Tagged “exploit-available”
CVEs tagged exploit-available, newest first.
3536 CVEsRSS
CVE-2026-93311Medium· 4.3PoCA vulnerability was detected in Freedesktop Poppler 26.07.0
A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument BitsPerSampl…
CVE-2026-93310Medium· 5.3PoCA vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10
A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocation of resources. Remote exploitation of the attack is possible. The exploit is …
CVE-2026-93308Medium· 4.3PoCA vulnerability was found in O-RAN-SC SMO OAM 2025-06-10
A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of resources. The attack may be initiate…
CVE-2026-93450High· 7.5PoCgo-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit
go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON docu…
CVE-2026-93454Medium· 5.4PoCAureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin
Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms end…
CVE-2026-93453High· 8.3PoCSOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains
SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password re…
CVE-2026-93452High· 7.5PoCsnappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination bu…
CVE-2026-93309Medium· 4.3PoCA vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10
A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation can lead to allocation of resources. The attack may be launched …
CVE-2026-87886High· 7.8CISA KEV0dayPoCLocal privilege escalation due to insecure file permissions
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638,…
CVE-2026-93307Medium· 4.3PoCA vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10
A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument additionalFields.padding leads to uncontrolled memory allocation. The attack…
CVE-2026-54767Critical· 9.1PoCWeGIA is a web manager for charitable institutions
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta valu…
CVE-2026-54671High· 8.8PoCWeGIA is a web manager for charitable institutions
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as uncondi…
CVE-2026-54670Critical· 9.1PoCWeGIA is a web manager for charitable institutions
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controlle…
CVE-2026-54648Medium· 6.5PoCCubeCart is an ecommerce software solution
CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely on page-level CC_PERM_READ access and do not require CC_PERM_DELETE for the purge, no_order_purge, or delete_guests c…
CVE-2026-54647High· 7.2PoCCubeCart is an ecommerce software solution
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without…
CVE-2026-54646High· 7.2PoCCubeCart is an ecommerce software solution
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the ident…
CVE-2026-54645Medium· 4.8PoCCubeCart is an ecommerce software solution
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS['RAW']['POST'] and removes only script elements befor…
CVE-2026-54644Medium· 6.1PoCCubeCart is an ecommerce software solution
CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and on…
CVE-2026-54643Medium· 5.4PoCCubeCart is an ecommerce software solution
CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.php verifies only the presence of order_id and delete-note parameters before deleting records from CubeCart_order_notes…
CVE-2026-54613Medium· 5.4PoCVvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, getThemeFolder() in admin/controller/editor/revisions.php returns the attacker-controlled theme parameter without s…
CVE-2026-54608High· 7.1PoCMythicalDash is a Pterodactyl client area
MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/System/Gateways/Stripe.php creates a pending row in mythicaldash_stripe_payments before Stripe checkout succeeds and embed…
CVE-2026-54520High· 8.1PoCAI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability
AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.…
CVE-2026-54519High· 8.8PoCAI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability
AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authenticates requests but listMemories, deleteMemory, and cle…
CVE-2026-54506High· 7.6PoCVvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] field and passes stored content through sanitizeHTML() in sys…
CVE-2026-53556Medium· 6.0PoCSQLBot is an intelligent Text-to-SQL system based on large language models and RAG
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the client-controlled table_n…
CVE-2026-53555Medium· 5.1PoCSQLBot is an intelligent Text-to-SQL system based on large language models and RAG
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+xml assistant UI logo through PATCH /api/v1/system/assistant/ui, and SQLBot stores the …
CVE-2026-53554High· 7.3PoCSQLBot is an intelligent Text-to-SQL system based on large language models and RAG
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled multipart filename …
CVE-2026-50291Medium· 5.5PoCOpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to versions 3.0.16.0 and 3.1.11.0, processing a crafted BMP file through oiiotool or an application l…
CVE-2026-93426High· 8.5PoCSigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL
SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in fi…
CVE-2026-77615High· 8.7PoCPaella Player is a set of libraries to create a multi stream video player
Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability i…