VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3538 CVEsRSS

CVE-2026-92456High· 7.1PoC
1w ago

yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer …

yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer …

▾ Midnightguchengwuyue · yshop-crmEPSS 0.50%via NVD
CVE-2026-92463Medium· 6.5PoC
1w ago

yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticated back-office users without system:user:list permission t…

yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticated back-office users without system:user:list permission t…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.46%via NVD
CVE-2026-92460Medium· 6.5PoC
1w ago

yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail

yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can query the operation log to …

▾ Twilightguchengwuyue · yshop-crmEPSS 0.45%via NVD
CVE-2026-92461Medium· 4.3PoC
1w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers can retrieve approval chain …

▾ Twilightguchengwuyue · yshop-crmEPSS 0.38%via NVD
CVE-2026-92459Medium· 6.5PoC
1w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can in…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.43%via NVD
CVE-2026-92462Medium· 6.5PoC
1w ago

yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps

yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps. Attackers can invoke the DELETE /adm…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.43%via NVD
CVE-2026-81642Critical· 9.8PoC
1w ago

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression po…

▾ Abyssalnlnetlabs · unboundEPSS 0.96%via NVD
CVE-2026-92091Medium· 5.9PoC
1w ago

A flaw was found in jwcrypto

A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauthenticated attacke…

▾ TwilightRed Hat · ansible-automation-platform-24/controller-rhel8EPSS 0.66%via NVD
CVE-2026-84906Medium· 5.3PoC
1w ago

The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or w…

The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or w…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-13407Medium· 5.4PoC
1w ago

The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated a…

The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated a…

▾ TwilightEPSS 0.22%via NVD
CVE-2026-19857Medium· 4.8PoC
1w ago

The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, allowing unauthenticated visitors to…

The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, allowing unauthenticated visitors to…

▾ TwilightEPSS 0.19%via NVD
CVE-2026-86475Medium· 5.3PoC
1w ago

The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitors to take slots that are already fully…

The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitors to take slots that are already fully…

▾ TwilightEPSS 0.31%via NVD
CVE-2026-89063High· 7.5PoC
1w ago

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation…

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation…

▾ Midnightladela · Online Scheduling and Appointment Booking System – BooklyEPSS 1.6%via NVD
CVE-2026-12793Critical· 9.8PoC
1w ago

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFo…

▾ Abyssaljetmonsters · JetFormBuilder — Dynamic Blocks Form BuilderEPSS 0.52%via NVD
CVE-2026-92247Medium· 4.7PoC
1w ago

A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4

A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of the component Admin File Manager. The manipulation leads to unrestricted upload.…

▾ Twilightsynaptikcms · synaptik-cmsEPSS 0.40%via NVD
CVE-2026-92221Medium· 4.7PoC
1w ago

A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8

A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this vulnerability is the function generate_index_pasien of the file application/models/app_global_admin_model.p…

▾ Twilightgedelumbung · HospitalManagementEPSS 0.35%via NVD
CVE-2026-61560Critical· 9.8PoC
1w ago

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from th…

▾ Abyssalzereight · @zereight/mcp-gitlabEPSS 0.81%via NVD
CVE-2026-92234Medium· 5.4PoC
1w ago

QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page

QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute inject…

▾ TwilightWebkul · QloAppsEPSS 0.31%via NVD
CVE-2026-91939Critical· 9.8PoC
1w ago

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can ex…

▾ AbyssalCotonti · CotontiEPSS 0.98%via NVD
CVE-2026-61559Critical· 9.6PoC
1w ago

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP…

▾ Abyssalzereight · gitlab-mcpEPSS 0.43%via NVD
CVE-2026-61554High· 7.5PoC
1w ago

emp3r0r is a C2 designed by Linux users for Linux environments

emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentication is completed. A remote unauthenti…

▾ Midnightjm33-m0 · github.com/jm33-m0/emp3r0r/coreEPSS 0.71%via NVD
CVE-2026-54544High· 7.2PoC
1w ago

Fireshare facilitates self-hosted media and link sharing

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. An unauthenticated attacker can call POST /api/test-disco…

▾ MidnightShaneIsrael · fireshareEPSS 0.41%via NVD
CVE-2026-54337Critical· 9.8PoC
1w ago

Fireshare facilitates self-hosted media and link sharing

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. Version 1.6.14 fixes the issue.

▾ AbyssalShaneIsrael · fireshareEPSS 0.63%via NVD
CVE-2026-76796Medium· 4.0PoC
1w ago

The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outsi…

The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outsi…

▾ TwilightNewell Brands · DYMO Connect DesktopEPSS 0.18%via NVD
CVE-2026-61544High· 8.2PoC
1w ago

libp2p-rust is the official Rust language implementation of the libp2p networking stack

libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic could panic during an inbound QUIC handshake when a remote peer presented a valid short-lived libp2p TLS certificate an…

▾ Midnightlibp2p · rust-libp2pEPSS 0.28%via NVD
CVE-2026-51134High· 7.5PoC
1w ago

The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.

The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.

▾ MidnightEPSS 1.7%via NVD
CVE-2026-51133Medium· 6.1PoC
1w ago

Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component

Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component

▾ TwilightEPSS 0.91%via NVD
CVE-2026-88743Medium· 6.1PoC
1w ago

Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.

Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.

▾ TwilightEPSS 0.26%via NVD
CVE-2026-79411High· 8.8PoC
1w ago

Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator

Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoin…

▾ MidnightEPSS 0.45%via NVD
CVE-2026-79410High· 8.1PoC
1w ago

Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.

Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.

▾ MidnightEPSS 0.39%via NVD
CVEs tagged “exploit-available” — page 28 · VulnSea