VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3546 CVEsRSS

CVE-2026-90824Low· 3.3PoC
1w ago

A vulnerability has been found in GPAC 26.07.0

A vulnerability has been found in GPAC 26.07.0. Affected is the function gf_sg_dom_event_bubble of the file src/scenegraph/dom_events.c of the component MP4Box. The manipulation leads to stack-based buffer overflow. The attack can only b…

▾ TwilightEPSS 0.18%via NVD
CVE-2026-90814Medium· 6.3PoC
1w ago

A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13

A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13. Affected by this vulnerability is the function githubRequest of the file src/utils/github.ts of the component GitHub API Handler. This manipulation of the argument pat…

▾ Twilightcosmicstack-labs · mercury-agentEPSS 0.37%via NVD
CVE-2026-90813Medium· 4.3PoC
1w ago

A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13

A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. The manipulation results in inc…

▾ Twilightcosmicstack-labs · mercury-agentEPSS 0.55%via NVD
CVE-2026-90815Medium· 6.3PoC
1w ago

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the component Convolution Filter. Such manipulation leads to out-o…

▾ TwilightRed Hat · FFmpegEPSS 0.42%via NVD
CVE-2026-73496High· 7.7PoC
1w ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src…

▾ Midnightsooperset · mcp-atlassianEPSS 0.48%via NVD
CVE-2026-90816Medium· 4.3PoC
1w ago

A vulnerability was found in FFmpeg 8.0.x

A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial…

▾ TwilightRed Hat · FFmpegEPSS 0.58%via NVD
CVE-2026-90812Medium· 4.3PoC
1w ago

A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0

A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation…

▾ Twilightcosmicstack-labs · mercury-agentEPSS 0.39%via NVD
CVE-2026-90808Medium· 6.3PoC
1w ago

A vulnerability was determined in HKUDS nanobot up to 0.2.1

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blackli…

▾ TwilightHKUDS · nanobotEPSS 0.41%via NVD
CVE-2026-77884High· 7.1PoC
1w ago

Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network

Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.

▾ MidnightBrain Trust · Gallery - Private Photo VaultEPSS 0.25%via NVD
CVE-2026-90810Medium· 6.3PoC
1w ago

A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13

A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell…

▾ Twilightcosmicstack-labs · mercury-agentEPSS 0.37%via NVD
CVE-2026-90811Low· 3.3PoC
1w ago

A weakness has been identified in cosmicstack-labs mercury-agent up to 1.2.0

A weakness has been identified in cosmicstack-labs mercury-agent up to 1.2.0. This affects the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Permission Manif…

▾ Twilightcosmicstack-labs · mercury-agentEPSS 0.15%via NVD
CVE-2026-91080High· 7.5PoC
1w ago

webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies

webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with inva…

▾ Midnightadnanh · webhookEPSS 0.66%via NVD
CVE-2026-90946High· 7.5PoC
1w ago

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary director…

▾ MidnightAsyncFuncAI · deepwiki-openEPSS 0.51%via NVD
CVE-2026-90945Critical· 9.8PoC
1w ago

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrativ…

▾ Abyssalcrawlab-team · crawlabEPSS 0.77%via NVD
CVE-2026-90944High· 8.2PoC
1w ago

Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox

Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with fo…

▾ Midnightkrayin · laravel-crmEPSS 0.66%via NVD
CVE-2026-90942Critical· 9.6PoC
1w ago

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key…

▾ Abyssalcasdoor · casdoorEPSS 0.28%via NVD
CVE-2026-90807Medium· 6.3PoC
1w ago

A vulnerability was found in nanocoai NanoClaw up to 2.1.17

A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. The manipulation results in link…

▾ Twilightnanocoai · NanoClawEPSS 0.43%via NVD
CVE-2026-70658High· 7.4PoC
1w ago

Pay is a payments engine for Ruby on Rails 6.0 and higher

Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid_signature? in app/controllers/pay/webhooks/paddle_billing_controller.rb compares the computed 64-character SHA-256 H…

▾ Midnightpay-rails · payEPSS 0.58%via NVD
CVE-2026-90805High· 7.3PoC
1w ago

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the argument doc_mail/doc_pswd ca…

▾ Midnightsubhajitkhan · online-clinic-management-systemEPSS 0.43%via NVD
CVE-2026-90804Medium· 4.8PoC
1w ago

A vulnerability was detected in GNU Binutils 2.47

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument…

▾ Twilightgnu · binutilsEPSS 0.20%via NVD
CVE-2026-90803Medium· 5.3PoC
1w ago

A security vulnerability has been detected in GNU Binutils 2.47

A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads …

▾ Twilightgnu · binutilsEPSS 0.20%via NVD
CVE-2026-90802Medium· 4.4PoC
1w ago

A weakness has been identified in GNU Binutils 2.47

A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has b…

▾ Twilightgnu · binutilsEPSS 0.18%via NVD
CVE-2026-90801Medium· 5.3PoC
1w ago

A security flaw has been discovered in GNU Binutils 2.47

A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local…

▾ Twilightgnu · binutilsEPSS 0.21%via NVD
CVE-2026-90796Medium· 6.3PoC
1w ago

A vulnerability was identified in itsourcecode Leave Management System 1.0

A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/company/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated r…

▾ Twilightitsourcecode · Leave Management SystemEPSS 0.33%via NVD
CVE-2026-57579High· 7.5PoC
1w ago

Alchemy is an open source content management system engine written in Ruby on Rails

Alchemy is an open source content management system engine written in Ruby on Rails. Prior to 7.4.15, 8.0.15, 8.1.14, and 8.2.6, the unauthenticated GET /api/pages/nested endpoint implemented by Api::PagesController#nested in app/control…

▾ MidnightAlchemyCMS · alchemy_cmsEPSS 0.65%via NVD
CVE-2026-90795Medium· 4.3PoC
1w ago

A vulnerability was determined in itsourcecode Loan Management System 1.0

A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function of the file navbar.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible…

▾ Twilightitsourcecode · Loan Management SystemEPSS 0.47%via NVD
CVE-2026-90794Medium· 6.3PoC
1w ago

A vulnerability was found in GPAC up to f1219cde

A vulnerability was found in GPAC up to f1219cde. The affected element is the function gf_sg_script_load of the file scenegraph/vrml_tools.c of the component MP4Box. Performing a manipulation results in use after free. It is possible to …

▾ TwilightEPSS 0.51%via NVD
CVE-2026-90793Medium· 5.4PoC
1w ago

A vulnerability has been found in GPAC up to f1219cde

A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack may be performed fro…

▾ TwilightEPSS 0.58%via NVD
CVE-2026-76461Critical· 9.8CISA KEV0dayPoC
1w ago

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …

▾ Hadalcisco · asyncosEPSS 28%via NVD
CVE-2026-90704Medium· 6.6PoC
1w ago

A vulnerability was found in D-Link DWR-M921 1.1.52

A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitatio…

▾ TwilightD-Link · DWR-M921EPSS 2.3%via NVD
CVEs tagged “exploit-available” — page 35 · VulnSea