VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3545 CVEsRSS

CVE-2026-47780Medium· 6.9PoC
1w ago

free5GC is an open-source implementation of the 5G core network

free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscriptions in free5gc/udr internal/sbi/api_datarepository.go validate the ueId path value with a regul…

▾ Twilightfree5gc · free5gcEPSS 0.54%via NVD
CVE-2026-54637Medium· 5.5PoC
1w ago

Dragonfly is an open source P2P-based file distribution and image acceleration system

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the scheduler's default unauthenticated v1 gRPC flow accepts attacker-controlled PeerHost.Ip and PeerHost.DownPort values through…

▾ Twilightdragonflyoss · dragonflyEPSS 0.80%via NVD
CVE-2026-46488Critical· 9.1PoC
1w ago

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash c…

▾ Abyssalmotioneye-project · motioneyeEPSS 0.46%via NVD
CVE-2026-55863Medium· 5.3PoC
1w ago

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, the ActionHandler.post() method in motioneye/handlers/action.py lacks the Base…

▾ Twilightmotioneye-project · motioneyeEPSS 0.50%via NVD
CVE-2026-55691High· 8.6PoC
1w ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/Embed…

▾ MidnightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.48%via NVD
CVE-2026-55650Medium· 4.4PoC
1w ago

Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite

Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangero…

▾ Twilightouterbase · studioEPSS 0.19%via NVD
CVE-2026-55692High· 7.5PoC
1w ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent…

▾ MidnightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.49%via NVD
CVE-2026-55770Medium· 6.8PoC
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/lda…

▾ Twilightopenbao · openbaoEPSS 0.53%via NVD
CVE-2026-55776Medium· 6.5PoC
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type paramete…

▾ Twilightopenbao · openbaoEPSS 0.61%via NVD
CVE-2026-55591Medium· 5.8PoC
1w ago

Signal K Server is a server application that runs on a central hub in a boat

Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, port, useTLS, and selfsignedcert parameters from the testSignalK…

▾ TwilightSignalK · signalk-serverEPSS 0.30%via NVD
CVE-2026-91197Medium· 6.5PoC
1w ago

Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources

Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. Attackers wit…

▾ Twilightflowable · flowable-engineEPSS 0.46%via NVD
CVE-2026-90829Medium· 5.3PoC
1w ago

A weakness has been identified in GNU Binutils 2.47

A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereferen…

▾ Twilightgnu · binutilsEPSS 0.17%via NVD
CVE-2026-90830Medium· 5.3PoC
1w ago

A security vulnerability has been detected in GNU Binutils 2.47

A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack ne…

▾ Twilightgnu · binutilsEPSS 0.17%via NVD
CVE-2026-90835Low· 3.5PoC
1w ago

A flaw has been found in michaelliao itranswarp up to 2.19

A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the file Markdown.java of the component Page Content Rendering. This manipulation causes cross site scripting. The attack…

▾ Twilightmichaelliao · itranswarpEPSS 0.35%via NVD
CVE-2026-90825Low· 3.3PoC
1w ago

A vulnerability was found in GPAC 26.07.0

A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack is only…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-90826Low· 2.8PoC
1w ago

A vulnerability was determined in GPAC 26.07.0

A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes out-of-bounds read. The attack is restricted to…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-91143High· 7.2PoC
1w ago

goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements

goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the aut…

▾ Midnightsnail007 · goproxyEPSS 0.47%via NVD
CVE-2026-90827Low· 3.3PoC
1w ago

A vulnerability was identified in GPAC 26.07.0

A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack must be carried out l…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-91145High· 7.1PoC
1w ago

Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering

Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated i…

▾ MidnightActiviti · ActivitiEPSS 0.42%via NVD
CVE-2026-12944Critical· 9.6PoC
1w ago

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential…

▾ AbyssalIBM · Langflow OSSEPSS 0.39%via NVD
CVE-2026-90828Medium· 5.3PoC
1w ago

A security flaw has been discovered in GNU Binutils 2.47

A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer…

▾ Twilightgnu · binutilsEPSS 0.19%via NVD
CVE-2026-90818Medium· 4.3PoC
1w ago

A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4

A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function OpenClawConfigSync.buildBrowserConfig of the file src/main/libs/openclawConfigSync.ts of the component Browse…

▾ Twilightnetease-youdao · LobsterAIEPSS 0.54%via NVD
CVE-2026-65374High· 8.8PoC
1w ago

A memory corruption issue was addressed with improved validation

A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious WebDAV server may result in code execution.

▾ Midnightapple · macosEPSS 0.53%via NVD
CVE-2026-43786High· 7.8PoC
1w ago

This issue was addressed with additional entitlement checks

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

▾ Midnightapple · macosEPSS 0.15%via NVD
CVE-2026-84616Medium· 5.5PoC
1w ago

A type confusion issue was addressed with improved memory handling

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An a…

▾ Twilightapple · ipadosEPSS 0.15%via NVD
CVE-2026-84568High· 7.8PoC
1w ago

A path traversal issue was addressed with improved path validation

A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker with control of a network directory server may be able to execute arbitrar…

▾ Midnightapple · macosEPSS 0.19%via NVD
CVE-2026-84600Medium· 5.4PoC
1w ago

An authorization issue was addressed with improved state management

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user conf…

▾ Twilightapple · ipadosEPSS 0.29%via NVD
CVE-2026-43783High· 7.8PoC
1w ago

A race condition was addressed with improved locking

A race condition was addressed with improved locking. This issue is fixed in macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

▾ Midnightapple · macosEPSS 0.13%via NVD
CVE-2026-43687Medium· 6.5PoC
1w ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server …

▾ Twilightapple · ipadosEPSS 0.44%via NVD
CVE-2026-84543High· 7.5PoC
1w ago

An out-of-bounds access issue was addressed with improved bounds checking

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may cause unexpected system termination or…

▾ Midnightapple · macosEPSS 0.43%via NVD
CVEs tagged “exploit-available” — page 34 · VulnSea