VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3474 CVEsRSS

CVE-2026-73546High· 7.4PoC
4d ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values …

▾ Midnightenvoyproxy · envoyEPSS 0.60%via NVD
CVE-2026-73512High· 7.5PoC
4d ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream r…

▾ Midnightenvoyproxy · envoyEPSS 0.83%via NVD
CVE-2026-58269High· 8.1PoC
4d ago

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full a…

▾ MidnightSync-in · serverEPSS 0.22%via NVD
CVE-2026-52835High· 7.0PoC
4d ago

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_config handler and the database_file branch of import_database in plexpy/webserve.py join the attacker-controlled config_file.file…

▾ MidnightTautulli · TautulliEPSS 0.59%via NVD
CVE-2026-54915Medium· 5.4PoC
4d ago

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /auth/redirect endpoint in plexpy/webauth.py removes forward slashes from the user-controlled redirect_uri parameter but …

▾ TwilightTautulli · TautulliEPSS 0.37%via NVD
CVE-2026-49995Medium· 4.8PoC
4d ago

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter cron field stored in the newsletters table is inserted by data/interfaces/default/newsletter_config.html into a JavaScript str…

▾ TwilightTautulli · TautulliEPSS 0.60%via NVD
CVE-2026-55897High· 8.8PoC
4d ago

luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI

luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI. Prior to 1.1.2-6, the lu…

▾ Midnightopenwrt · luciEPSS 0.65%via NVD
CVE-2026-73548High· 7.5PoC
4d ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a configured non-WebSocket HTTP upgrade before the upstream accepts the upgrade.…

▾ Midnightenvoyproxy · envoyEPSS 0.66%via NVD
CVE-2026-48521Medium· 5.9PoC
4d ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ProdClusterManagerFactory::allocateConnPool dereferences transport_socket_options while selectin…

▾ Twilightenvoyproxy · envoyEPSS 0.70%via NVD
CVE-2026-58271Medium· 6.8PoC
4d ago

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/app/sync/register` accepts credentials and a TOTP code to register a desktop sync client. On a failed TOT…

▾ TwilightSync-in · serverEPSS 0.28%via NVD
CVE-2026-91166Medium· 5.7PoC
4d ago

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown without the presenting hop identity and instead pas…

▾ Twilightwarp-tech · warpgateEPSS 0.28%via NVD
CVE-2026-63330High· 7.7PoC
4d ago

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session aut…

▾ Midnightwarp-tech · warpgateEPSS 0.45%via NVD
CVE-2026-61746Medium· 5.3PoC
4d ago

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginSettingDetail set GlobalSettingsPermissions without the IsAuthenticated permission used by the project default an…

▾ Twilightinventree · InvenTreeEPSS 0.40%via NVD
CVE-2026-94411High· 8.8PoC
4d ago

jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles

jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST request with type=UserRole, their own us…

▾ Midnightjishenghua · jshERPEPSS 0.52%via NVD
CVE-2026-94413Medium· 6.5PoC
4d ago

jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user

jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user. Attackers can request arbitrary user information by supplying user IDs to…

▾ Twilightjishenghua · jshERPEPSS 0.55%via NVD
CVE-2026-94412High· 8.8PoC
4d ago

jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password

jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password. Attackers can submit a request with an arbitrary target user ID to …

▾ Midnightjishenghua · jshERPEPSS 0.55%via NVD
CVE-2026-94496High· 8.3PoC
4d ago

jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles

jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles. Attackers can exploit the /role/update and /role/delete endpoints to esca…

▾ Midnightjishenghua · jshERPEPSS 0.46%via NVD
CVE-2026-94495High· 7.1PoC
4d ago

jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration

jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration. Attackers can rewrite or delete tenant-wide settings covering co…

▾ Midnightjishenghua · jshERPEPSS 0.44%via NVD
CVE-2026-94494Medium· 5.0PoC
4d ago

jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint

jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can iterate the primary key to enumerate and access sensitive…

▾ Twilightjishenghua · jshERPEPSS 0.37%via NVD
CVE-2026-94497High· 8.3PoC
4d ago

jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types

jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object …

▾ Midnightjishenghua · jshERPEPSS 0.46%via NVD
CVE-2026-94414Medium· 5.4PoC
4d ago

jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions

jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions. Attackers can supply arbitrary roleId and btnStr parameter…

▾ Twilightjishenghua · jshERPEPSS 0.38%via NVD
CVE-2026-94501High· 8.8PoC
4d ago

jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks

jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipul…

▾ Midnightjishenghua · jshERPEPSS 0.55%via NVD
CVE-2026-61745Medium· 4.3PoC
4d ago

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in src/backend/InvenTree/machine/api.py uses IsAuthenticatedOrReadScope without requiring the ADMIN role used by other …

▾ Twilightinventree · InvenTreeEPSS 0.43%via NVD
CVE-2026-94488High· 8.2PoC
4d ago

Telegram Desktop before 6.9.4 allows XSS in the HTML exporter

Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. How…

▾ MidnightTelegram · Telegram DesktopEPSS 0.20%via NVD
CVE-2026-77561Medium· 5.3PoC
4d ago

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to fill MaxLoginAttemptRecords and activate a globa…

▾ Twilighttinyauthapp · tinyauthEPSS 0.86%via NVD
CVE-2026-63116High· 8.8PoC
4d ago

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. From 10.1.0 until 10.1.1, src/services/permission/valve/rules-map.ts omits RECORD_ACTION.PATCH_MULTI from RULES_MAP. When…

▾ MidnightdeepstreamIO · deepstream.ioEPSS 0.51%via NVD
CVE-2026-62866Medium· 6.2PoC
4d ago

Dasel is a command-line tool and library for querying, modifying, and transforming data structures

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.2, selector/lexer/tokenize.go parseCurRune advances the input index across trailing whitespace and then reads the s…

▾ TwilightTomWright · daselEPSS 0.19%via NVD
CVE-2026-62987Medium· 5.8PoC
4d ago

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the operator-…

▾ Twilightfabiolb · fabioEPSS 0.20%via NVD
CVE-2026-61674Critical· 9.2PoC
4d ago

Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows

Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0 until 5.0.8, plugins/out_forward/forward.c secure_forward_pong copies the server-controlled PONG[2] reason into the …

▾ Abyssalfluent · fluent-bitEPSS 0.85%via NVD
CVE-2026-63416Low· 3.7PoC
4d ago

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, src/main/java/com/mxgraph/online/ExportProxyServlet.java uses request.getPathInfo() to build a proxyPath and appends it directly to EXPORT_URL …

▾ Twilightjgraph · drawioEPSS 0.37%via NVD
CVEs tagged “exploit-available” — page 11 · VulnSea