VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3546 CVEsRSS

CVE-2026-76796Medium· 4.0PoC
1w ago

The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outsi…

The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outsi…

▾ TwilightNewell Brands · DYMO Connect DesktopEPSS 0.18%via NVD
CVE-2026-61544High· 8.2PoC
1w ago

libp2p-rust is the official Rust language implementation of the libp2p networking stack

libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic could panic during an inbound QUIC handshake when a remote peer presented a valid short-lived libp2p TLS certificate an…

▾ Midnightlibp2p · rust-libp2pEPSS 0.28%via NVD
CVE-2026-51134High· 7.5PoC
1w ago

The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.

The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.

▾ MidnightEPSS 1.7%via NVD
CVE-2026-51133Medium· 6.1PoC
1w ago

Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component

Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component

▾ TwilightEPSS 0.91%via NVD
CVE-2026-88743Medium· 6.1PoC
1w ago

Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.

Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.

▾ TwilightEPSS 0.26%via NVD
CVE-2026-79411High· 8.8PoC
1w ago

Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator

Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoin…

▾ MidnightEPSS 0.45%via NVD
CVE-2026-79410High· 8.1PoC
1w ago

Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.

Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.

▾ MidnightEPSS 0.39%via NVD
CVE-2026-79409Medium· 6.5PoC
1w ago

An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.

An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-69212Medium· 5.9PoC
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware strips Authorization and Cookie headers only when a redirect changes authority, but authority comparison excludes the URI…

▾ Twilighthttp4s · http4sEPSS 0.28%via NVD
CVE-2026-58704High· 8.8CISA KEV0dayPoC
1w ago

In Cellular Modem, there is a possible permission bypass due to a logic error in the code

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not need…

▾ Abyssalgoogle · androidEPSS 0.59%via NVD
CVE-2026-58502High· 7.1PoC
1w ago

githubtoplanguages generates a user's top GitHub languages as an SVG

githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow runs when an issue is opened or closed and interpolates github.event.issue.title directly into the Bash assignment for…

▾ Midnightgouef · githubtoplanguagesEPSS 0.53%via NVD
CVE-2026-58485High· 7.1PoC
1w ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read receives its caller-controlled URL through src/index.ts and validates only the …

▾ Midnightihor-sokoliuk · mcp-searxngEPSS 0.19%via NVD
CVE-2026-58483High· 7.5PoC
1w ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read in src/index.ts passes a caller-supplied URL to readUrlContent() in src/url-rea…

▾ Midnightihor-sokoliuk · mcp-searxngEPSS 0.67%via NVD
CVE-2026-57442Medium· 6.9PoC
1w ago

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian, and node_modules pa…

▾ Twilightbitbonsai · mcpvaultEPSS 0.19%via NVD
CVE-2026-52484High· 8.8PoC
1w ago

An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code via the /cgi-bin/device-management-utilities-internet.cgi component

An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code via the /cgi-bin/device-management-utilities-internet.cgi component

▾ MidnightEPSS 0.64%via NVD
CVE-2026-39038Medium· 6.1PoC
1w ago

BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx.

BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-91855Medium· 5.3PoC
1w ago

A security flaw has been discovered in Open5GS up to 2.7.7

A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality of the file lib/pfcp/handler.c of the component PFCP Message Handler. Performing a manipulation results in denial of s…

▾ TwilightEPSS 0.72%via NVD
CVE-2026-89026Critical· 9.8PoC
1w ago

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticate…

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticate…

▾ AbyssalIssabel Foundation · Issabel FrameworkEPSS 0.69%via NVD
CVE-2024-58385Critical· 9.8PoC
1w ago

Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL querie…

Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL querie…

▾ AbyssalYonyou · U8 CRMEPSS 0.38%via NVD
CVE-2023-54398Critical· 9.8PoC
1w ago

Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialize…

Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialize…

▾ AbyssalYonyou · U8 CloudEPSS 0.64%via NVD
CVE-2026-91853High· 7.4PoC
1w ago

A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224

A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvpn of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user of the component Export Ovpn Handler. The manipulation…

▾ MidnightTOTOLINK · X5000REPSS 1.8%via NVD
CVE-2026-91854Medium· 4.3PoC
1w ago

A vulnerability was identified in code-projects Record Management System 1.0

A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc leads to cross site scripting. The attack may be launched remo…

▾ Twilightcode-projects · Record Management SystemEPSS 0.47%via NVD
CVE-2026-85013High· 7.3PoC
1w ago

A flaw was found in environment-modules

A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `…

▾ MidnightRed Hat · environment-modules-mainEPSS 0.22%via NVD
CVE-2026-91848High· 7.3PoC
1w ago

A vulnerability was identified in WuzhiCMS up to 4.1.0

A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the argument title/master_table leads t…

▾ MidnightEPSS 0.43%via NVD
CVE-2026-91930High· 7.5PoC
1w ago

Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs

Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, cre…

▾ MidnightFlowiseAI · FlowiseEPSS 0.40%via NVD
CVE-2024-14029High· 7.5PoC⚖ disputed
1w ago

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deploye…

▾ Midnighttornadoweb · tornadoEPSS 0.35%via NVD
CVE-2026-91932High· 8.5PoC
1w ago

Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter

Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean fil…

▾ MidnightFlowiseAI · FlowiseEPSS 0.73%via NVD
CVE-2026-91936Medium· 6.8PoC
1w ago

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shel…

▾ TwilightFlowiseAI · FlowiseEPSS 0.46%via NVD
CVE-2026-91931High· 8.5PoC
1w ago

Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter

Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invok…

▾ MidnightFlowiseAI · FlowiseEPSS 0.68%via NVD
CVE-2026-91940High· 7.5PoC
1w ago

crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields

crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies w…

▾ Midnightunclecode · crawl4aiEPSS 0.46%via NVD
CVEs tagged “exploit-available” — page 29 · VulnSea