XZ1r0
78 exploits
Active since Jan 2026
iOS and iPadOS < 18.7.7 - Use-After-Free
CVSS 7.1
mm/mseal: update VMA end correctly on merge
crypto: algif_aead - Revert to operating out-of-place
CVSS 7.8
Microsoft Windows 11 Version 24H2 - Windows Kernel Elevation of Privilege Vulnerability
CVSS 7.8
Google Android - Heap Buffer Overflow
CVSS 9.8
ActivityManagerService - Privilege Escalation
CVSS 8.4
Google Android <16-qpr2 - Auth Bypass
CVSS 8.8
Cisco Catalyst SD-WAN - Auth Bypass
CVSS 10.0
GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
CVSS 9.8
GNU inetutils through 2.7 - Buffer Overflow
CVSS 9.8
ProFTPD < 1.3.10rc1 - Remote Code Execution
CVSS 8.1
Palo Alto PAN-OS User-ID Authentication Portal - Unauthenticated Root RCE
CVSS 9.8
Langflow validate exec_globals - Unauthenticated Root Code Execution
CVSS 9.8
Lenovo Diagnostics < 5.26.0 and Lenovo Vantage < 4.7.1.4 - Authenticated Arbitrary File Write via Hardware Scan
CVSS 7.1
Snow Monkey Forms <12.0.3 - Path Traversal
CVSS 9.8
WPvivid Backup & Migration <0.9.123 - Unauthenticated RCE
CVSS 9.8
BeyondTrust Privileged Remote Access < 25.1 and Remote Support < 25.3.2 - Unauthenticated Remote Code Execution
CVSS 9.8
PostgreSQL <18.2, 17.8, 16.12, 15.16, 14.21 - RCE
CVSS 8.8
Windows Notepad App - Command Injection
CVSS 7.8
Windows 10/11 Privilege Escalation via Untrusted Search Path
CVSS 7.0
Claude Code < 2.0.65 - Unauthenticated API Key Exfiltration via Malicious Repository Settings
CVSS 7.5
SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution
CVSS 9.8
OpenCode <1.0.216 - Command Injection
CVSS 8.8
React Server Components 19.0.0-19.0.4 19.1.0-19.1.5 19.2.0-19.2.4 - Denial of Service via Crafted HTTP Requests
CVSS 7.5
pac4j-jwt <4.5.9/5.7.9/6.3.3 - Auth Bypass
CVSS 9.1