XZ1r0
78 exploits
Active since Jan 2026
react-server-dom-webpack 19.0.0-19.0.5, 19.1.0-19.1.6, 19.2.0-19.2.5 - DoS via Crafted HTTP Requests
CVSS 7.5
Next.js: Middleware / Proxy redirects can be cache-poisoned
CVSS 3.7
Next.js: Middleware / Proxy bypass in Pages Router applications using i18n
CVSS 7.5
Next.js: Middleware / Proxy bypass through dynamic route parameter injection
CVSS 8.1
Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
CVSS 7.5
Next.js: Cache poisoning in React Server Component responses
CVSS 5.4
Next.js: Denial of Service in the Image Optimization API
CVSS 5.9
Next.js: Server-side request forgery in applications using WebSocket upgrades
CVSS 8.6
Next.js: Denial of Service via connection exhaustion in applications using Cache Components
CVSS 7.5
Next.js: Cross-site scripting in beforeInteractive scripts with untrusted input
CVSS 6.1
Next.js: Cross-site scripting in App Router applications using CSP nonces
CVSS 4.7
Next.js: Cache poisoning via collisions in React Server Component cache-busting
CVSS 3.7
Google Chrome <147.0.7727.55 - Type Confusion
CVSS 8.8
Fortinet FortiClientEMS <7.4.4 - SQL Injection
CVSS 9.8
n8n 1.65.0-1.120.9 - Unauthenticated Arbitrary File Read via Form-Based Workflow Execution
CVSS 10.0
MCPJam inspector < 1.4.3 - Remote Code Execution via HTTP Request
CVSS 9.8
tar < 7.5.3 - Arbitrary File Overwrite and Symlink Poisoning via Hardlink and SymbolicLink Entries
CVSS 6.1
Apache HTTP Server: http2: double free and possible RCE on early reset
CVSS 8.8
Google Cloud Vertex AI SDK 1.98.0-1.131.0 - XSS
NGINX ngx_http_dav_module vulnerability
CVSS 8.2
nginxui/nginx_ui < 2.3.3 - Unauthenticated Sensitive Data Exposure via Backup Endpoint
CVSS 9.8
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
CVSS 7.5
Desktop Windows Manager - Info Disclosure
CVSS 5.5
Windows Error Reporting - Privilege Escalation
CVSS 7.8
Microsoft 365 Apps and Office - Security Feature Bypass via Untrusted Input
CVSS 7.8