VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3464 CVEsRSS

CVE-2026-88404Critical· 9.8PoC
4d ago

A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

▾ AbyssalEPSS 0.86%via NVD
CVE-2026-88402Critical· 9.8PoC
4d ago

A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.

A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.

▾ AbyssalEPSS 0.47%via NVD
CVE-2026-67827Critical· 9.8PoC
4d ago

Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffm…

Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffm…

▾ AbyssalEPSS 0.27%via NVD
CVE-2026-59816Medium· 4.3PoC
4d ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, the GET /api/transcribe/:id and POST /api/transcribe/:id handlers in packages/server/src/routes/api/transcribe.ts o…

▾ Twilightlaurent22 · joplinEPSS 0.36%via NVD
CVE-2026-55179Medium· 6.5PoC
4d ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /items/:id/content route in packages/server/src/routes/index/items.ts loads item content from a…

▾ Twilightlaurent22 · joplinEPSS 0.26%via NVD
CVE-2026-55105High· 7.7PoC
4d ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, packages/renderer/MdToHtml/rules/fountain.ts passes HTML generated by the vendored fountain.js renderer …

▾ Midnightlaurent22 · joplinEPSS 0.44%via NVD
CVE-2026-49453High· 7.0PoC
4d ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, Joplin accepts synchronized resource metadata whose id or file_extension contains parent-directory or pa…

▾ Midnightlaurent22 · joplinEPSS 0.41%via NVD
CVE-2026-49450High· 7.1PoC
4d ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName from packages/app-desktop/package.json, so the generated app-update.…

▾ Midnightlaurent22 · joplinEPSS 0.18%via NVD
CVE-2026-94572Critical· 9.4PoC
4d ago

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and t…

▾ AbyssalOpenStack · OctaviaEPSS 0.53%via NVD
CVE-2026-73553High· 7.5PoC
4d ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_parameters_in_path_matching is enabled, Envoy's router strips the semicolon suffix befo…

▾ Midnightenvoyproxy · envoyEPSS 0.52%via NVD
CVE-2026-77519Medium· 5.4PoC
4d ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, the /chat/api/mcp authentication path looks up an ApplicationApiKey using only its secret and active status, without enforcing the is_permanent and expire_ti…

▾ Twilight1Panel-dev · MaxKBEPSS 0.28%via NVD
CVE-2026-58272Medium· 5.3PoC
4d ago

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1 contain an observable timing discrepancy in the login endpoint because authentication attempts for nonexistent accou…

▾ TwilightSync-in · serverEPSS 0.34%via NVD
CVE-2026-58270Medium· 6.5PoC
4d ago

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string into a `RegExp` with no complexity validation. A catastrophic…

▾ TwilightSync-in · serverEPSS 0.35%via NVD
CVE-2026-88405Critical· 9.8PoC
4d ago

A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-function.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-function.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

▾ AbyssalEPSS 0.27%via NVD
CVE-2026-77518Medium· 5.0PoC
4d ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows another user's active MCP tool_id in the same workspace can retrieve the hidden tool through the tool-detail route because …

▾ Twilight1Panel-dev · MaxKBEPSS 0.27%via NVD
CVE-2026-88403Medium· 6.5PoC
4d ago

A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.

A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.

▾ TwilightEPSS 0.40%via NVD
CVE-2026-77525Medium· 4.2PoC
4d ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, management chat-record routes authorize the path application_id but load records using global chat_id and chat_record_id values without confirming that the c…

▾ Twilight1Panel-dev · MaxKBEPSS 0.19%via NVD
CVE-2026-77522Medium· 4.3PoC
4d ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document import and synchronization crawler passes an authenticated workspace user's URL to Fork.fork, which calls requests.get wit…

▾ Twilight1Panel-dev · MaxKBEPSS 0.28%via NVD
CVE-2026-77521Critical· 10.0PoC
4d ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits exe…

▾ Abyssal1Panel-dev · MaxKBEPSS 1.0%via NVD
CVE-2026-77517Medium· 5.4PoC
4d ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph operate routes authorize only knowledge_id in the request path, then query the target Document by document_id or Paragraph…

▾ Twilight1Panel-dev · MaxKBEPSS 0.23%via NVD
CVE-2026-73546High· 7.4PoC
4d ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values …

▾ Midnightenvoyproxy · envoyEPSS 0.60%via NVD
CVE-2026-73512High· 7.5PoC
4d ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream r…

▾ Midnightenvoyproxy · envoyEPSS 0.83%via NVD
CVE-2026-58269High· 8.1PoC
4d ago

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full a…

▾ MidnightSync-in · serverEPSS 0.22%via NVD
CVE-2026-52835High· 7.0PoC
4d ago

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_config handler and the database_file branch of import_database in plexpy/webserve.py join the attacker-controlled config_file.file…

▾ MidnightTautulli · TautulliEPSS 0.59%via NVD
CVE-2026-54915Medium· 5.4PoC
4d ago

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /auth/redirect endpoint in plexpy/webauth.py removes forward slashes from the user-controlled redirect_uri parameter but …

▾ TwilightTautulli · TautulliEPSS 0.37%via NVD
CVE-2026-49995Medium· 4.8PoC
4d ago

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter cron field stored in the newsletters table is inserted by data/interfaces/default/newsletter_config.html into a JavaScript str…

▾ TwilightTautulli · TautulliEPSS 0.60%via NVD
CVE-2026-55897High· 8.8PoC
4d ago

luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI

luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI. Prior to 1.1.2-6, the lu…

▾ Midnightopenwrt · luciEPSS 0.65%via NVD
CVE-2026-73548High· 7.5PoC
4d ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a configured non-WebSocket HTTP upgrade before the upstream accepts the upgrade.…

▾ Midnightenvoyproxy · envoyEPSS 0.66%via NVD
CVE-2026-48521Medium· 5.9PoC
4d ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ProdClusterManagerFactory::allocateConnPool dereferences transport_socket_options while selectin…

▾ Twilightenvoyproxy · envoyEPSS 0.70%via NVD
CVE-2026-58271Medium· 6.8PoC
4d ago

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/app/sync/register` accepts credentials and a TOTP code to register a desktop sync client. On a failed TOT…

▾ TwilightSync-in · serverEPSS 0.28%via NVD
CVEs tagged “exploit-available” — page 10 · VulnSea