VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3537 CVEsRSS

CVE-2026-69200Low· 3.7PoC
1w ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to node-opcua-client 2.145.0, the internal fieldsToJson method in packages/node-opcua-client/source/alarms_and_conditions/client_alarm.ts directly assigns unsanitiz…

▾ Twilightnode-opcua · node-opcuaEPSS 0.35%via NVD
CVE-2026-85732Medium· 4.7PoC
1w ago

oras-go is a Go library for managing OCI artifacts

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. …

▾ Twilightoras-project · oras-goEPSS 0.35%via NVD
CVE-2026-85731High· 8.8PoC
1w ago

oras-go is a Go library for managing OCI artifacts

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractT…

▾ Midnightoras-project · oras-goEPSS 0.63%via NVD
CVE-2026-20284Critical· 9.1⚠ ExploitedPoC
1w ago

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacke…

▾ AbyssalCisco · Cisco Identity Services Engine SoftwareEPSS 0.39%via NVD
CVE-2026-76460Critical· 10.0CISA KEV0dayPoC
1w ago

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attack…

▾ Hadalcisco · identity_services_engineEPSS 14%via NVD
CVE-2026-92385Low· 2.4PoC
1w ago

A vulnerability has been found in SourceCodester Online Food Ordering System 1.0

A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation leads to cross site s…

▾ TwilightSourceCodester · Online Food Ordering SystemEPSS 0.38%via NVD
CVE-2026-92397Critical· 9.1PoC
1w ago

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads t…

▾ AbyssalRuijie · RG-EW3000GXEPSS 3.2%via NVD
CVE-2025-59953Critical· 9.8PoC
1w ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC commu…

▾ AbyssalInternLM · lmdeployEPSS 0.80%via NVD
CVE-2026-92383Medium· 4.3PoC
1w ago

A security vulnerability has been detected in PbootCMS up to 3.2.24

A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the component User Manage…

▾ TwilightEPSS 0.24%via NVD
CVE-2026-92366High· 7.3PoC
1w ago

A vulnerability was determined in code-projects Matrimonial System 1.0

A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mothertongue/maritialstatus/country/state…

▾ Midnightcode-projects · Matrimonial SystemEPSS 0.56%via NVD
CVE-2026-63671High· 8.1PoC
1w ago

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml enabled by default and relies on validateProps, validateProp, and…

▾ Midnightnuxt-content · mdcEPSS 0.47%via NVD
CVE-2026-92380High· 7.3PoC
1w ago

A flaw has been found in WuzhiCMS up to 4.1.0

A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote Image Fetch. This manipulation of the argument source[] causes…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-92568Medium· 5.4PoC
1w ago

MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses

MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses. Attackers can update …

▾ Twilightmlrun · mlrunEPSS 0.33%via NVD
CVE-2026-92569Medium· 4.3PoC
1w ago

Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter

Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter. Authenticated attackers can supply arbitrary hostnames and ports to trig…

▾ Twilightopengoofy · hippo4jEPSS 0.34%via NVD
CVE-2026-92566High· 8.2PoC
1w ago

DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI

DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI. Attackers ca…

▾ Midnightdatageartech · datagearEPSS 0.54%via NVD
CVE-2026-92570Medium· 6.5PoC
1w ago

reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files

reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. Attackers with low-privilege Auditor roles can ac…

▾ Twilightyogeshojha · rengineEPSS 0.44%via NVD
CVE-2026-82964High· 8.8PoC
1w ago

Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox…

Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox…

▾ MidnightGen Digital · Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business SecurityEPSS 0.16%via NVD
CVE-2026-92381Low· 3.5PoC
1w ago

A weakness has been identified in PbootCMS up to 3.2.22

A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/controller/content/ContentController.php of the component Template Rendering. This manipulation of the argument Title…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-84997High· 7.5PoC
1w ago

react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP

react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body …

▾ Midnightreactphp · httpEPSS 0.66%via NVD
CVE-2026-63128High· 7.5PoC
1w ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an unauthenticated client to send a well-fo…

▾ Midnightmodelcontextprotocol · rust-sdkEPSS 0.63%via NVD
CVE-2026-63127High· 8.2PoC
1w ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oau…

▾ Midnightmodelcontextprotocol · rust-sdkEPSS 0.20%via NVD
CVE-2026-91843Critical· 9.8PoC
1w ago

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

▾ Abyssalcheckpoint · Quantum Security ManagementEPSS 0.52%via NVD
CVE-2026-92469High· 8.1PoC
1w ago

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifie…

▾ Midnightzlt2000 · microservices-platformEPSS 0.54%via NVD
CVE-2026-92467High· 8.3PoC
1w ago

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. …

▾ Midnightzlt2000 · microservices-platformEPSS 0.46%via NVD
CVE-2026-92468Medium· 6.5PoC
1w ago

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{in…

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{in…

▾ Twilightzlt2000 · microservices-platformEPSS 0.48%via NVD
CVE-2026-92466High· 8.8PoC
1w ago

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated user…

▾ Midnightzlt2000 · microservices-platformEPSS 0.91%via NVD
CVE-2026-92364Medium· 6.3PoC
1w ago

A vulnerability has been found in itsourcecode Leave Management System 1.0

A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/employee/index.php. The manipulation of the argument ID leads to sql injection. It…

▾ Twilightitsourcecode · Leave Management SystemEPSS 0.33%via NVD
CVE-2026-92455Medium· 4.3PoC
1w ago

yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers

yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers. Attackers can invoke POST /a…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.36%via NVD
CVE-2026-92458Medium· 4.3PoC
1w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status. Attackers can invoke the GET /admin-api/produc…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.35%via NVD
CVE-2026-92457Medium· 6.5PoC
1w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call the PUT /admin-api/crm/i…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.43%via NVD
CVEs tagged “exploit-available” — page 27 · VulnSea