VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3545 CVEsRSS

CVE-2026-90845Low· 3.5PoC
1w ago

A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1

A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to cross site scripting. …

▾ TwilightPHPGurukul · Daily Expense Tracker SystemEPSS 0.35%via NVD
CVE-2026-90844High· 7.3PoC
1w ago

A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1

A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injec…

▾ MidnightPHPGurukul · Daily Expense Tracker SystemEPSS 0.43%via NVD
CVE-2026-90843High· 8.3PoC
1w ago

A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25

A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler. Such manipul…

▾ MidnightSabyasachiRana · WebMapEPSS 2.2%via NVD
CVE-2026-90842Low· 3.7PoC
1w ago

A weakness has been identified in PHPGurukul Blood Donor Management System 1.0

A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/c…

▾ TwilightPHPGurukul · Blood Donor Management SystemEPSS 0.31%via NVD
CVE-2026-90841High· 7.3PoC
1w ago

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The m…

▾ MidnightPHPGurukul · Blood Donor Management SystemEPSS 0.43%via NVD
CVE-2026-90840High· 7.3PoC
1w ago

A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0

A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to i…

▾ MidnightPHPGurukul · Blood Donor Management SystemEPSS 0.69%via NVD
CVE-2026-59973High· 8.5PoC
1w ago

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP)

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts loadOpenAPISp…

▾ Midnightagentfront · frontmcpEPSS 0.39%via NVD
CVE-2026-56831Medium· 6.5PoC
1w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Di…

▾ Twilightshopperlabs · shopperEPSS 0.43%via NVD
CVE-2026-56829High· 8.1PoC
1w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable be…

▾ Midnightshopperlabs · shopperEPSS 0.50%via NVD
CVE-2026-56827High· 8.1PoC
1w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/Attribute/Browse.php, packages/admin/src/Livewire/Pages/Tag/Index.php, packages/admin/src/Livewire/Pages/Brand/Index.ph…

▾ Midnightshopperlabs · shopperEPSS 0.50%via NVD
CVE-2026-56825High· 8.1PoC
1w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Collection/CollectionProducts.php exposes Action::make('delete') and DeleteBulkAction::make() without delete_collections authorization, …

▾ Midnightshopperlabs · shopperEPSS 0.50%via NVD
CVE-2026-59965High· 7.1PoC
1w ago

Payload Plugins is a collection of plugins designed to enhance Payload CMS

Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts a…

▾ Midnightjhb-software · payload-pluginsEPSS 0.38%via NVD
CVE-2026-59160High· 8.8PoC
1w ago

Yeger is a monorepo for npm packages maintained under the yeger scope

Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by defaul…

▾ MidnightDerYeger · yegerEPSS 0.49%via NVD
CVE-2026-54050Medium· 6.5PoC
1w ago

Sakai is a Collaboration and Learning Environment (CLE)

Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another user's profile image because ProfileController.r…

▾ Twilightsakaiproject · sakaiEPSS 0.31%via NVD
CVE-2026-55149High· 7.5PoC
1w ago

Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module

Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part count from an attacker-controlled multipart cookie name and passes the val…

▾ Midnightvouch · vouch-proxyEPSS 0.72%via NVD
CVE-2026-53957High· 7.7PoC
1w ago

Contentful MCP Server is a Model Context Protocol server for the Contentful Management API

Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-…

▾ Midnightcontentful · contentful-mcp-serverEPSS 0.41%via NVD
CVE-2026-54688Medium· 6.5PoC
1w ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, web_url_read passes a caller-supplied URL to the server-side fetch path while assertUrlAllow…

▾ Twilightihor-sokoliuk · mcp-searxngEPSS 0.50%via NVD
CVE-2026-54689Medium· 6.3PoC
1w ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy in src/url-reader.ts can be bypassed while MCP_HTTP_HARDEN is en…

▾ Twilightihor-sokoliuk · mcp-searxngEPSS 0.19%via NVD
CVE-2026-49446Medium· 6.1PoC
1w ago

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tu…

▾ Twilightazukaar · Cosmos-ServerEPSS 0.30%via NVD
CVE-2026-57112High· 8.3PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts SseServerTransport on the legac…

▾ MidnightMervinPraison · PraisonAIEPSS 0.22%via NVD
CVE-2026-57148Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance …

▾ AbyssalMervinPraison · PraisonAIEPSS 0.64%via NVD
CVE-2026-57147Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run whe…

▾ AbyssalMervinPraison · PraisonAIEPSS 0.77%via NVD
CVE-2026-54561Medium· 6.2PoC
1w ago

MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants

MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath directly to fs.readFileSync without restricting the path …

▾ Twilightmkreyman · mcp-memory-keeperEPSS 0.25%via NVD
CVE-2026-54549High· 8.3PoC
1w ago

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, the upload_ad_image tool in meta_ads_mcp/core/ads.py passes an attacker-controlled image_url to try_multiple_download_m…

▾ Midnightpipeboard-co · meta-ads-mcpEPSS 0.40%via NVD
CVE-2026-54547High· 7.4PoC
1w ago

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py rejects HTTP MCP requests only when both auth_tok…

▾ Midnightpipeboard-co · meta-ads-mcpEPSS 0.52%via NVD
CVE-2026-58196Medium· 4.7PoC
1w ago

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.31.0, remote.Handler.Authenticate in pkg/auth/remote/handler.go invokes discovery.DetectAuthenticationFromServer…

▾ Twilightstacklok · toolhiveEPSS 0.43%via NVD
CVE-2026-52819Medium· 6.3PoC
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with view_other_timesheet but does not apply access_user or verify that a…

▾ Twilightkimai · kimaiEPSS 0.50%via NVD
CVE-2026-52824Critical· 9.1PoC
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that …

▾ Abyssalkimai · kimaiEPSS 1.3%via NVD
CVE-2026-48737Medium· 4.9PoC
1w ago

pyLoad is a free and open-source download manager written in Python

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in src/pyload/core/utils/web/check.py relies on Python's global-address classification without examining IPv4 destinations em…

▾ Twilightpyload · pyloadEPSS 0.29%via NVD
CVE-2026-48987Medium· 6.5PoC
1w ago

pyLoad is a free and open-source download manager written in Python

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload/core/managers/event_manager.py appends a Client object to the clients list for each unique uuid submitted to the aut…

▾ Twilightpyload · pyloadEPSS 0.44%via NVD
CVEs tagged “exploit-available” — page 33 · VulnSea