Vulnerabilities & exploits
Exploit catalogue
Zero-days from our own research and n-days recovered from intrusions. Each write-up gives the class, the impact, how to detect it, and a link to public proof-of-concept.
Exploits
27
20 targets
With a CVE
27
assigned
In CISA KEV
0
known exploited
With full report
1
linked teardown
org.http4s:http4s-scala-xml_2.12 1
- org.http4s:http4s-scala-xml_2.12 remote code execution (CVE-2026-61741) CVSS 9.3 CriticalEPSS 0.29% (p20)
CVE-2026-61741n-day Arbitrary code execution against the vulnerable build September 24, 2026
io.moquette:moquette-broker 1
- io.moquette:moquette-broker remote code execution (CVE-2026-85724) CVSS 9.6 CriticalEPSS 0.27% (p17)
CVE-2026-85724n-day Arbitrary code execution against the vulnerable build September 23, 2026
lightrag-hku 1
- lightrag-hku remote code execution (CVE-2026-85734) CVSS 9.1 CriticalEPSS 0.36% (p27)
CVE-2026-85734n-day Arbitrary code execution against the vulnerable build September 22, 2026
mcp-atlassian 1
- mcp-atlassian remote code execution (CVE-2026-77244) CVSS 10.0 CriticalEPSS 0.50% (p42)
CVE-2026-77244n-day Arbitrary code execution against the vulnerable build September 22, 2026
lmdeploy 2
- lmdeploy remote code execution (CVE-2025-66455) CVSS 9.8 CriticalEPSS 0.70% (p52)
CVE-2025-66455n-day Arbitrary code execution from loading untrusted input September 18, 2026 - lmdeploy remote code execution (CVE-2026-33625) CVSS 8.8 HighEPSS 0.24% (p16)
CVE-2026-33625n-day Arbitrary code execution against the vulnerable build September 18, 2026
org.opencastproject:opencast-engage-paella-player-7 1
- org.opencastproject:opencast-engage-paella-player-7 remote code execution (CVE-2026-77615) CVSS 8.7 HighEPSS 0.39% (p33)
CVE-2026-77615n-day Arbitrary code execution against the vulnerable build September 17, 2026
@vendure/core 1
- @vendure/core remote code execution (CVE-2026-63472) CVSS 9.1 Critical
CVE-2026-63472n-day Arbitrary code execution against the vulnerable build September 17, 2026
djust 1
- djust remote code execution (CVE-2026-61594) CVSS 9.1 CriticalEPSS 0.43% (p36)
CVE-2026-61594n-day Arbitrary code execution against the vulnerable build September 16, 2026
org.http4s:http4s-ember-core_2.12 1
- org.http4s:http4s-ember-core_2.12 remote code execution (CVE-2026-69204) CVSS 9.2 CriticalEPSS 0.33% (p26)
CVE-2026-69204n-day Arbitrary code execution against the vulnerable build September 15, 2026
@zereight/mcp-gitlab 1
- @zereight/mcp-gitlab remote code execution (CVE-2026-61568) CVSS 9.6 CriticalEPSS 0.32% (p25)
CVE-2026-61568n-day Arbitrary code execution against the vulnerable build September 15, 2026
yayson 1
- yayson remote code execution (CVE-2026-61534) CVSS 9.1 Critical
CVE-2026-61534n-day Arbitrary code execution against the vulnerable build September 14, 2026
morgan 1
- morgan remote code execution (CVE-2026-87859) CVSS 5.3 MediumEPSS 0.41% (p33)
CVE-2026-87859n-day Arbitrary code execution against the vulnerable build September 11, 2026
open-webui 1
- open-webui remote code execution (CVE-2026-88006) CVSS 6.5 Medium
CVE-2026-88006n-day Arbitrary code execution against the vulnerable build September 10, 2026
httpx2 3
- httpx2 remote code execution (CVE-2026-84378) CVSS 5.9 Medium
CVE-2026-84378n-day Arbitrary code execution against the vulnerable build September 2, 2026 - httpx2 remote code execution (CVE-2026-84380) CVSS 5.6 Medium
CVE-2026-84380n-day Arbitrary code execution against the vulnerable build September 2, 2026 - httpx2 remote code execution (CVE-2026-84382) CVSS 7.5 High
CVE-2026-84382n-day Arbitrary code execution against the vulnerable build September 2, 2026
gitpython 1
- gitpython remote code execution (CVE-2026-78676) CVSS 9.8 Critical
CVE-2026-78676n-day Arbitrary code execution against the vulnerable build August 25, 2026
nltk 2
- nltk remote code execution (CVE-2026-78683) CVSS 9.6 Critical
CVE-2026-78683n-day Arbitrary code execution from loading untrusted input August 25, 2026 - nltk remote code execution (CVE-2026-79657) CVSS 9.8 Critical
CVE-2026-79657n-day Arbitrary code execution from loading untrusted input August 25, 2026
vllm 4
- vllm remote code execution (CVE-2026-71486) CVSS 4.3 Medium
CVE-2026-71486n-day Arbitrary code execution from loading untrusted input August 17, 2026 - vllm remote code execution (CVE-2026-73560) CVSS 6.5 Medium
CVE-2026-73560n-day Arbitrary code execution against the vulnerable build August 17, 2026 - vllm remote code execution (CVE-2026-73557) CVSS 6.3 Medium
CVE-2026-73557n-day Arbitrary code execution from loading untrusted input August 13, 2026 - vllm remote code execution (CVE-2026-73558) CVSS 5.3 Medium
CVE-2026-73558n-day Arbitrary code execution against the vulnerable build August 13, 2026
@mockoon/commons-server 1
- @mockoon/commons-server remote code execution (CVE-2026-59148) CVSS 8.8 High
CVE-2026-59148n-day Arbitrary code execution against the vulnerable build July 9, 2026
Linux kernel 1
- getroot — AF_ALG page-cache LPE and container escape CVSS 8.8 High
CVE-2026-31431n-day Local privilege escalation to root, with escape from a container to the host June 15, 2026
PyYAML 1
- PyYAML FullLoader deserialization RCE (CVE-2020-14343) CVSS 9.8 Critical
CVE-2020-14343n-day Arbitrary code execution from loading untrusted input February 9, 2021
No exploits match that filter.
Proof of concept & handling
Where a proof-of-concept is already public, the write-up links straight to it. Everything catalogued here is real and some of it is working exploit code, so run any of it in a disposable VM with no route to a network you use. For anything without a public link, email security@kinryu.sh and say who you are and what you need it for.