VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3538 CVEsRSS

CVE-2026-86000Medium· 5.3PoC
1w ago

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and V…

▾ Twilightfacelessuser · soupsieveEPSS 0.61%via NVD
CVE-2026-85999Medium· 5.3PoC
1w ago

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used …

▾ Twilightfacelessuser · soupsieveEPSS 0.61%via NVD
CVE-2026-85721High· 7.5PoC
1w ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses ChannelM…

▾ Midnightasynchttpclient · org.asynchttpclient:async-http-clientEPSS 0.63%via NVD
CVE-2026-85715High· 7.5PoC
1w ago

ExifReader is a JavaScript Exif information parser

ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEIC or AVIF ISO-BMFF files in getItems() within src/image-header-iso-bmff-iloc.js and trusts iloc itemCount and extentCount value…

▾ Midnightmattiasw · ExifReaderEPSS 0.61%via NVD
CVE-2026-92985High· 8.8PoC
1w ago

SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree

SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft malicious .sy notebook files with unescaped HTML in bookmark attributes that execute scrip…

▾ Midnightsiyuan-note · siyuanEPSS 0.82%via NVD
CVE-2026-92983High· 7.5PoC
1w ago

InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of internal scheduler keys

InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of internal scheduler keys. Unauthenticated attackers can send co…

▾ MidnightInternLM · lmdeployEPSS 0.66%via NVD
CVE-2026-79752Critical· 9.2PoC
1w ago

CakePHP is a rapid development framework for PHP

CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBui…

▾ Abyssalcakephp · cakephpEPSS 0.62%via NVD
CVE-2026-77614High· 8.8PoC
1w ago

Opencast is a free, open-source platform to support the management of educational audio and video content

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in etc/security/mh_default_org.xml accepts a client-selected J…

▾ Midnightopencast · opencastEPSS 0.55%via NVD
CVE-2026-63472Critical· 9.1PoC
1w ago

Vendure is an open-source headless commerce platform

Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing…

▾ Abyssalvendurehq · vendureEPSS 0.59%via NVD
CVE-2026-63460High· 7.5PoC
1w ago

Vendure is an open-source headless commerce platform

Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern through StringOperators.regex. packages/core/src/service…

▾ Midnightvendurehq · vendureEPSS 0.61%via NVD
CVE-2026-63459High· 8.7PoC
1w ago

Vendure is an open-source headless commerce platform

Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx attempts to strip markup by assigning an administrat…

▾ Midnightvendurehq · vendureEPSS 0.42%via NVD
CVE-2026-61793Medium· 6.9PoC
1w ago

Nuxt OG Image generates OG Images with Vue templates in Nuxt

Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and b…

▾ Twilightnuxt-modules · og-imageEPSS 0.50%via NVD
CVE-2026-92971High· 7.5PoC
1w ago

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with a…

▾ MidnightInternLM · lmdeployEPSS 0.70%via NVD
CVE-2026-92963Medium· 5.3PoC
1w ago

vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable

vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalThis to retrieve sensitive sandbox inter…

▾ Twilightpatriksimek · vm2EPSS 0.34%via NVD
CVE-2026-92962Low· 2.1PoC
1w ago

vm2 is a sandbox for running untrusted JavaScript

vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepareStackTrace function in lib/setup-sandbox.js builds its output array using prototype-walking index assignment (lines[l…

▾ Twilightpatriksimek · vm2EPSS 0.15%via NVD
CVE-2026-92960Critical· 10.0PoC
1w ago

vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology

vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host …

▾ Abyssalpatriksimek · vm2EPSS 0.47%via NVD
CVE-2026-92959High· 7.1PoC
1w ago

vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM

vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with a handler that throws 'Async not available', the sandbox's Promise static methods (Promise.resolve…

▾ Midnightpatriksimek · vm2EPSS 0.45%via NVD
CVE-2026-92958High· 8.5PoC
1w ago

vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM

vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard together with negative entries (e.g. require: { builtin: ['*', '-fs', '-child_process'] }), negative entries are matched …

▾ Midnightpatriksimek · vm2EPSS 0.38%via NVD
CVE-2026-92957Critical· 9.9PoC
1w ago

vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy

vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, n…

▾ Abyssalpatriksimek · vm2EPSS 0.57%via NVD
CVE-2026-92955Critical· 10.0PoC
1w ago

vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr

vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and tri…

▾ Abyssalpatriksimek · vm2EPSS 0.71%via NVD
CVE-2026-92954High· 8.6PoC
1w ago

vm2 is a sandbox library for running untrusted JavaScript in Node.js

vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host realm into the sandbox are not marked as handled at the bridge boundary; only Promises created ins…

▾ Midnightpatriksimek · vm2EPSS 0.49%via NVD
CVE-2026-92953Critical· 10.0PoC
1w ago

vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation

vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype…

▾ Abyssalpatriksimek · vm2EPSS 0.50%via NVD
CVE-2026-92952Medium· 6.8PoC
1w ago

vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary

vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross-realm symbol checks and write traps in lib/bridge.js use…

▾ Twilightpatriksimek · vm2EPSS 0.46%via NVD
CVE-2026-92950High· 8.6PoC
1w ago

vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process

vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filena…

▾ Midnightpatriksimek · vm2EPSS 0.20%via NVD
CVE-2026-92949Medium· 4.0PoC
1w ago

vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections

vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescr…

▾ Twilightpatriksimek · vm2EPSS 0.32%via NVD
CVE-2026-92948Critical· 9.9PoC
1w ago

vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g

vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g. require: { builtin: ['node:test']…

▾ Abyssalpatriksimek · vm2EPSS 0.65%via NVD
CVE-2026-92947Critical· 10.0PoC
1w ago

vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations

vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring A…

▾ Abyssalpatriksimek · vm2EPSS 0.48%via NVD
CVE-2026-92944Critical· 9.8PoC
1w ago

vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6

vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploi…

▾ Abyssalpatriksimek · vm2EPSS 0.84%via NVD
CVE-2026-92942High· 7.5PoC
1w ago

vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call

vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout only wraps the single call to _runScript() via doWithTimeout() in lib/vm.js, …

▾ Midnightpatriksimek · vm2EPSS 0.49%via NVD
CVE-2026-92941Critical· 10.0PoC
1w ago

vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities

vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls an…

▾ Abyssalpatriksimek · vm2EPSS 0.29%via NVD
CVEs tagged “exploit-available” — page 22 · VulnSea