VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3546 CVEsRSS

CVE-2026-90703Critical· 9.1PoC
1w ago

A vulnerability has been found in D-Link DWR-M921 1.1.52

A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be …

▾ AbyssalD-Link · DWR-M921EPSS 3.6%via NVD
CVE-2026-90608Critical· 9.9PoC
1w ago

A flaw has been found in Totolink A3002MU Hh-B20211125.1046

A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It i…

▾ AbyssalTotolink · A3002MUEPSS 0.85%via NVD
CVE-2026-90606Critical· 9.9PoC
1w ago

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to…

▾ AbyssalTotolink · A3002MUEPSS 0.85%via NVD
CVE-2026-90605Critical· 9.9PoC
1w ago

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to bu…

▾ AbyssalTotolink · A3002MUEPSS 0.85%via NVD
CVE-2026-90604Low· 3.5PoC
1w ago

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is …

▾ TwilightTotolink · A3002MUEPSS 0.35%via NVD
CVE-2026-90623Low· 3.7PoC
1w ago

A weakness has been identified in andreashappe cochise up to 0.4.1

A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/ssh_connection.py of the component SSH Host Key Handler. Executing a manipulation can lead to improper …

▾ Twilightandreashappe · cochiseEPSS 0.28%via NVD
CVE-2026-90621Medium· 6.3PoC
1w ago

A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0

A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the file src/hackingBuddyGPT/extensions/ssh_run_command.py. Such manipulation leads to os command injection. The attack c…

▾ Twilightipa-lab · HackingBuddyGPTEPSS 1.8%via NVD
CVE-2026-90618High· 7.3PoC
1w ago

A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2

A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. Executing a manipu…

▾ MidnightGH05TCREW · PentestAgentEPSS 2.1%via NVD
CVE-2026-90617High· 7.3PoC
1w ago

A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2

A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerability affects the function run_task of the file interface/main.py of the component MCP HTTP Server. Performing a manipula…

▾ MidnightGH05TCREW · PentestAgentEPSS 2.1%via NVD
CVE-2026-90615Medium· 4.3PoC
1w ago

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The atta…

▾ TwilightSourceCodester · Class and Exam Timetabling SystemEPSS 0.47%via NVD
CVE-2026-90613Low· 3.3PoC
1w ago

A security flaw has been discovered in GPAC up to f1219cde

A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the component MP4Box. The manipulation results in reachable assertion. The…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-90612Low· 3.3PoC
1w ago

A vulnerability was identified in GPAC up to f1219cde

A vulnerability was identified in GPAC up to f1219cde. Affected is the function gf_sm_dump_command_list of the file scene_manager/scene_dump.c of the component MP4Box. The manipulation leads to reachable assertion. The attack must be car…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-90611Low· 3.3PoC
1w ago

A vulnerability was determined in GPAC up to f1219cde

A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_manager/loader_xmt.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. The attack is re…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-90610Low· 3.3PoC
1w ago

A vulnerability was found in GPAC up to f1219cde

A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-90607Critical· 9.9PoC
1w ago

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow…

▾ AbyssalTotolink · A3002MUEPSS 0.85%via NVD
CVE-2026-38924Low· 2.9PoC
1w ago

In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0

In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was a "potential security hazard" but the Serena documentation, at the time of the issue report prop…

▾ TwilightOraios AI · SerenaEPSS 0.16%via NVD
CVE-2026-31278High· 7.7PoC
1w ago

An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET re…

An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET re…

▾ Midnightsupremainc · BioStar 2EPSS 0.28%via NVD
CVE-2025-68624Medium· 4.3PoC
1w ago

N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants

N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants. When connecting to the SMTP TCP port and…

▾ TwilightN-able · Mail AssureEPSS 0.33%via NVD
CVE-2025-64031Low· 2.5PoC⚖ disputed
1w ago

libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9

libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar.…

▾ Twilightlibarchive · libarchiveEPSS 0.18%via NVD
CVE-2025-63842Medium· 5.4PoC
1w ago

A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in the multiple-choice…

A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in the multiple-choice…

▾ TwilightRepetico · web backendEPSS 0.23%via NVD
CVE-2026-90685Low· 2.8PoC
1w ago

A vulnerability has been found in GPAC up to f1219cde

A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is requi…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-90684Low· 2.8PoC
1w ago

A flaw has been found in GPAC up to f1219cde

A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable asserti…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-90683Low· 3.3PoC
1w ago

A vulnerability was detected in GPAC up to f1219cde

A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locall…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-90682Medium· 5.3PoC
1w ago

A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3

A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG …

▾ TwilightMatthias-Wandel · jheadEPSS 0.17%via NVD
CVE-2026-90622Low· 3.3PoC
1w ago

A security flaw has been discovered in GNU libredwg 0.13.4

A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec of the component Layer Encoding. Performing a manipulation results in null pointer dereference. The attack needs to …

▾ TwilightGNU · libredwgEPSS 0.17%via NVD
CVE-2023-37252Low· 3.1PoC
1w ago

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.

▾ TwilightMediaWiki · CheckUserEPSS 0.24%via NVD
CVE-2026-90688Medium· 6.5PoC
1w ago

A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC

A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. This issue affects the function formIPMacBindAdd of the component HTTP Handler. Such manipulation of the argument IPMacBindRule leads to stack-based buffer overf…

▾ TwilightTenda · W20EEPSS 0.71%via NVD
CVE-2026-90687Medium· 6.3PoC
1w ago

A vulnerability was determined in GPAC up to f1219cde

A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is poss…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-90702Critical· 9.1PoC
1w ago

A flaw has been found in D-Link DWR-M921 1.1.52

A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The explo…

▾ AbyssalD-Link · DWR-M921EPSS 3.6%via NVD
CVE-2026-90700Medium· 6.3PoC
1w ago

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_edit1.php. Such manipulation of the argument prodcode leads to sql injection. The attack ca…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVEs tagged “exploit-available” — page 36 · VulnSea