VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3523 CVEsRSS

CVE-2026-94096Critical· 9.9PoC
5d ago

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4…

▾ AbyssalNetcore · NBR200V2EPSS 3.2%via NVD
CVE-2026-94095Critical· 9.9PoC
5d ago

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the a…

▾ AbyssalNetcore · NBR200V2EPSS 3.2%via NVD
CVE-2026-55071High· 8.4PoC
5d ago

MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design

MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled input directly into a Stata command stri…

▾ MidnightSepineTam · mcp-for-stataEPSS 0.25%via NVD
CVE-2026-94094Medium· 4.3PoC
6d ago

A flaw has been found in OpenClaw up to 2026.9.5

A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the component Canvas Host Route. Executing a manipulation can lead to denial of servic…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-94093Medium· 6.3PoC
6d ago

A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0

A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/load_replay_buffer/VecNormalize.load of the file save_util.py. Such manipulation leads to deserialization. It is possi…

▾ TwilightDLR-RM · stable-baselines3EPSS 0.45%via NVD
CVE-2026-94092Medium· 5.5PoC
6d ago

A vulnerability was detected in dmlc dgl up to 2.1.0

A vulnerability was detected in dmlc dgl up to 2.1.0. This impacts the function load_info/_read_torch_data of the file utils.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remot…

▾ Twilightdmlc · dglEPSS 0.34%via NVD
CVE-2026-94091Medium· 5.5PoC
6d ago

A weakness has been identified in piskvorky gensim up to 4.4.0

A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Loader. This manipulation of the argument fname causes deserialization. It is po…

▾ Twilightpiskvorky · gensimEPSS 0.34%via NVD
CVE-2026-94089Critical· 10.0PoC
6d ago

A vulnerability was determined in D-Link DIR-868L 2.01b05

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lea…

▾ AbyssalD-Link · DIR-868LEPSS 1.9%via NVD
CVE-2026-94051Medium· 6.3PoC
6d ago

A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d

A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNode of the file local_servers/pdf-tools-mcp/pdf_tools_mcp/server.py of the compo…

▾ Twilight0717376 · cowork_benchEPSS 0.37%via NVD
CVE-2026-94049Medium· 4.3PoC
6d ago

A flaw has been found in 06ketan slideshot up to 4.4.0

A flaw has been found in 06ketan slideshot up to 4.4.0. This impacts the function render_slides of the file packages/cli/src/renderer.ts. This manipulation of the argument htmlPath causes path traversal. The attack is possible to be carr…

▾ Twilight06ketan · slideshotEPSS 0.47%via NVD
CVE-2026-94048Medium· 6.6PoC
6d ago

A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0

A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege man…

▾ TwilightCodeAstro · QR Code Attendance Management SystemEPSS 0.40%via NVD
CVE-2026-94047Medium· 6.3PoC
6d ago

A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32

A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32. The impacted element is the function importTemplate of the file src/services/templateService.ts of the component Template Import Endpoint. The manipulation lea…

▾ Twilightsamanhappy · MCPHubEPSS 0.43%via NVD
CVE-2026-94046Medium· 4.3PoC
6d ago

A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8

A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8. The affected element is the function get_file_snippet of the file getFileSnippet.ts of the component MCP Tool. Executing a manipulation of the argument projectRootPat…

▾ Twilight0215AndrewFeng · ACE-MCPEPSS 0.47%via NVD
CVE-2026-94045Low· 3.5PoC
6d ago

A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0

A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0. Impacted is an unknown function of the file controller/common/UploadController.java of the component Goods Save Endpoint. Performing a manipulation of the argumen…

▾ Twilightnewbee-ltd · newbee-mallEPSS 0.41%via NVD
CVE-2026-94043Medium· 5.3PoC
6d ago

A vulnerability was determined in Free5GC up to 4.2.3

A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go of the component Gmm Handler. This manipulation causes race condition. Th…

▾ TwilightEPSS 0.57%via NVD
CVE-2026-94042Medium· 6.3PoC
6d ago

A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c

A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/add_table.php. The manipulation of the argument table/membe…

▾ TwilightAdithyaYelloju · Restaurant Management SystemEPSS 0.32%via NVD
CVE-2026-88854Critical· 9.3PoC
6d ago

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with …

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with …

▾ AbyssalOrdaSoft.com · com_osgallery_lightEPSS 0.39%via NVD
CVE-2026-94041Medium· 6.3PoC
6d ago

A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c

A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some unknown functionality of the file admin/add_menu.php. The manipulation of the ar…

▾ TwilightAdithyaYelloju · Restaurant-Management-SystemEPSS 0.33%via NVD
CVE-2026-94040Medium· 5.3PoC
6d ago

A flaw has been found in vas3k TaxHacker up to 0.8.5

A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of the file app/(app)/apps/settings/actions.ts. Executing a manipulation of the argument provider/apiKey/model/bas…

▾ Twilightvas3k · TaxHackerEPSS 0.53%via NVD
CVE-2026-94038High· 7.3PoC
6d ago

A security vulnerability has been detected in NonceGeek dim-sum-app

A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the file deno/main.tsx of the component Deno Backend. Such manipulation of the argument supabase_url leads to server-si…

▾ MidnightNonceGeek · dim-sum-appEPSS 0.51%via NVD
CVE-2026-94037Medium· 4.3PoC
6d ago

A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405

A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405. This affects the function ControlFlowNode of the file main.py of the component analyze_csv_data MCP tool. This manipulation of…

▾ Twilight00Kisumi00 · mcp-file-analyzerEPSS 0.47%via NVD
CVE-2026-94036High· 8.8PoC
6d ago

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results…

▾ MidnightD-Link · DIR-X1860EPSS 0.56%via NVD
CVE-2026-94035Medium· 4.3PoC
6d ago

A vulnerability was determined in SourceCodester Drug Recommendation System 1.0

A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /drug_recommender/index.php. Executing a manipulation of the argument full name can lead to cross site scripting…

▾ TwilightSourceCodester · Drug Recommendation SystemEPSS 0.47%via NVD
CVE-2026-94033Low· 3.5PoC
6d ago

A vulnerability has been found in SourceCodester Drug Recommendation System 1.0

A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of the file /drug_recommender/Admin/add_user of the component User Management. Such manipulation of the argument txt…

▾ TwilightSourceCodester · Drug Recommendation SystemEPSS 0.35%via NVD
CVE-2026-94032Medium· 6.3PoC
6d ago

A flaw has been found in itsourcecode Leave Management System 1.0

A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part of the file /module/department/index.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack re…

▾ Twilightitsourcecode · Leave Management SystemEPSS 0.33%via NVD
CVE-2026-94031Medium· 6.3PoC
6d ago

A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914

A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914. Affected by this issue is the function child_process.exec of the file src/auth/browser.ts of the component nexus_reauth MCP tool. The manipula…

▾ Twilight0-Gaurav-0 · nexus-mcpEPSS 1.8%via NVD
CVE-2026-94030Low· 3.1PoC
6d ago

A security vulnerability has been detected in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c

A security vulnerability has been detected in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c. Affected by this vulnerability is the function decode_bmp_pixel_data of the file Userland/Libraries/LibGfx/ImageFormats/BMPLoader.cp…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-94016Low· 2.4PoC
6d ago

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file /drug_recommender/Admin/add_symptom. Performing a manipulation of the argument txtname results in cross si…

▾ TwilightSourceCodester · Drug Recommendation SystemEPSS 0.37%via NVD
CVE-2026-94015High· 7.3PoC
6d ago

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file /drug_recommender/Admin/edit_user.php. Such manipulation of the argument ID leads to sql injection. The attack …

▾ MidnightSourceCodester · Drug Recommendation SystemEPSS 0.43%via NVD
CVE-2026-90817Critical· 9.8PoC
6d ago

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an uninte…

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an uninte…

▾ AbyssalVanderbilt University · REDCapEPSS 0.95%via NVD
CVEs tagged “exploit-available” — page 14 · VulnSea