VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3538 CVEsRSS

CVE-2026-63126High· 7.5PoC
1w ago

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary b…

▾ Midnightsquare · wireEPSS 0.82%via NVD
CVE-2026-92418Low· 3.5PoC
1w ago

A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd

A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects unknown code of the file src/main/resources/public/js/customerServe/customer.serve.js of the component Save Endp…

▾ TwilightChangeWeDer · crmEPSS 0.35%via NVD
CVE-2026-38999High· 7.5PoC
1w ago

A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0c16 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0c16 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

▾ MidnightEPSS 1.4%via NVD
CVE-2026-92729High· 8.2PoC
1w ago

SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler

SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including …

▾ MidnightSigNoz · signozEPSS 0.58%via NVD
CVE-2026-91097Critical· 9.8PoC⚖ disputed
1w ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

▾ Abyssalhp · linux_imaging_and_printingEPSS 1.0%via NVD
CVE-2026-82399High· 7.5PoC
1w ago

CoreDNS is a DNS server written in Go

CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC request paths in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call d…

▾ Midnightcoredns · corednsEPSS 0.61%via NVD
CVE-2026-77360Medium· 6.3PoC
1w ago

oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards

oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.8, the @orpc/server CORS plugin in packages/server/src/plugins/cors.ts copies a client's incoming Vary request header into…

▾ Twilightmiddleapi · orpcEPSS 0.54%via NVD
CVE-2026-92472Low· 3.3PoC
1w ago

A vulnerability was determined in GPAC 26.08-DEV

A vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the file src/scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to use after free. The a…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-81875High· 7.5PoC
1w ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume attacker…

▾ Midnighthapifhir · org.hl7.fhir.coreEPSS 0.63%via NVD
CVE-2026-86043High· 7.5PoC
1w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent beca…

▾ Midnightzalando · skipperEPSS 0.45%via NVD
CVE-2026-79298High· 8.4PoC
1w ago

An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker to execute arbitrary code via the BOOTia32.efi and a crafted cloak32.dat file on the ESP.

An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker to execute arbitrary code via the BOOTia32.efi and a crafted cloak32.dat file on the ESP.

▾ MidnightEPSS 0.19%via NVD
CVE-2026-92716Critical· 9.6PoC
1w ago

Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users in other organizations

Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users in other organizations. Attackers with …

▾ AbyssalShuffle · ShuffleEPSS 0.43%via NVD
CVE-2026-92718High· 7.3PoC
1w ago

Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums

Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modific…

▾ Midnightprojectdiscovery · nucleiEPSS 0.12%via NVD
CVE-2026-92717Critical· 9.1PoC
1w ago

Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token

Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained token to authenticate…

▾ Abyssalcobbr · CovenantEPSS 0.50%via NVD
CVE-2026-92413Medium· 4.3PoC
1w ago

A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9

A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref Loading. Executing a manipulation ca…

▾ TwilightArtifex · MuPDFEPSS 0.59%via NVD
CVE-2026-51990Critical· 9.8PoC
1w ago

An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component

An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component

▾ AbyssalEPSS 0.93%via NVD
CVE-2026-47094High· 8.8PoC
1w ago

SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to access and modify arbitrary employee records due to missing server-side ownership validation

SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to access and modify arbitrary employee records due to missing server-side ownership validation. Attackers can send a P…

▾ MidnightSIMAC · MyPHREPSS 0.51%via NVD
CVE-2026-92416Medium· 4.3PoC
1w ago

A vulnerability has been found in Open5GS up to 2.8.0

A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_report_request of the file src/smf/n4-handler.c of the component PFCP Session Report Request Handler. The manipulation le…

▾ TwilightEPSS 0.53%via NVD
CVE-2026-92719High· 7.5PoC
1w ago

Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses

Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses. Attackers can supply a malicious queue_url t…

▾ Midnightquickwit-oss · quickwitEPSS 0.48%via NVD
CVE-2026-69147Medium· 6.5PoC
1w ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetch_video forwards …

▾ Twilightvllm-project · vllmEPSS 0.55%via NVD
CVE-2026-92604High· 8.1PoC
1w ago

Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacker-controlled JSON content to filesystem paths

Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacker-controlled JSON content to filesystem paths. Attackers can supply path trave…

▾ MidnightStamusNetworks · sciriusEPSS 0.58%via NVD
CVE-2026-92406High· 7.3PoC
1w ago

A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0

A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation of the argum…

▾ MidnightSourceCodester · Inventory and Monitoring SystemEPSS 0.43%via NVD
CVE-2026-88593Medium· 6.1PoC
1w ago

kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint

kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without sanitization, and the templat…

▾ TwilightEPSS 0.25%via NVD
CVE-2026-92405High· 7.3PoC
1w ago

A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0

A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such manipulation of the argument Username leads to sql injection. The …

▾ MidnightSourceCodester · Inventory and Monitoring SystemEPSS 0.43%via NVD
CVE-2026-92398Critical· 9.1PoC
1w ago

A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380

A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. Performing a manipulation of the argument Nam…

▾ AbyssalRuijie · RG-EW3000GXEPSS 3.2%via NVD
CVE-2026-92602High· 7.1PoC
1w ago

TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController

TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attach webhooks to other users' forms and exfiltrate submissions to arbitrary exter…

▾ MidnightTDuckCloud · tduck-survey-formEPSS 0.40%via NVD
CVE-2026-92601Medium· 6.5PoC
1w ago

Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods

Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods. Authenticated users without assigned roles can exploit th…

▾ Twilightstylefeng · GunsEPSS 0.39%via NVD
CVE-2026-92603Medium· 6.5PoC
1w ago

ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements

ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements. Attackers can supply arbitrary message…

▾ Twilightcontinew-org · continew-adminEPSS 0.47%via NVD
CVE-2026-59974High· 7.8PoC
1w ago

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.resources.common.unzip in stanza/resources/common.py passes downloaded model and resource …

▾ Midnightstanfordnlp · stanzaEPSS 0.40%via NVD
CVE-2026-92399High· 7.3PoC
1w ago

A vulnerability was determined in GPAC 26.07.0

A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of the argument payload_size can lead to hea…

▾ MidnightEPSS 0.69%via NVD
CVEs tagged “exploit-available” — page 26 · VulnSea