rootdirective-sec
8 exploits
Active since Jan 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
CVSS 9.8
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
CVSS 9.8
Wholesale Suite <=2.2.6 - Privilege Escalation
CVSS 7.2
pac4j-jwt <4.5.9/5.7.9/6.3.3 - Auth Bypass
CVSS 9.1
MaxSite CMS <109.1 - Code Injection
CVSS 7.3
wpForo Forum <2.4.14 - SQL Injection
CVSS 7.5
WPvivid Backup & Migration <0.9.123 - Unauthenticated RCE
CVSS 9.8
MCPJam inspector <1.4.2 - RCE
CVSS 9.8