VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

2797 CVEsRSS

CVE-2026-93958Critical· 9.1PoC
yesterday

A vulnerability was found in D-Link R95 BE9500_1.00.16

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack c…

AbyssalD-Link · R95EPSS 2.2%via NVD
CVE-2026-93956Low· 3.5PoC
2d ago

A flaw has been found in olivier-ls PHP-FTS up to 1.1.2

A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php of the component Search Engine. Executing a manipulation of the argument Query…

Twilightolivier-ls · PHP-FTSEPSS 0.24%via NVD
CVE-2026-93988Medium· 6.5PoC
2d ago

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email par…

Twilightwebkul · qloappsEPSS 0.37%via NVD
CVE-2026-93993High· 8.8PoC
2d ago

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes…

Midnightmistralai · mistral-vibeEPSS 0.60%via NVD
CVE-2026-93985Critical· 9.9PoC
2d ago

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can c…

AbyssalOpenpanel-dev · openpanelEPSS 0.48%via NVD
CVE-2026-89274Critical· 9.1PoC
2d ago

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()…

Abyssalbrechtvds · WP Recipe MakerEPSS 0.38%via NVD
CVE-2026-92229Critical· 9.1PoC
2d ago

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to e…

Abyssalwpmudev · Forminator Forms – Contact Form, Payment Form & Custom Form BuilderEPSS 0.40%via NVD
CVE-2026-84434Critical· 9.8PoC
2d ago

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persis…

AbyssalGravity Forms · Gravity FormsEPSS 0.70%via NVD
CVE-2026-93923High· 8.8PoC
2d ago

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject maliciou…

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.41%via NVD
CVE-2026-93921Medium· 4.3PoC
2d ago

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read bl…

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.23%via NVD
CVE-2026-93740Critical· 10.0PoC
3d ago

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initi…

AbyssalTotolink · A3002MUEPSS 0.61%via NVD
CVE-2026-85272Medium· 4.3PoC
3d ago

Open edX Platform enables the authoring and delivery of online learning at any scale

Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawood.1, openedx/core/lib/extract_archive.py uses _is_bad_path to validate safe_extractall targets by comparing resolved…

Twilightopenedx · openedx-platformEPSS 0.33%via NVD
CVE-2026-93873Medium· 4.3PoC
3d ago

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-submit contact forms from attacker-controlled pages to send forged messages attri…

TwilightCotonti · CotontiEPSS 0.16%via NVD
CVE-2026-93871Medium· 5.4PoC
3d ago

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attackers can craft pa…

TwilightCotonti · CotontiEPSS 0.17%via NVD
CVE-2026-93869Medium· 6.1PoC
3d ago

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers can bypass the redirect guard by sup…

TwilightCotonti · CotontiEPSS 0.22%via NVD
CVE-2026-93868High· 8.1PoC
3d ago

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the s…

MidnightCotonti · CotontiEPSS 0.61%via NVD
CVE-2026-63647Critical· 9.3PoC
3d ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFi…

Abyssal1Panel-dev · CordysCRMEPSS 0.47%via NVD
CVE-2026-63646Medium· 6.9PoC
3d ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, GET /mcp/form/config/{formKey} calls McpController.getMcpField without authentication because ShiroFilter.ad…

Twilight1Panel-dev · CordysCRMEPSS 0.49%via NVD
CVE-2017-20284High· 7.5PoC
3d ago

Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the…

Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the…

MidnightCaucho Technology, Inc. · ResinEPSS 0.96%via NVD
CVE-2026-93838Medium· 5.9PoC
3d ago

SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments

SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access …

Twilightsgl-project · sglangEPSS 0.46%via NVD
CVE-2026-93650Low· 3.7PoC
3d ago

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of…

TwilightEPSS 0.55%via NVD
CVE-2026-93753High· 7.5PoC
3d ago

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to…

MidnightTehShrike · deepmergeEPSS 0.36%via NVD
CVE-2026-93752High· 7.5PoC
3d ago

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal…

MidnightNV · CSSOMEPSS 0.47%via NVD
CVE-2026-93750Medium· 5.9PoC
3d ago

http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison

http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previous…

Twilightkornelski · http-cache-semanticsEPSS 0.35%via NVD
CVE-2026-93748High· 7.5PoC
3d ago

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers …

Midnightkornelski · http-cache-semanticsEPSS 0.40%via NVD
CVE-2026-92747Medium· 5.0PoC
3d ago

A flaw was found in `cockpit-machines`

A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This …

TwilightRed Hat · cockpit-machinesEPSS 0.15%via NVD
CVE-2026-59163Critical· 9.1PoC
3d ago

Mnemosyne is a memory layer for artificial intelligence agents

Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt library call with…

Abyssalmnemosyne-memory · mnemosyne-memoryEPSS 0.25%via NVD
CVE-2026-92701Critical· 9.1PoC
3d ago

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expe…

Abyssalultravioletrs · cocosEPSS 0.22%via NVD
CVE-2026-77385Medium· 4.3PoC
3d ago

Kyoo is a self-hosted media server focused on movies, series, and anime

Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src…

Twilightzoriya · KyooEPSS 0.32%via NVD
CVE-2026-69186Medium· 5.3PoC
3d ago

c-ares is an asynchronous resolver library

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Beca…

Twilightc-ares · c-aresEPSS 0.52%via NVD
CVEs tagged “exploit-available” — page 2 · VulnSea