VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3535 CVEsRSS

CVE-2026-61794Medium· 6.8PoC
1w ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update validation in internal/webhook/tenant/validation/forbidden_annotations_regex.go compiles ForbiddenLabels.Regex for both the…

▾ Twilightprojectcapsule · capsuleEPSS 0.59%via NVD
CVE-2026-61672High· 7.1PoC
1w ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assume…

▾ Midnightprojectcapsule · capsuleEPSS 0.33%via NVD
CVE-2026-77339Medium· 5.1PoC
1w ago

Process Compose is a scheduler and orchestrator for non-containerized applications

Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listener in src/mcp/server.go accepts browser-origin requests to /sse and the returned message endpoint without validating …

▾ Twilightf1bonacc1 · github.com/f1bonacc1/process-composeEPSS 0.26%via NVD
CVE-2026-58197High· 8.8PoC
1w ago

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission pro…

▾ Midnightstacklok · github.com/stacklok/toolhiveEPSS 0.37%via NVD
CVE-2026-77301High· 7.5PoC
1w ago

adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js

adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEntry.js trusts an entry's central-directory uncompressed size and allocates output memory before validating that value …

▾ Midnightadm-zip · adm-zipEPSS 0.61%via NVD
CVE-2026-77240Critical· 9.9PoC
1w ago

WACRM is a self-hostable CRM template for WhatsApp

WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security policy in supabase/migrations/017_account_sharing.sql permits authenticated users to modify their own account_role a…

▾ AbyssalArnasDon · wacrmEPSS 0.35%via NVD
CVE-2026-91147Medium· 5.9PoC
1w ago

A flaw was found in `cockpit-ws`

A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made t…

▾ TwilightRed Hat · cockpitEPSS 0.51%via NVD
CVE-2026-93736Medium· 4.3PoC
1w ago

Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path

Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path. Attackers ca…

▾ Twilightmealie-recipes · mealieEPSS 0.39%via NVD
CVE-2026-93532Medium· 6.3PoC
1w ago

A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8

A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function application/modules/global/controllers/password.php::simpan/application/modules/…

▾ Twilightgedelumbung · HospitalManagementEPSS 0.51%via NVD
CVE-2026-84449Low· 3.7PoC
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in an integer width that can overflow for extremely large RGB images created through heif_…

▾ Twilightstrukturag · libheifEPSS 0.43%via NVD
CVE-2026-84448Medium· 4.0PoC
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in libheif/api/libheif/heif_regions.cc accepts mask_data_len without verifying that it equals…

▾ Twilightstrukturag · libheifEPSS 0.15%via NVD
CVE-2026-84447High· 7.5PoC
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_i…

▾ Midnightstrukturag · libheifEPSS 0.61%via NVD
CVE-2026-84444High· 7.4PoC
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, heif_context_add_image_tile() accepts an independently constructed tile whose component-plane dimensions do not match t…

▾ Midnightstrukturag · libheifEPSS 0.53%via NVD
CVE-2026-84384High· 7.5PoC
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image data can cause decompress_brotli() and do_inflate() to grow accumulated output without an effective s…

▾ Midnightstrukturag · libheifEPSS 0.61%via NVD
CVE-2026-84383Critical· 9.8PoC⚖ disputed
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplica…

▾ Abyssalstrukturag · libheifEPSS 0.90%via NVD
CVE-2026-67549High· 7.6PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A crafted 1-bit contiguous cmyk tiff is exposed through a native uint1 imagespec, so cal…

▾ MidnightAcademySoftwareFoundation · OpenImageIOEPSS 0.38%via NVD
CVE-2026-65970Medium· 5.3PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, a crafted ZIP-compressed TIFF processed with TIFF multithreading enabled can make TIFFIn…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.40%via NVD
CVE-2026-63638High· 8.3PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted cineon image can declare unsupported component bi…

▾ MidnightAcademySoftwareFoundation · OpenImageIOEPSS 0.45%via NVD
CVE-2026-63635Medium· 5.5PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted psd with an invalid color_mode bypasses normal va…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.20%via NVD
CVE-2026-63420Medium· 5.5PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, An indexed psd with transparency metadata creates fewer sto…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.17%via NVD
CVE-2026-63419High· 7.8PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A zbuffer-only tiled iff is exposed with a 16-bit public im…

▾ MidnightAcademySoftwareFoundation · OpenImageIOEPSS 0.19%via NVD
CVE-2026-59956Medium· 6.1PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, An uncompressed 16-bit iff image with a z-buffer makes iffi…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.17%via NVD
CVE-2026-59181Medium· 6.1PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted cineon file can supply a numberofelements value g…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.17%via NVD
CVE-2026-59156Medium· 6.5PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted fits stream containing consecutive 2880-byte head…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.40%via NVD
CVE-2025-61682High· 8.6PoC
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as…

▾ Midnightmediawiki · mediawiki/semantic-media-wikiEPSS 0.29%via NVD
CVE-2026-7006High· 7.3PoC
1w ago

Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges …

Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges …

▾ MidnightSublime HQ Pty Ltd · Sublime Text 4EPSS 0.13%via NVD
CVE-2026-93687High· 7.5PoC
1w ago

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Nod…

▾ Midnightmicromatch · bracesEPSS 0.74%via NVD
CVE-2026-93690High· 7.5PoC
1w ago

uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators

uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling removeDot…

▾ Midnightgarycourt · uri-jsEPSS 0.68%via NVD
CVE-2026-93531Medium· 4.3PoC
1w ago

A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8

A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects unknown code. This manipulation causes cross-site request forgery. The attack may be initiated re…

▾ Twilightgedelumbung · HospitalManagementEPSS 0.23%via NVD
CVE-2026-93558High· 7.5PoC
1w ago

A flaw was found in Netty's WebSocketServerExtensionHandler

A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unboun…

▾ MidnightRed Hat · netty-codec-httpEPSS 0.79%via NVD
CVEs tagged “exploit-available” — page 18 · VulnSea