Tagged “exploit-available”
CVEs tagged exploit-available, newest first.
3538 CVEsRSS
CVE-2026-77615High· 8.7PoCPaella Player is a set of libraries to create a multi stream video player
Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability i…
CVE-2026-54597High· 8.3PoCITFlow provides an IT documentation, ticketing and accounting system for small managed service providers
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write permission and access to a credential record can perform ti…
CVE-2026-54596High· 8.1PoCITFlow provides an IT documentation, ticketing and accounting system for small managed service providers
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access to at least one client invoice can inject SQL through the…
CVE-2026-54510High· 7.1PoCSpeakr is a personal, self-hosted web application designed for transcribing audio recordings
Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() before_request hook in src/app.py calls csrf.exempt(view_func), permanently adding the …
CVE-2026-54355Medium· 5.3PoCMapServer is a system for developing web-based GIS applications
MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value…
CVE-2026-54339High· 7.7PoCGlean is a self-hosted RSS reader and personal knowledge management tool
Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passes an attacker-supplied feed_url to discover_feed(feed_url), creates a subscription through FeedService.create_subscri…
CVE-2026-52483High· 8.8PoCThe ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authenticated users execute arbitrary OS command via concatenated params on a crafted POST request fo…
The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authenticated users execute arbitrary OS command via concatenated params on a crafted POST request fo…
CVE-2021-3030Medium· 6.1PoCCute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx
Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated attacker can craft a URL that, once opened by a vict…
CVE-2026-45140Critical· 9.8PoCChamilo LMS is an open-source learning management system
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, …
CVE-2026-54752Critical· 9.6PoCNetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the rea…
CVE-2026-54692High· 7.8PoCSAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using t…
CVE-2026-54627Critical· 9.8PoCSAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in …
CVE-2026-54626Critical· 9.8PoCSAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by image_type == 9 allocates an image buffer using the one-by…
CVE-2026-54618Critical· 9.4PoCObsidian Web MCP is a secure remote MCP server for Obsidian vaults
Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exchange that code for the static VAULT_MC…
CVE-2026-54594Medium· 5.3PoCOmniBlocks is a monorepo for the OmniBlocks project
OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenev…
CVE-2026-92993Medium· 6.3PoCA vulnerability was detected in Dromara mayfly-go up to 1.11.5
A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machine Script Feature. The manipulation of …
CVE-2026-92992Medium· 6.3PoCA security vulnerability has been detected in Dromara mayfly-go up to 1.11.5
A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authoriza…
CVE-2026-54253High· 8.2PoCTS3 Manager is modern web interface for maintaining Teamspeak3 servers
TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter to socket.connect(port, host) and retu…
CVE-2026-52852Medium· 6.5PoCTraccar is an open source GPS tracking system
Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarchy and request a trips or stops report for a device in tha…
CVE-2026-52851High· 7.1PoCTraccar is an open source GPS tracking system
Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/permissions with an extra attacker-controlled JSON key. Permi…
CVE-2026-92927Medium· 5.3PoCA vulnerability was found in SourceCodester Drug Recommendation System 1.0
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Performing a manipulation results in information disclosure. The attack is possi…
CVE-2026-92926High· 7.3PoCA vulnerability has been found in code-projects Matrimonial System 1.0
A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. Th…
CVE-2026-89038Medium· 6.2PoCVerizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplyi…
Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplyi…
CVE-2026-44236High· 7.1PoCrabbitmq-c is a C-language AMQP client library for RabbitMQ
rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized connection.tune.frame_max value during amqp_login(), and rabbitmq-c accepts the value in amqp_login_inner() in l…
CVE-2026-44235Medium· 6.5PoCrabbitmq-c is a C-language AMQP client library for RabbitMQ
rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause unsigned size_t underflow in amqp_handle_input() in librabb…
CVE-2026-93292High· 8.5PoCSigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping
SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attac…
CVE-2026-28326High· 8.8PoCSolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
CVE-2026-93014High· 7.1PoCRosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal
RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal. Attackers can use parent-directory sequences to …
CVE-2026-86039High· 8.2PoClibp2p is a JavaScript implementation of the libp2p networking stack
libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but does not require PeerR…
CVE-2026-86038High· 7.5PoClibp2p is a JavaScript implementation of the libp2p networking stack
libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies …