VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3546 CVEsRSS

CVE-2026-91992Medium· 5.9PoC
1w ago

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through th…

▾ Twilighttornadoweb · tornadoEPSS 0.26%via NVD
CVE-2026-91991Medium· 5.4PoC
1w ago

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-de…

▾ Twilighttornadoweb · tornadoEPSS 0.28%via NVD
CVE-2026-91849Medium· 6.3PoC
1w ago

A security flaw has been discovered in WuzhiCMS up to 4.1.0

A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in …

▾ TwilightEPSS 0.37%via NVD
CVE-2026-37152Critical· 9.8PoC
1w ago

TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.

TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.

▾ AbyssalEPSS 0.51%via NVD
CVE-2026-91842Medium· 4.1PoC
1w ago

A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1

A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. Such manipulation leads t…

▾ TwilightOpenBankProject · OBP-APIEPSS 0.38%via NVD
CVE-2026-91836Low· 2.8PoC
1w ago

A flaw has been found in OpenClaw ClawScan up to 0.1.6

A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomplete comparison with missing factors. …

▾ TwilightOpenClaw · ClawScanEPSS 0.33%via NVD
CVE-2026-88618Medium· 6.5PoC
1w ago

1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality

1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This allows a remote attacker to execute arbitrary code.

▾ TwilightEPSS 0.34%via NVD
CVE-2026-79551High· 7.5PoC
1w ago

Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key.

Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key.

▾ MidnightEPSS 0.30%via NVD
CVE-2026-79425High· 8.1PoC
1w ago

An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows attackers to scan internal resources via a crafted POST request.

An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows attackers to scan internal resources via a crafted POST request.

▾ MidnightEPSS 0.36%via NVD
CVE-2026-79303Critical· 9.9PoC
1w ago

kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection

kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without the required data validation and without using parameterized statements or stored procedures.

▾ AbyssalEPSS 0.43%via NVD
CVE-2026-91835Low· 2.8PoC
1w ago

A vulnerability was detected in OpenClaw ClawScan up to 0.1.6

A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File Classifier. The manipulation results in interpretation c…

▾ TwilightOpenClaw · ClawScanEPSS 0.16%via NVD
CVE-2026-88616High· 8.8PoC
1w ago

An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /wo…

An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /wo…

▾ MidnightEPSS 0.69%via NVD
CVE-2026-77179Critical· 9.4PoC
1w ago

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, an…

▾ AbyssalDocker · Docker SandboxesEPSS 0.20%via NVD
CVE-2026-91998Critical· 9.9PoC
1w ago

Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizati…

Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizati…

▾ Abyssalcasdoor · casdoorEPSS 0.59%via NVD
CVE-2026-91997Medium· 5.3PoC
1w ago

evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint

evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restricti…

▾ Twilightevolution-foundation · evolution-apiEPSS 0.45%via NVD
CVE-2026-91996High· 7.5PoC
1w ago

lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map

lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getPrope…

▾ Midnightdromara · lamp-cloudEPSS 0.50%via NVD
CVE-2026-91994Medium· 6.5PoC
1w ago

Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware

Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all project environments including plaintext secrets, credenti…

▾ Twilightsemaphoreui · semaphoreEPSS 0.41%via NVD
CVE-2026-91993Medium· 4.3PoC
1w ago

Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces

Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces. Attackers can submit repository identif…

▾ Twilightdromara · JpomEPSS 0.34%via NVD
CVE-2026-91925High· 8.8PoC
1w ago

Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code

Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code. Attackers can submit runs with Jinja2 paylo…

▾ Midnightpolyaxon · polyaxonEPSS 0.78%via NVD
CVE-2026-91924High· 8.5PoC
1w ago

pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings

pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings. Attackers can bypass the resource-to-database mapp…

▾ Midnightsosedoff · pgwebEPSS 0.42%via NVD
CVE-2026-91922Medium· 6.1PoC
1w ago

Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/page/render endpoint that fails to properly escape query parameters in inline script elements

Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/page/render endpoint that fails to properly escape query parameters in inline script elements. Attackers can craft mali…

▾ Twilightsteedos · steedos-platformEPSS 0.34%via NVD
CVE-2026-57137High· 8.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop.ts passes executable tools to generateText() before invoking the onToolCall approval callback. Because the wrapped A…

▾ MidnightMervinPraison · PraisonAIEPSS 0.51%via NVD
CVE-2026-57135High· 7.6PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment…

▾ MidnightMervinPraison · PraisonAIEPSS 0.42%via NVD
CVE-2026-57134High· 8.2PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth …

▾ MidnightMervinPraison · PraisonAIEPSS 0.41%via NVD
CVE-2026-57139Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards every HTTP POST request to handleRequest() without authentication …

▾ AbyssalMervinPraison · PraisonAIEPSS 0.75%via NVD
CVE-2026-57133High· 8.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delimited token against safeCommands and then passes the compl…

▾ MidnightMervinPraison · PraisonAIEPSS 0.80%via NVD
CVE-2026-57136High· 8.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExec…

▾ MidnightMervinPraison · PraisonAIEPSS 0.55%via NVD
CVE-2026-59341Medium· 4.2PoC
1w ago

A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints

A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modified payload containing custom Go template logic in spec.template.data, an attacker with internal network access can a…

▾ TwilightBitnami · sealed-secretsEPSS 0.40%via NVD
CVE-2026-91781Low· 3.3PoC
1w ago

A security vulnerability has been detected in GNU Binutils 2.47

A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer derefer…

▾ Twilightgnu · binutilsEPSS 0.18%via NVD
CVE-2026-91780Low· 3.3PoC
1w ago

A weakness has been identified in GNU Binutils 2.47

A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally.…

▾ Twilightgnu · binutilsEPSS 0.17%via NVD
CVEs tagged “exploit-available” — page 31 · VulnSea