VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3538 CVEsRSS

CVE-2026-92579Medium· 5.4PoC
1w ago

In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions

In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugi…

▾ TwilightWWBN · AVideoEPSS 0.27%via NVD
CVE-2026-92578High· 8.1PoC
1w ago

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify()

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attacke…

▾ MidnightWWBN · AVideoEPSS 0.62%via NVD
CVE-2026-92583Medium· 6.5PoC
1w ago

AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concu…

AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concu…

▾ TwilightWWBN · AVideoEPSS 0.30%via NVD
CVE-2026-92586Medium· 4.3PoC
1w ago

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted vide…

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted vide…

▾ TwilightWWBN · AVideoEPSS 0.26%via NVD
CVE-2026-92585Medium· 4.3PoC
1w ago

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can …

▾ TwilightWWBN · AVideoEPSS 0.26%via NVD
CVE-2026-92595Medium· 5.9PoC
1w ago

Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` us…

Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` us…

▾ Twilightnodemailer · nodemailerEPSS 0.29%via NVD
CVE-2026-92598Medium· 6.5PoC
1w ago

Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers

Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient add…

▾ Twilightnodemailer · nodemailerEPSS 0.40%via NVD
CVE-2026-92596High· 7.5PoC
1w ago

Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list

Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a s…

▾ Midnightnodemailer · nodemailerEPSS 0.82%via NVD
CVE-2025-56565High· 7.6PoC
1w ago

DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory

DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory. The exposed material includes SSH private keys, dynamic DNS passwords, email n…

▾ MidnightEPSS 0.19%via NVD
CVE-2025-56566Medium· 4.6PoC
1w ago

MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage

MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract this material from an SPI flash dump, without aut…

▾ TwilightEPSS 0.16%via NVD
CVE-2025-56563Critical· 9.8PoC
1w ago

A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0

A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validat…

▾ AbyssalEPSS 0.40%via NVD
CVE-2026-92748High· 8.8PoC
1w ago

BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server

BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server. Attackers can use path traversal sequences in th…

▾ MidnightBC-SECURITY · EmpireEPSS 0.82%via NVD
CVE-2026-63506High· 8.8PoC
1w ago

Tina is a headless content management system

Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected Tin…

▾ Midnighttinacms · tinacmsEPSS 0.52%via NVD
CVE-2026-92753High· 7.1PoC
1w ago

PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering

PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modif…

▾ MidnightPatrowl · PatrowlManagerEPSS 0.38%via NVD
CVE-2026-92761High· 8.8PoC
1w ago

WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions

WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers with read-only grants can power off virtual machines, reset root passwords, install SSH ke…

▾ Midnightretspen · webvirtcloudEPSS 0.61%via NVD
CVE-2026-92754Medium· 4.3PoC
1w ago

PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out

PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all use…

▾ TwilightPatrowl · PatrowlManagerEPSS 0.34%via NVD
CVE-2026-92751High· 8.1PoC
1w ago

CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators

CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft hidden forms that submit to destructive endpoints l…

▾ Midnightyahoo · CMAKEPSS 0.26%via NVD
CVE-2026-92760Medium· 6.5PoC
1w ago

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with author-only or domain-only keys can access the mercure-info end…

▾ Twilightshlinkio · shlinkEPSS 0.41%via NVD
CVE-2026-92752High· 8.3PoC
1w ago

metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions

metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers to read, replace,…

▾ Midnightmetasfresh · metasfreshEPSS 0.46%via NVD
CVE-2026-92763High· 8.1PoC
1w ago

Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint

Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security…

▾ Midnightrundeck · rundeckEPSS 0.51%via NVD
CVE-2026-92762High· 8.8PoC
1w ago

Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks

Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft Livewire state updates to inv…

▾ Midnightpelican · panelEPSS 0.65%via NVD
CVE-2026-92775Medium· 6.5PoC
1w ago

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img…

▾ Twilightrequarks · Wiki.jsEPSS 0.41%via NVD
CVE-2026-92771Medium· 6.5PoC
1w ago

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers with canReadObjectRecords permission but canReadFieldValue…

▾ Twilighttwentyhq · twentyEPSS 0.44%via NVD
CVE-2026-92770Medium· 6.5PoC
1w ago

Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials

Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on the AccessCredential column to recover the scanner adapter…

▾ Twilightgoharbor · harborEPSS 0.45%via NVD
CVE-2026-92774Medium· 4.3PoC
1w ago

Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed

Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links resolvers to retrieve…

▾ Twilightrequarks · Wiki.jsEPSS 0.37%via NVD
CVE-2026-92765Medium· 6.5PoC
1w ago

ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations

ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to r…

▾ Twilightarcherysec · archerysecEPSS 0.45%via NVD
CVE-2026-92780High· 8.8PoC
1w ago

KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality

KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator acc…

▾ Midnightdidi · KnowStreamingEPSS 0.52%via NVD
CVE-2026-92776High· 8.1PoC
1w ago

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated …

▾ Midnightrequarks · Wiki.jsEPSS 0.45%via NVD
CVE-2026-92772High· 7.1PoC
1w ago

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary prope…

▾ MidnightLeantime · leantimeEPSS 0.53%via NVD
CVE-2026-92782High· 8.1PoC
1w ago

Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier

Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, a…

▾ Midnightchroma-core · chromaEPSS 0.45%via NVD
CVEs tagged “exploit-available” — page 24 · VulnSea