VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3485 CVEsRSS

CVE-2026-63334Medium· 6.8PoC
5d ago

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with ENABLE_DRAWIO_PROXY=1 are vulnerable to server-side request forgery because src/main/java/com/mxgraph/online/Utils.java perfor…

▾ Twilightjgraph · drawioEPSS 0.32%via NVD
CVE-2026-63373Medium· 4.2PoC
5d ago

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callback handler in src/main/java/com/mxgraph/online/AbsAuth.java skips comparison of stateToken and cookieToken whenever IS_GAE is f…

▾ Twilightjgraph · drawioEPSS 0.15%via NVD
CVE-2026-76898High· 7.7PoC
5d ago

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.3.8, src/main/java/com/mxgraph/online/Utils.java checks IPv6 Unique Local Addresses in Utils.sanitizeUrl() by comparing the text prefixes fc00:: and…

▾ Midnightjgraph · drawioEPSS 0.48%via NVD
CVE-2026-77582Medium· 6.9PoC
5d ago

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_contr…

▾ Twilighttinyauthapp · tinyauthEPSS 0.48%via NVD
CVE-2026-77166Low· 2.4PoC
5d ago

The emoji field in the page emoji update endpoint does not properly validate user input

The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.

▾ TwilightNextcloud · CollectivesEPSS 0.27%via NVD
CVE-2026-77165Medium· 6.5PoC
5d ago

File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.

File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.

▾ TwilightNextcloud · ServerEPSS 0.37%via NVD
CVE-2026-53940High· 8.8PoC
5d ago

Conda is a system-level binary package and environment manager that runs on major operating systems and platforms

Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior to 26.5.2, parse_entry_point_def in conda/common/path/python.py accepted an unvalidated entry-point command from a n…

▾ Midnightconda · condaEPSS 0.55%via NVD
CVE-2026-55563High· 8.9PoC
5d ago

Feast is the open source feature store for AI and machine learning

Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_integration_tests.yml uses pull_request_target with the synchronize event and preserves ok-to-test, approved, or lgtm labels across…

▾ Midnightfeast-dev · feastEPSS 0.50%via NVD
CVE-2026-61628High· 8.1PoC
5d ago

nginx ignition is a user interface for the nginx web server

nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the …

▾ Midnightlucasdillmann · nginx-ignitionEPSS 0.43%via NVD
CVE-2026-61629High· 7.5PoC
5d ago

nginx ignition is a user interface for the nginx web server

nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptL…

▾ Midnightlucasdillmann · nginx-ignitionEPSS 0.61%via NVD
CVE-2026-55567High· 7.8PoC
5d ago

BleachBit cleans files to free disk space and to maintain privacy

BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that directory w…

▾ Midnightbleachbit · bleachbitEPSS 0.14%via NVD
CVE-2025-71420Medium· 4.3PoC
5d ago

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate …

▾ Twilightuvdesk · core-frameworkEPSS 0.30%via NVD
CVE-2026-94382Medium· 4.2PoC
5d ago

Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access

Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access. Attacker…

▾ Twilighthenrygd · beszelEPSS 0.30%via NVD
CVE-2026-94216Medium· 4.3PoC
5d ago

A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717

A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This vulnerability affects the function authorize of the file /usr/sbin/webserver of the component HTTP Header Handler. E…

▾ TwilightST Engineering iDirect · EvolutionEPSS 0.46%via NVD
CVE-2026-94211Low· 2.4PoC
5d ago

A vulnerability has been found in Hyve5 Leantime up to 3.9.8

A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/show.blade.php of the component Project Dashboard. Such manipulation leads to …

▾ TwilightHyve5 · LeantimeEPSS 0.35%via NVD
CVE-2026-94214Medium· 4.3PoC
5d ago

A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717

A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html of the component Management Service. Performing a manipulation of the arg…

▾ TwilightST Engineering iDirect · EvolutionEPSS 0.46%via NVD
CVE-2026-94210Low· 3.5PoC
5d ago

A flaw has been found in Hyve5 Leantime up to 3.9.8

A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the component Kanban Board. This manipulation causes cross site scri…

▾ TwilightHyve5 · LeantimeEPSS 0.36%via NVD
CVE-2026-92612Low· 1.0PoC
5d ago

In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8

In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can…

▾ TwilightEclipse Foundation · Eclipse iceoryx™EPSS 0.15%via NVD
CVE-2026-94152Medium· 4.3PoC
5d ago

A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025

A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the component User Profile API. The manipulation of the argument ID leads to authorizatio…

▾ TwilightOmega Solution · FBP Fulfillment by PeopleEPSS 0.37%via NVD
CVE-2025-12999Critical· 9.1PoC
5d ago

UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a truste…

UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a truste…

▾ AbyssalEclipse Foundation · Eclipse Open VSXEPSS 0.34%via NVD
CVE-2026-94151Medium· 5.3PoC
5d ago

A weakness has been identified in Omega Solution HRM OS up to 20260717

A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component Role Permission API. Executing a manipulation of the argument roleId can le…

▾ TwilightOmega Solution · HRM OSEPSS 0.68%via NVD
CVE-2026-94150Low· 2.4PoC
5d ago

A security flaw has been discovered in Omega Solution HRM OS up to 20260717

A security flaw has been discovered in Omega Solution HRM OS up to 20260717. The impacted element is an unknown function of the file /media/view/ of the component SVG File Upload. Performing a manipulation results in cross site scripting…

▾ TwilightOmega Solution · HRM OSEPSS 0.35%via NVD
CVE-2026-94149Medium· 4.3PoC
5d ago

A vulnerability was identified in Omega Solution HRM OS up to 20260717

A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of the file /role-permission/permission of the component Role Permission Retrieval Endpoint. Such manipulation of the arg…

▾ TwilightOmega Solution · HRM OSEPSS 0.38%via NVD
CVE-2026-94148Medium· 5.3PoC
5d ago

A vulnerability was determined in ScadaBR up to 1.1

A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the component Export Project Endpoint. This manipulation causes information disclosure. T…

▾ TwilightEPSS 0.54%via NVD
CVE-2026-94145Low· 3.5PoC
5d ago

A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0

A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Manag…

▾ Twilightxuxueli · xxl-jobEPSS 0.33%via NVD
CVE-2026-94144High· 7.3PoC
5d ago

A flaw has been found in drogonframework drogon up to 1.9.13

A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_lib/src/Criteria.cc of the component ORM. Executing a manipulation of the argument filter can lead to sql injection. …

▾ Midnightdrogonframework · drogonEPSS 0.43%via NVD
CVE-2026-94143High· 7.3PoC
5d ago

A vulnerability was detected in drogonframework drogon up to 1.9.13

A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected by this issue is the function Mapper::orderBy in the library Mapper.h of the component ORM Mapper. Performing a manipulation of the argument sort results in sq…

▾ Midnightdrogonframework · drogonEPSS 0.43%via NVD
CVE-2026-94142High· 8.8PoC
5d ago

A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200

A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of…

▾ MidnightBioStar · Temperature Monitor UtilityEPSS 0.18%via NVD
CVE-2026-94139High· 7.4PoC
5d ago

A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656

A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation o…

▾ MidnightChengdu Feiyuxing Technology · Feiyu Star RouterEPSS 2.0%via NVD
CVE-2026-94138Medium· 6.6PoC
5d ago

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation of the argument mac result…

▾ TwilightChengdu Feiyuxing Technology · Feiyu Star RouterEPSS 2.9%via NVD
CVEs tagged “exploit-available” — page 12 · VulnSea