VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

2824 CVEsRSS

CVE-2026-93873Medium· 4.3PoC
3d ago

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-submit contact forms from attacker-controlled pages to send forged messages attri…

TwilightCotonti · CotontiEPSS 0.16%via NVD
CVE-2026-93871Medium· 5.4PoC
3d ago

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attackers can craft pa…

TwilightCotonti · CotontiEPSS 0.17%via NVD
CVE-2026-93869Medium· 6.1PoC
3d ago

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers can bypass the redirect guard by sup…

TwilightCotonti · CotontiEPSS 0.22%via NVD
CVE-2026-93868High· 8.1PoC
3d ago

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the s…

MidnightCotonti · CotontiEPSS 0.61%via NVD
CVE-2026-63647Critical· 9.3PoC
3d ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFi…

Abyssal1Panel-dev · CordysCRMEPSS 0.47%via NVD
CVE-2026-63646Medium· 6.9PoC
3d ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, GET /mcp/form/config/{formKey} calls McpController.getMcpField without authentication because ShiroFilter.ad…

Twilight1Panel-dev · CordysCRMEPSS 0.49%via NVD
CVE-2017-20284High· 7.5PoC
3d ago

Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the…

Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the…

MidnightCaucho Technology, Inc. · ResinEPSS 0.96%via NVD
CVE-2026-93838Medium· 5.9PoC
3d ago

SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments

SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access …

Twilightsgl-project · sglangEPSS 0.46%via NVD
CVE-2026-91203Medium· 6.0PoC
3d ago

A flaw was found in cockpit-files

A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating…

TwilightRed Hat · cockpit-filesEPSS 0.07%via NVD
CVE-2026-93650Low· 3.7PoC
3d ago

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of…

TwilightEPSS 0.55%via NVD
CVE-2026-93753High· 7.5PoC
3d ago

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to…

MidnightTehShrike · deepmergeEPSS 0.36%via NVD
CVE-2026-93752High· 7.5PoC
3d ago

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal…

MidnightNV · CSSOMEPSS 0.47%via NVD
CVE-2026-93750Medium· 5.9PoC
3d ago

http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison

http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previous…

Twilightkornelski · http-cache-semanticsEPSS 0.35%via NVD
CVE-2026-93748High· 7.5PoC
3d ago

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers …

Midnightkornelski · http-cache-semanticsEPSS 0.40%via NVD
CVE-2026-92747Medium· 5.0PoC
3d ago

A flaw was found in `cockpit-machines`

A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This …

TwilightRed Hat · cockpit-machinesEPSS 0.15%via NVD
CVE-2026-59163Critical· 9.1PoC
3d ago

Mnemosyne is a memory layer for artificial intelligence agents

Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt library call with…

Abyssalmnemosyne-memory · mnemosyne-memoryEPSS 0.25%via NVD
CVE-2026-92701Critical· 9.1PoC
3d ago

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expe…

Abyssalultravioletrs · cocosEPSS 0.22%via NVD
CVE-2026-77385Medium· 4.3PoC
3d ago

Kyoo is a self-hosted media server focused on movies, series, and anime

Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src…

Twilightzoriya · KyooEPSS 0.32%via NVD
CVE-2026-69186Medium· 5.3PoC
3d ago

c-ares is an asynchronous resolver library

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Beca…

Twilightc-ares · c-aresEPSS 0.52%via NVD
CVE-2026-84992Medium· 6.1PoC
3d ago

md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript

md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts inserts a fenced-code language …

Twilightimzbf · md-editor-v3EPSS 0.23%via NVD
CVE-2026-63406Medium· 5.9PoC
3d ago

AnyCable is a realtime server for reliable two-way communication that supports any backend

AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a hardcoded public authToken, while clusterFingerprint in t…

Twilightanycable · github.com/anycable/anycableEPSS 0.24%via NVD
CVE-2026-63405Medium· 5.9PoC
3d ago

AnyCable is a realtime server for reliable two-way communication that supports any backend

AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher-compatible REST API in pusher/http.go includes the caller-supplied body_md5 value in the HMAC input but does not calc…

Twilightanycable · github.com/anycable/anycableEPSS 0.17%via NVD
CVE-2026-44639Low· 3.7PoC
3d ago

NanoMQ is an MQTT broker

NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c uses property_append() to walk the entire linked list for each property added by decode_buf_properties(). A remote un…

Twilightnanomq · nanomqEPSS 0.34%via NVD
CVE-2026-61633Low· 2.0PoC
3d ago

NanoMQ is an MQTT broker

NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/supplemental/mqtt/mqtt_codec.c does not handle a failed read_uint16() while counting topics in a malformed UNSUBSCRIBE pa…

Twilightnanomq · nanomqEPSS 0.25%via NVD
CVE-2026-81505High· 7.1PoC
3d ago

Convoy is a cloud native webhooks gateway

Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() a…

Midnightfrain-dev · github.com/frain-dev/convoyEPSS 0.34%via NVD
CVE-2026-93534Medium· 6.3PoC
3d ago

A vulnerability was identified in spatie Scotty up to 1.4.2

A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the component Self Update Handler. Such manipulation leads to download of code without i…

Twilightspatie · ScottyEPSS 0.20%via NVD
CVE-2026-77339Medium· 5.1PoC
3d ago

Process Compose is a scheduler and orchestrator for non-containerized applications

Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listener in src/mcp/server.go accepts browser-origin requests to /sse and the returned message endpoint without validating …

Twilightf1bonacc1 · github.com/f1bonacc1/process-composeEPSS 0.21%via NVD
CVE-2026-58197High· 8.8PoC
3d ago

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission pro…

Midnightstacklok · github.com/stacklok/toolhiveEPSS 0.36%via NVD
CVE-2026-77301High· 7.5PoC
3d ago

adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js

adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEntry.js trusts an entry's central-directory uncompressed size and allocates output memory before validating that value …

Midnightadm-zip · adm-zipEPSS 0.41%via NVD
CVE-2026-93736Medium· 4.3PoC
3d ago

Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path

Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path. Attackers ca…

Twilightmealie-recipes · mealieEPSS 0.28%via NVD
CVEs tagged “exploit-available” — page 3 · VulnSea