VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3538 CVEsRSS

CVE-2026-77615High· 8.7PoC
1w ago

Paella Player is a set of libraries to create a multi stream video player

Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability i…

▾ Midnightopencast · opencastEPSS 0.56%via NVD
CVE-2026-54597High· 8.3PoC
1w ago

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write permission and access to a credential record can perform ti…

▾ Midnightitflow-org · itflowEPSS 0.43%via NVD
CVE-2026-54596High· 8.1PoC
1w ago

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access to at least one client invoice can inject SQL through the…

▾ Midnightitflow-org · itflowEPSS 0.48%via NVD
CVE-2026-54510High· 7.1PoC
1w ago

Speakr is a personal, self-hosted web application designed for transcribing audio recordings

Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() before_request hook in src/app.py calls csrf.exempt(view_func), permanently adding the …

▾ Midnightmurtaza-nasir · speakrEPSS 0.21%via NVD
CVE-2026-54355Medium· 5.3PoC
1w ago

MapServer is a system for developing web-based GIS applications

MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value…

▾ TwilightMapServer · MapServerEPSS 0.50%via NVD
CVE-2026-54339High· 7.7PoC
1w ago

Glean is a self-hosted RSS reader and personal knowledge management tool

Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passes an attacker-supplied feed_url to discover_feed(feed_url), creates a subscription through FeedService.create_subscri…

▾ MidnightLeslieLeung · gleanEPSS 0.47%via NVD
CVE-2026-52483High· 8.8PoC
1w ago

The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authenticated users execute arbitrary OS command via concatenated params on a crafted POST request fo…

The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authenticated users execute arbitrary OS command via concatenated params on a crafted POST request fo…

▾ MidnightEPSS 0.52%via NVD
CVE-2021-3030Medium· 6.1PoC
1w ago

Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx

Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated attacker can craft a URL that, once opened by a vict…

▾ TwilightEPSS 0.27%via NVD
CVE-2026-45140Critical· 9.8PoC
1w ago

Chamilo LMS is an open-source learning management system

Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, …

▾ Abyssalchamilo · chamilo-lmsEPSS 1.3%via NVD
CVE-2026-54752Critical· 9.6PoC
1w ago

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the rea…

▾ Abyssalnetbox-community · devicetype-libraryEPSS 0.66%via NVD
CVE-2026-54692High· 7.8PoC
1w ago

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using t…

▾ MidnightHappySeaFox · sailEPSS 0.19%via NVD
CVE-2026-54627Critical· 9.8PoC
1w ago

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in …

▾ AbyssalHappySeaFox · sailEPSS 0.78%via NVD
CVE-2026-54626Critical· 9.8PoC
1w ago

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by image_type == 9 allocates an image buffer using the one-by…

▾ AbyssalHappySeaFox · sailEPSS 0.78%via NVD
CVE-2026-54618Critical· 9.4PoC
1w ago

Obsidian Web MCP is a secure remote MCP server for Obsidian vaults

Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exchange that code for the static VAULT_MC…

▾ Abyssaljimprosser · obsidian-web-mcpEPSS 0.51%via NVD
CVE-2026-54594Medium· 5.3PoC
1w ago

OmniBlocks is a monorepo for the OmniBlocks project

OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenev…

▾ TwilightOmniBlocks · monorepoEPSS 0.45%via NVD
CVE-2026-92993Medium· 6.3PoC
1w ago

A vulnerability was detected in Dromara mayfly-go up to 1.11.5

A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machine Script Feature. The manipulation of …

▾ TwilightDromara · mayfly-goEPSS 1.5%via NVD
CVE-2026-92992Medium· 6.3PoC
1w ago

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authoriza…

▾ TwilightDromara · mayfly-goEPSS 0.39%via NVD
CVE-2026-54253High· 8.2PoC
1w ago

TS3 Manager is modern web interface for maintaining Teamspeak3 servers

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter to socket.connect(port, host) and retu…

▾ Midnightjoni1802 · ts3-managerEPSS 0.28%via NVD
CVE-2026-52852Medium· 6.5PoC
1w ago

Traccar is an open source GPS tracking system

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarchy and request a trips or stops report for a device in tha…

▾ Twilighttraccar · traccarEPSS 0.53%via NVD
CVE-2026-52851High· 7.1PoC
1w ago

Traccar is an open source GPS tracking system

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/permissions with an extra attacker-controlled JSON key. Permi…

▾ Midnighttraccar · traccarEPSS 0.39%via NVD
CVE-2026-92927Medium· 5.3PoC
1w ago

A vulnerability was found in SourceCodester Drug Recommendation System 1.0

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Performing a manipulation results in information disclosure. The attack is possi…

▾ TwilightSourceCodester · Drug Recommendation SystemEPSS 0.53%via NVD
CVE-2026-92926High· 7.3PoC
1w ago

A vulnerability has been found in code-projects Matrimonial System 1.0

A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. Th…

▾ Midnightcode-projects · Matrimonial SystemEPSS 0.43%via NVD
CVE-2026-89038Medium· 6.2PoC
1w ago

Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplyi…

Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplyi…

▾ TwilightVerizon · com.vcast.mediamanagerEPSS 0.19%via NVD
CVE-2026-44236High· 7.1PoC
1w ago

rabbitmq-c is a C-language AMQP client library for RabbitMQ

rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized connection.tune.frame_max value during amqp_login(), and rabbitmq-c accepts the value in amqp_login_inner() in l…

▾ Midnightalanxz · rabbitmq-cEPSS 0.48%via NVD
CVE-2026-44235Medium· 6.5PoC
1w ago

rabbitmq-c is a C-language AMQP client library for RabbitMQ

rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause unsigned size_t underflow in amqp_handle_input() in librabb…

▾ Twilightalanxz · rabbitmq-cEPSS 0.36%via NVD
CVE-2026-93292High· 8.5PoC
1w ago

SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping

SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attac…

▾ MidnightSigNoz · signozEPSS 0.40%via NVD
CVE-2026-28326High· 8.8PoC
1w ago

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

▾ MidnightSolarWinds · Access Rights ManagerEPSS 0.69%via NVD
CVE-2026-93014High· 7.1PoC
1w ago

RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal

RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal. Attackers can use parent-directory sequences to …

▾ MidnightRosarioSIS · RosarioSISEPSS 0.50%via NVD
CVE-2026-86039High· 8.2PoC
1w ago

libp2p is a JavaScript implementation of the libp2p networking stack

libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but does not require PeerR…

▾ Midnightlibp2p · js-libp2pEPSS 0.27%via NVD
CVE-2026-86038High· 7.5PoC
1w ago

libp2p is a JavaScript implementation of the libp2p networking stack

libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies …

▾ Midnightlibp2p · @libp2p/gossipsubEPSS 0.19%via NVD
CVEs tagged “exploit-available” — page 21 · VulnSea