VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3522 CVEsRSS

CVE-2026-55567High· 7.8PoC
5d ago

BleachBit cleans files to free disk space and to maintain privacy

BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that directory w…

▾ Midnightbleachbit · bleachbitEPSS 0.14%via NVD
CVE-2025-71420Medium· 4.3PoC
5d ago

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate …

▾ Twilightuvdesk · core-frameworkEPSS 0.30%via NVD
CVE-2026-94382Medium· 4.2PoC
5d ago

Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access

Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access. Attacker…

▾ Twilighthenrygd · beszelEPSS 0.30%via NVD
CVE-2026-94216Medium· 4.3PoC
5d ago

A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717

A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This vulnerability affects the function authorize of the file /usr/sbin/webserver of the component HTTP Header Handler. E…

▾ TwilightST Engineering iDirect · EvolutionEPSS 0.46%via NVD
CVE-2026-94211Low· 2.4PoC
5d ago

A vulnerability has been found in Hyve5 Leantime up to 3.9.8

A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/show.blade.php of the component Project Dashboard. Such manipulation leads to …

▾ TwilightHyve5 · LeantimeEPSS 0.35%via NVD
CVE-2026-94214Medium· 4.3PoC
5d ago

A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717

A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html of the component Management Service. Performing a manipulation of the arg…

▾ TwilightST Engineering iDirect · EvolutionEPSS 0.46%via NVD
CVE-2026-94210Low· 3.5PoC
5d ago

A flaw has been found in Hyve5 Leantime up to 3.9.8

A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the component Kanban Board. This manipulation causes cross site scri…

▾ TwilightHyve5 · LeantimeEPSS 0.36%via NVD
CVE-2026-92612Low· 1.0PoC
5d ago

In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8

In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can…

▾ TwilightEclipse Foundation · Eclipse iceoryx™EPSS 0.15%via NVD
CVE-2026-94152Medium· 4.3PoC
5d ago

A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025

A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the component User Profile API. The manipulation of the argument ID leads to authorizatio…

▾ TwilightOmega Solution · FBP Fulfillment by PeopleEPSS 0.37%via NVD
CVE-2025-12999Critical· 9.1PoC
5d ago

UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a truste…

UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a truste…

▾ AbyssalEclipse Foundation · Eclipse Open VSXEPSS 0.34%via NVD
CVE-2026-94151Medium· 5.3PoC
5d ago

A weakness has been identified in Omega Solution HRM OS up to 20260717

A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component Role Permission API. Executing a manipulation of the argument roleId can le…

▾ TwilightOmega Solution · HRM OSEPSS 0.68%via NVD
CVE-2026-94150Low· 2.4PoC
5d ago

A security flaw has been discovered in Omega Solution HRM OS up to 20260717

A security flaw has been discovered in Omega Solution HRM OS up to 20260717. The impacted element is an unknown function of the file /media/view/ of the component SVG File Upload. Performing a manipulation results in cross site scripting…

▾ TwilightOmega Solution · HRM OSEPSS 0.35%via NVD
CVE-2026-94149Medium· 4.3PoC
5d ago

A vulnerability was identified in Omega Solution HRM OS up to 20260717

A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of the file /role-permission/permission of the component Role Permission Retrieval Endpoint. Such manipulation of the arg…

▾ TwilightOmega Solution · HRM OSEPSS 0.38%via NVD
CVE-2026-94148Medium· 5.3PoC
5d ago

A vulnerability was determined in ScadaBR up to 1.1

A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the component Export Project Endpoint. This manipulation causes information disclosure. T…

▾ TwilightEPSS 0.54%via NVD
CVE-2026-94145Low· 3.5PoC
5d ago

A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0

A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Manag…

▾ Twilightxuxueli · xxl-jobEPSS 0.33%via NVD
CVE-2026-94144High· 7.3PoC
5d ago

A flaw has been found in drogonframework drogon up to 1.9.13

A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_lib/src/Criteria.cc of the component ORM. Executing a manipulation of the argument filter can lead to sql injection. …

▾ Midnightdrogonframework · drogonEPSS 0.43%via NVD
CVE-2026-94143High· 7.3PoC
5d ago

A vulnerability was detected in drogonframework drogon up to 1.9.13

A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected by this issue is the function Mapper::orderBy in the library Mapper.h of the component ORM Mapper. Performing a manipulation of the argument sort results in sq…

▾ Midnightdrogonframework · drogonEPSS 0.43%via NVD
CVE-2026-94142High· 8.8PoC
5d ago

A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200

A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of…

▾ MidnightBioStar · Temperature Monitor UtilityEPSS 0.18%via NVD
CVE-2026-94139High· 7.4PoC
5d ago

A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656

A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation o…

▾ MidnightChengdu Feiyuxing Technology · Feiyu Star RouterEPSS 2.0%via NVD
CVE-2026-94138Medium· 6.6PoC
5d ago

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation of the argument mac result…

▾ TwilightChengdu Feiyuxing Technology · Feiyu Star RouterEPSS 2.9%via NVD
CVE-2026-94129High· 8.8PoC
5d ago

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results…

▾ MidnightBioStar · VALKYRIE AURORAEPSS 0.18%via NVD
CVE-2026-94128High· 8.8PoC
5d ago

A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500

A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-…

▾ MidnightBioStar · VIVID LED DJEPSS 0.18%via NVD
CVE-2026-94110High· 7.3PoC
5d ago

A security vulnerability has been detected in QCMS up to 6.0.6

A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulation of the argument ID leads to sql in…

▾ MidnightEPSS 0.41%via NVD
CVE-2026-94102Medium· 4.3PoC
5d ago

A flaw has been found in WuzhiCMS up to 4.1.0

A flaw has been found in WuzhiCMS up to 4.1.0. This affects an unknown function of the file /index.php?m=member&v=Login of the component Login. This manipulation of the argument forward causes open redirect. The attack can be initiated r…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-94101Critical· 9.9PoC
5d ago

A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246

A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It…

▾ AbyssalNetcore · NBR200V2EPSS 0.80%via NVD
CVE-2026-94103Medium· 4.7PoC
5d ago

A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2

A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2. This impacts the function eval of the file roocms/site_pagePHP.php of the component Frontend Rendering. Such manipulation of the argument content leads to code injection.…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-94100Critical· 9.9PoC
5d ago

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX…

▾ AbyssalNetcore · NBR200V2EPSS 0.80%via NVD
CVE-2026-94099Critical· 9.9PoC
5d ago

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results…

▾ AbyssalNetcore · NBR200V2EPSS 3.2%via NVD
CVE-2026-94098Critical· 9.1PoC
5d ago

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING…

▾ AbyssalNetcore · NBR200V2EPSS 3.7%via NVD
CVE-2026-94096Critical· 9.9PoC
5d ago

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4…

▾ AbyssalNetcore · NBR200V2EPSS 3.2%via NVD
CVEs tagged “exploit-available” — page 13 · VulnSea