plus and NGINX Open Source - Heap-based Buffer Overflow in ngx_http_rewrite_module
CVSS 8.1
Next.js: Server-side request forgery in applications using WebSocket upgrades
CVSS 8.6
Exim 4.97-4.99.2 - Unauthenticated Use-After-Free via TLS Close Notify During CHUNKING Transfer
CVSS 9.8
Microsoft Windows 11 Version 24H2 - Windows BitLocker Security Feature Bypass Vulnerability
CVSS 6.8
Microsoft SharePoint Remote Code Execution Vulnerability
CVSS 8.8
net: skbuff: propagate shared-frag marker through frag-transfer helpers
CVSS 7.8
LiteSpeed cPanel Plugin < 2.4.5 - Privilege Escalation via Redis Feature Mishandling
CVSS 9.8
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
CVSS 6.5
Langflow - Path Traversal Arbitrary File Write via upload_user_file
CVSS 8.8
Divi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role'
CVSS 9.8
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
CVSS 9.8
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
CVSS 9.8
net: skbuff: preserve shared-frag marker during coalescing
CVSS 8.8