VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3535 CVEsRSS

CVE-2026-93505Low· 3.5PoC
1w ago

A vulnerability was found in SveltyCMS 0.0.6

A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG Media Upload. Performing a manipulation results in cross site scripting. The a…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-93659High· 8.7PoC
1w ago

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute …

▾ Midnightconcretecms-community-store · concretecms-community-store/community_storeEPSS 0.47%via NVD
CVE-2026-93658High· 7.0PoC
1w ago

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes…

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes…

▾ Midnightuutils · coreutilsEPSS 0.14%via NVD
CVE-2026-93019Critical· 9.1PoC
1w ago

Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more beco…

Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more beco…

▾ AbyssalEPSS 0.65%via NVD
CVE-2026-88623High· 7.5PoC
1w ago

NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read

NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and fopen() is used to open the URL in binary read-only mode. The content is then written to…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-88622High· 8.8PoC
1w ago

NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.

NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.

▾ MidnightEPSS 1.1%via NVD
CVE-2026-79294Medium· 6.1PoC
1w ago

Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview rendering; public Share view component

Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview rendering; public Share view component

▾ TwilightEPSS 0.51%via NVD
CVE-2026-62282Medium· 6.5PoC
1w ago

OpenCVE is a vulnerability intelligence platform

OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack integrations does not sufficiently validate user-supplied HTTP or HTTPS destinations. An authenticated user with permiss…

▾ Twilightopencve · opencveEPSS 0.42%via NVD
CVE-2026-93504Medium· 6.3PoC
1w ago

A vulnerability has been found in SveltyCMS 0.0.6

A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute Update Endpoint. Such manipulation leads to improper access controls. It is p…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-93591High· 7.6PoC
1w ago

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous vis…

▾ Midnightsiyuan-note · siyuanEPSS 0.32%via NVD
CVE-2026-93594High· 8.1PoC
1w ago

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through LSM index files or th…

▾ MidnightArcadeData · arcadedbEPSS 0.44%via NVD
CVE-2026-93593High· 8.1PoC
1w ago

ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets

ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets. An authenticated low-privil…

▾ MidnightArcadeData · arcadedbEPSS 0.36%via NVD
CVE-2026-93592High· 7.5PoC
1w ago

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a nega…

▾ Midnightvllm-project · vllmEPSS 0.51%via NVD
CVE-2026-93598High· 7.1PoC
1w ago

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED lists java.util.ResourceBundle as a bare clas…

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED lists java.util.ResourceBundle as a bare clas…

▾ MidnightArcadeData · arcadedbEPSS 0.63%via NVD
CVE-2026-93597High· 7.7PoC
1w ago

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC…

▾ MidnightArcadeData · arcadedbEPSS 0.35%via NVD
CVE-2026-93599High· 7.5PoC
1w ago

rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs

rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (ze…

▾ Midnightrustls · webpkiEPSS 0.49%via NVD
CVE-2026-93596Medium· 4.3PoC
1w ago

ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker threads used by the parallel edge-connect phase of POST /api/v1/batch/{database}

ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker threads used by the parallel edge-connect phase of POST /api/v1/batch/{database}. Be…

▾ TwilightArcadeData · arcadedbEPSS 0.29%via NVD
CVE-2026-93603Critical· 10.0PoC
1w ago

vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.…

vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.…

▾ Abyssalpatriksimek · vm2EPSS 0.73%via NVD
CVE-2026-93606Critical· 10.0PoC
1w ago

vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`

vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromis…

▾ Abyssalpatriksimek · vm2EPSS 0.71%via NVD
CVE-2026-93604High· 7.2PoC
1w ago

vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowlists the crypto builtin for a NodeVM (require.builtin: ['crypto'])

vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowlists the crypto builtin for a NodeVM (require.builtin: ['crypto']). The builtin sanitizer (sanitizeCryptoModule in l…

▾ Midnightpatriksimek · vm2EPSS 0.34%via NVD
CVE-2026-93578Medium· 5.9PoC
1w ago

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate is…

▾ TwilightRed Hat · netty-handler-ssl-ocspEPSS 0.29%via NVD
CVE-2026-81627High· 8.2PoC
1w ago

A flaw was found in QEMU

A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over locked S…

▾ MidnightRed Hat · qemu-kvmEPSS 0.19%via NVD
CVE-2026-87915High· 7.2PoC
1w ago

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via values[Name] Parameter in all versions up to, and including, 1.24.0 …

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via values[Name] Parameter in all versions up to, and including, 1.24.0 …

▾ Midnightdanieliser · Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup BuilderEPSS 0.49%via NVD
CVE-2026-75157High· 7.5PoC
1w ago

Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`

Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset events, silently sup…

▾ MidnightApache Software Foundation · apache-airflowEPSS 0.44%via NVD
CVE-2026-89059High· 7.5PoC
1w ago

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafte…

▾ MidnightRed Hat · RESTEasyEPSS 0.79%via NVD
CVE-2026-89058High· 7.4PoC
1w ago

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. Thi…

▾ MidnightRed Hat · RESTEasyEPSS 0.47%via NVD
CVE-2026-93485High· 7.1PoC
1w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 throug…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 throug…

▾ MidnightAutomattic · WordPressEPSS 0.28%via NVD
CVE-2026-93313Medium· 6.3PoC
1w ago

A vulnerability was found in Freedesktop Poppler 26.07.0

A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be ini…

▾ TwilightFreedesktop · PopplerEPSS 0.43%via NVD
CVE-2026-93314Medium· 6.3PoC
1w ago

A vulnerability was determined in Freedesktop Poppler 26.07.0

A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attac…

▾ TwilightFreedesktop · PopplerEPSS 0.43%via NVD
CVE-2026-93312Medium· 4.3PoC
1w ago

A flaw has been found in Freedesktop Poppler 26.07.0

A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The…

▾ TwilightFreedesktop · PopplerEPSS 0.59%via NVD
CVEs tagged “exploit-available” — page 19 · VulnSea