VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3546 CVEsRSS

CVE-2026-91779Low· 3.3PoC
1w ago

A security flaw has been discovered in GNU Binutils 2.47

A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dere…

▾ Twilightgnu · binutilsEPSS 0.17%via NVD
CVE-2026-91091Medium· 4.3PoC
1w ago

A vulnerability was identified in GPAC up to f1219cde

A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption.…

▾ TwilightEPSS 0.69%via NVD
CVE-2026-91088Medium· 4.8PoC
1w ago

A vulnerability has been found in GPAC up to f1219cde

A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be …

▾ TwilightEPSS 0.16%via NVD
CVE-2026-91087High· 7.3PoC
1w ago

A flaw has been found in GPAC up to f1219cde

A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can lead to use after free. The attack may …

▾ MidnightEPSS 0.64%via NVD
CVE-2026-91086Medium· 6.3PoC
1w ago

A security vulnerability has been detected in GPAC up to f1219cde

A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the component MPEG Video Reframer. Such manipulation leads to heap-based …

▾ TwilightEPSS 0.55%via NVD
CVE-2026-91004High· 7.3PoC
1w ago

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack c…

▾ MidnightSourceCodester · Online Faculty Clearance SystemEPSS 0.43%via NVD
CVE-2026-91003Critical· 9.1PoC
1w ago

A flaw has been found in D-Link DI-8300 16.07

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exp…

▾ AbyssalD-Link · DI-8300EPSS 0.98%via NVD
CVE-2026-91002Medium· 5.3PoC
1w ago

A weakness has been identified in stamparm maltrail up to 3.0.1

A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist Endpoint. Executing a manipulation can lead to missing authenticatio…

▾ Twilightstamparm · maltrailEPSS 0.77%via NVD
CVE-2026-91001Critical· 9.9PoC
1w ago

A security flaw has been discovered in D-Link DI-8400 16.07

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip resul…

▾ AbyssalD-Link · DI-8400EPSS 0.93%via NVD
CVE-2026-90881Medium· 5.3PoC
1w ago

A weakness has been identified in D-Link DIR-882 up to 20260814

A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launc…

▾ TwilightD-Link · DIR-882EPSS 0.83%via NVD
CVE-2026-90880High· 7.4PoC
1w ago

A security flaw has been discovered in D-Link DSL-3782 2016-07-28

A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr resul…

▾ MidnightD-Link · DSL-3782EPSS 1.9%via NVD
CVE-2026-90879High· 7.3PoC
1w ago

A vulnerability was identified in zyx0814 FilePress up to 3.0.1

A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz/publish/search.php of the component Publish Module. Such manipulation of the argument orderby/order leads to sql inj…

▾ Midnightzyx0814 · FilePressEPSS 0.43%via NVD
CVE-2026-90878Medium· 4.3PoC
1w ago

A vulnerability was determined in vllm-project vLLM up to 0.27.1

A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource co…

▾ Twilightvllm-project · vLLMEPSS 0.53%via NVD
CVE-2026-90877High· 7.3PoC
1w ago

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation of the argument haydi results in sql injec…

▾ MidnightSourceCodester · Online Faculty Clearance SystemEPSS 0.43%via NVD
CVE-2026-90876High· 7.3PoC
1w ago

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_requirement.php. The manipulation of the argument ID leads to sql inject…

▾ MidnightSourceCodester · Online Faculty Clearance SystemEPSS 0.43%via NVD
CVE-2026-90858High· 7.3PoC
1w ago

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is the function session_start of the file adminappview.php. Executing a manipulation of …

▾ Midnightsubhajitkhan · online-clinic-management-systemEPSS 0.52%via NVD
CVE-2026-90857Medium· 6.3PoC
1w ago

A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0

A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile Upload. Performing a manipulation of the argument…

▾ TwilightSourceCodester · College Notes Gallery Management SystemEPSS 0.37%via NVD
CVE-2026-90856High· 7.3PoC
1w ago

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role …

▾ MidnightSourceCodester · College Notes Gallery Management SystemEPSS 0.50%via NVD
CVE-2026-90855High· 7.3PoC
1w ago

A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0

A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the argument ID causes sql injection. The attack can be init…

▾ MidnightSourceCodester · Online Food Ordering SystemEPSS 0.41%via NVD
CVE-2026-90852High· 7.3PoC
1w ago

A vulnerability has been found in luben zstd-jni up to 1.5.7-13

A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the file ZstdCompressCtx.java of the component Dictionary Sharing. Such manipulation leads to use after …

▾ Midnightluben · zstd-jniEPSS 0.54%via NVD
CVE-2026-91772Medium· 6.1PoC
1w ago

Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter

Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter. Attackers can craft malicious links on the trusted Halo domain that redirect visitors to arbi…

▾ Twilighthalo-dev · haloEPSS 0.32%via NVD
CVE-2026-91770Medium· 6.5PoC
1w ago

IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records

IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. Attackers can substitute arbitrary employee IDs in skill, education, cer…

▾ Twilightgamonoid · icehrmEPSS 0.45%via NVD
CVE-2026-90851Medium· 6.3PoC
1w ago

A flaw has been found in PHPGurukul Hostel Management System 3.0

A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote exploitation of the a…

▾ TwilightPHPGurukul · Hostel Management SystemEPSS 0.37%via NVD
CVE-2026-90850Low· 2.4PoC
1w ago

A vulnerability was detected in PHPGurukul Hostel Management System 3.0

A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The attack may be lau…

▾ TwilightPHPGurukul · Hostel Management SystemEPSS 0.37%via NVD
CVE-2026-90849High· 7.3PoC
1w ago

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User le…

▾ MidnightSourceCodester · College Notes Gallery Management SystemEPSS 0.43%via NVD
CVE-2026-91752High· 7.5PoC
1w ago

GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data

GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarO…

▾ MidnightGNU · libextractorEPSS 0.74%via NVD
CVE-2026-91751High· 8.3PoC
1w ago

Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory

Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can use traversal seq…

▾ Midnightflextype · flextypeEPSS 0.54%via NVD
CVE-2026-91750Medium· 6.5PoC
1w ago

WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs

WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attackers can bypass initial SSRF validation…

▾ TwilightTencent · WeKnoraEPSS 0.44%via NVD
CVE-2026-90847Critical· 9.1PoC
1w ago

A vulnerability was determined in EFM ipTIME C200E 1.094

A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the at…

▾ AbyssalEFM · ipTIME C200EEPSS 3.4%via NVD
CVE-2026-90846High· 7.3PoC
1w ago

A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1

A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is …

▾ MidnightPHPGurukul · Daily Expense Tracker SystemEPSS 0.43%via NVD
CVEs tagged “exploit-available” — page 32 · VulnSea