VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3546 CVEsRSS

CVE-2026-90698Medium· 5.3PoC
1w ago

A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43

A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds…

▾ TwilightRed Hat · memcachedEPSS 0.86%via NVD
CVE-2026-90697Medium· 4.3PoC
1w ago

A vulnerability was identified in SourceCodester Inventory Management System 1.0

A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file invoice.php. The manipulation of the argument ID leads to authorization bypass. It is possible to initiate the att…

▾ TwilightSourceCodester · Inventory Management SystemEPSS 0.41%via NVD
CVE-2026-90695Low· 3.5PoC
1w ago

A vulnerability was found in SourceCodester Inventory Management System 1.0

A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management. Performing a manipulation re…

▾ TwilightSourceCodester · Inventory Management SystemEPSS 0.35%via NVD
CVE-2026-90693Critical· 9.9PoC
1w ago

A flaw has been found in D-Link DIR-878 120B05

A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer overflow. Remote exploitation of the a…

▾ AbyssalD-Link · DIR-878EPSS 0.91%via NVD
CVE-2026-90691High· 8.3PoC
1w ago

A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04

A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is the function FileOperationsManager of the file hexstrike_server.py of the component API Files Endpoi…

▾ Midnight0x4m4 · HexStrike AIEPSS 0.62%via NVD
CVE-2026-90690High· 7.3PoC
1w ago

A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04

A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the component API Tools Endpoint. Executing a m…

▾ Midnight0x4m4 · HexStrike AIEPSS 2.1%via NVD
CVE-2024-23176Medium· 5.4PoC
1w ago

An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2

An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.

▾ TwilightRed Hat · MassMessageEPSS 0.21%via NVD
CVE-2026-90705Medium· 6.6PoC
1w ago

A vulnerability was determined in D-Link DWR-M921 1.1.52

A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command inj…

▾ TwilightD-Link · DWR-M921EPSS 2.3%via NVD
CVE-2026-90699Critical· 9.9PoC
1w ago

A weakness has been identified in D-Link DWR-M920 1.1.7

A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated…

▾ AbyssalD-Link · DWR-M920EPSS 3.3%via NVD
CVE-2026-90694Low· 3.5PoC
1w ago

A vulnerability has been found in SourceCodester Inventory Management System 1.0

A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file /api/customers_handler.php of the component Customer Management Module. Such manipulation of the argument Custo…

▾ TwilightSourceCodester · Inventory Management SystemEPSS 0.35%via NVD
CVE-2026-90898Critical· 9.8PoC
1w ago

Bifrost registers MCP clients through its management API

Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_conf…

▾ Abyssalmaximhq · github.com/maximhq/bifrost/transportsEPSS 0.62%via NVD
CVE-2026-90708High· 7.3PoC
1w ago

A weakness has been identified in Yot CMS up to 3.3.1

A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file global.php of the component Cookie Handler. This manipulation of the argument yot3_user/yot3_pass causes sql injectio…

▾ MidnightYot · CMSEPSS 0.41%via NVD
CVE-2026-90710High· 7.3PoC
1w ago

A vulnerability was determined in taisan tarzan-cms 1.0.0

A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file com/tarzan/cms/modules/admin/service/biz/ThemeService.java of the component Theme Download Function. Executing a manipu…

▾ Midnighttaisan · tarzan-cmsEPSS 0.50%via NVD
CVE-2026-90709Medium· 4.7PoC
1w ago

A security vulnerability has been detected in Yot CMS up to 3.3.1

A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code inje…

▾ TwilightYot · CMSEPSS 0.41%via NVD
CVE-2026-90713Low· 3.3PoC
1w ago

A security flaw has been discovered in vllm-project vLLM up to 0.29.0

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipula…

▾ Twilightvllm-project · vLLMEPSS 0.16%via NVD
CVE-2026-90714Medium· 6.3PoC
1w ago

A weakness has been identified in marcobambini Gravity up to 0.9.7

A weakness has been identified in marcobambini Gravity up to 0.9.7. The impacted element is an unknown function of the file src/utils/gravity_json.c of the component JSON parser. This manipulation causes memory corruption. The attack is …

▾ Twilightmarcobambini · GravityEPSS 0.47%via NVD
CVE-2026-90715High· 7.3PoC
1w ago

A security vulnerability has been detected in marcobambini Gravity up to 0.9.7

A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the file src/utils/gravity_json.c of the component udp json-parser. Such manipulation leads to integer overflow. The atta…

▾ Midnightmarcobambini · GravityEPSS 0.64%via NVD
CVE-2024-58383High· 7.3PoC
1w ago

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. O…

▾ Midnightfroxlor · froxlorEPSS 0.10%via NVD
CVE-2026-90936Medium· 4.3PoC
1w ago

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying a…

▾ Twilightfroxlor · froxlorEPSS 0.31%via NVD
CVE-2026-90932High· 7.2PoC
1w ago

LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling

LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file…

▾ Midnightlaradashboard · laradashboardEPSS 0.82%via NVD
CVE-2026-90931Medium· 5.4PoC
1w ago

LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags

LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags. When any user incl…

▾ Twilightlaradashboard · laradashboardEPSS 0.24%via NVD
CVE-2026-90927Medium· 6.5PoC
1w ago

filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages

filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages. Attackers can send oversized WebSocket messages…

▾ Twilightfilebrowser · filebrowserEPSS 0.44%via NVD
CVE-2026-90716Medium· 5.5PoC
1w ago

A vulnerability was detected in marcobambini Gravity up to 0.9.7

A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of the file src/compiler/gravity_parser.c of the component Number Parser. Performing a manipulation results in out-of-bou…

▾ Twilightmarcobambini · GravityEPSS 0.36%via NVD
CVE-2026-90792Medium· 4.3PoC
1w ago

A flaw has been found in GPAC up to f1219cde

A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation of the argument Target causes null pointer dereferen…

▾ TwilightEPSS 0.69%via NVD
CVE-2026-90681Low· 3.3PoC
1w ago

A weakness has been identified in Matthias-Wandel jhead up to 3.3

A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The expl…

▾ TwilightMatthias-Wandel · jheadEPSS 0.16%via NVD
CVE-2026-90620High· 7.3PoC
1w ago

A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04

A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This manipulation cau…

▾ Midnight0x4m4 · HexStrike AIEPSS 0.65%via NVD
CVE-2026-90609Low· 3.3PoC
1w ago

A vulnerability has been found in GPAC up to f1219cde

A vulnerability has been found in GPAC up to f1219cde. The impacted element is an unknown function of the file scenegraph/vrml_tools.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be p…

▾ TwilightEPSS 0.17%via NVD
CVE-2023-40772Medium· 4.3PoC
1w ago

A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.

A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.

▾ TwilightDataEase · DataEaseEPSS 1.1%via NVD
CVE-2023-37253Low· 3.1PoC
1w ago

An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3

An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.

▾ TwilightMediaWiki · ProofreadPageEPSS 0.24%via NVD
CVE-2026-90791Medium· 6.3PoC
1w ago

A vulnerability was detected in GPAC up to f1219cde

A vulnerability was detected in GPAC up to f1219cde. This vulnerability affects the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack can …

▾ TwilightEPSS 0.51%via NVD
CVEs tagged “exploit-available” — page 37 · VulnSea