keraattin
9 exploits
Active since Dec 2025
Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
CVSS 9.8
OpenRemote is Vulnerable to Expression Injection
CVSS 9.9
Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint
CVSS 9.8
Jellyfin: Potential RCE via subtitle upload path traversal + .strm chain
CVSS 9.9
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
CVSS 9.8
Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
CVSS 8.8
Pi-hole FTL affected by Remote Code Execution (RCE) via dns.upstreams Newline Injection
CVSS 8.8
Fortinet FortiClientEMS 7.4.5-7.4.6 - Command Injection
CVSS 9.8
MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed
CVSS 7.5