VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3545 CVEsRSS

CVE-2026-90789High· 7.3PoC
1w ago

A weakness has been identified in itsourcecode Leave Management System 1.0

A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Executing a manipulation of the argument user_email can lead to sql injection. The a…

▾ Midnightitsourcecode · Leave Management SystemEPSS 0.43%via NVD
CVE-2026-82019Medium· 4.2PoC
1w ago

TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a publisher's domain by sending crafted postMessage paylo…

TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a publisher's domain by sending crafted postMessage paylo…

▾ TwilightTripleLift · video-bundle.jsEPSS 0.29%via NVD
CVE-2026-90941Medium· 4.3PoC
1w ago

novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters

novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters. Attackers can supply a bookI…

▾ Twilight201206030 · novel-plusEPSS 0.41%via NVD
CVE-2026-90940Medium· 5.3PoC
1w ago

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL …

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL …

▾ Twilight201206030 · novel-plusEPSS 0.55%via NVD
CVE-2026-90939Medium· 6.5PoC
1w ago

novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations

novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retrieve password hashes and personal data including email add…

▾ Twilight201206030 · novel-plusEPSS 0.46%via NVD
CVE-2026-90788Medium· 4.7PoC
1w ago

A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055

A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown functionality of the file /admin1.php/admin/template/index/path/.%40template%40default%40html%40label.html of the com…

▾ Twilightmagicblack · MacCMS10EPSS 2.2%via NVD
CVE-2026-90787High· 7.3PoC
1w ago

A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e

A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow.…

▾ MidnightSoarkey · StudentManagementEPSS 0.54%via NVD
CVE-2026-90786Medium· 5.3PoC
1w ago

A vulnerability was determined in Dvidelabs flatcc up to 0.6.3

A vulnerability was determined in Dvidelabs flatcc up to 0.6.3. This impacts the function align_order_members of the file src/compiler/semantics.c of the component Duplicate Symbol Handler. This manipulation causes reachable assertion. T…

▾ TwilightDvidelabs · flatccEPSS 0.72%via NVD
CVE-2026-90785Medium· 5.3PoC
1w ago

A vulnerability was found in Dvidelabs flatcc up to 0.6.3

A vulnerability was found in Dvidelabs flatcc up to 0.6.3. This affects the function analyze_struct of the file src/compiler/semantics.c of the component Struct Analysis. The manipulation results in reachable assertion. It is possible to…

▾ TwilightDvidelabs · flatccEPSS 0.72%via NVD
CVE-2026-90938High· 8.6PoC
1w ago

LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin/ws) whose authentication is gated on plugin_debug_key, which defaults to an empty string and is never set by th…

LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin/ws) whose authentication is gated on plugin_debug_key, which defaults to an empty string and is never set by th…

▾ Midnightlangbot-app · LangBotEPSS 0.57%via NVD
CVE-2026-90935Medium· 4.3PoC
1w ago

Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command

Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on for…

▾ Twilightfroxlor · froxlorEPSS 0.29%via NVD
CVE-2026-90933High· 7.1PoC
1w ago

laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys

laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys. Attackers with low-privileged ac…

▾ Midnightlaradashboard · laradashboardEPSS 0.30%via NVD
CVE-2026-90930Medium· 6.8PoC
1w ago

File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules

File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules. Attackers can read and overwrite rule-de…

▾ Twilightfilebrowser · filebrowserEPSS 0.50%via NVD
CVE-2026-90928Medium· 6.5PoC
1w ago

File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits

File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request co…

▾ Twilightfilebrowser · filebrowserEPSS 0.44%via NVD
CVE-2026-90919Critical· 9.8PoC
1w ago

LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads()

LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Confi…

▾ AbyssalModelTC · LightLLMEPSS 1.1%via NVD
CVE-2026-90784Medium· 5.3PoC
1w ago

A vulnerability has been found in Dvidelabs flatcc up to 0.6.3

A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted element is the function fb_clear_parser of the file src/Compiler/semantics.c. The manipulation leads to memory leak. It is possible to initiate the attack remot…

▾ TwilightDvidelabs · flatccEPSS 0.72%via NVD
CVE-2026-90712Medium· 4.3PoC
1w ago

A vulnerability was identified in Gitlawb openclaude up to 0.30.0

A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file src/services/api/xaiOAuthCallback.ts of the component xAI OAuth Callback Handler. The manipulation of the argument Er…

▾ TwilightGitlawb · openclaudeEPSS 0.56%via NVD
CVE-2026-90706Medium· 6.6PoC
1w ago

A vulnerability was identified in D-Link DWR-M921 1.1.52

A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc. The manipulation of the argument targetAPSsid leads to os command injection. The attack is possible to be carried ou…

▾ TwilightD-Link · DWR-M921EPSS 2.3%via NVD
CVE-2026-90701High· 7.3PoC
1w ago

A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578

A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. The affected element is an unknown function of the file listdoctor.php. Performing a manipulation of the argumen…

▾ Midnightsubhajitkhan · online-clinic-management-systemEPSS 0.43%via NVD
CVE-2026-90696Low· 3.5PoC
1w ago

A vulnerability was determined in SourceCodester Inventory Management System 1.0

A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /api/products_handler.php of the component Product Management Module. Executing a manipula…

▾ TwilightSourceCodester · Inventory Management SystemEPSS 0.35%via NVD
CVE-2026-90686Medium· 5.3PoC
1w ago

A vulnerability was found in GPAC up to f1219cde

A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remot…

▾ TwilightEPSS 0.86%via NVD
CVE-2026-55073Medium· 6.2PoC
1w ago

WeasyPrint helps web developers to create PDF documents

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed through t…

▾ TwilightKozea · WeasyPrintEPSS 0.22%via NVD
CVE-2026-61534Critical· 9.1PoC
1w ago

Yayson is a library for serializing and reading JSON API data in JavaScript

Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use attacker-controlled JSON:API type, id, and relationship names as keys in plain-object lookup tables in src/yayson/stor…

▾ Abyssalyayson · yaysonEPSS 0.84%via NVD
CVE-2025-24890Medium· 6.8PoC
1w ago

gitoxide is an implementation of git written in Rust

gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered e…

▾ TwilightGitoxideLabs · gitoxideEPSS 0.19%via NVD
CVE-2026-55451High· 8.3PoC
1w ago

gettext-converter provides gettext resource conversion utilities for JavaScript

gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2i18next.js splits nested translation keys using options.keyseparator, whose default value consists of two number sign…

▾ Midnightlocize · gettext-converterEPSS 0.57%via NVD
CVE-2026-55244Medium· 5.0PoC
1w ago

ASTEVAL is an evaluator of Python expressions and statements

ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes BaseException, SystemExit, KeyboardInterrupt, and GeneratorExit to expressions evaluated by asteval.Interpreter.eval(), …

▾ Twilightlmfit · astevalEPSS 0.18%via NVD
CVE-2026-53708Medium· 6.6PoC
1w ago

ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs

ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call site in mcpgateway/admin.py calls valid…

▾ TwilightIBM · mcp-context-forgeEPSS 0.35%via NVD
CVE-2026-55072High· 8.5PoC
1w ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/Dat…

▾ Midnightpimcore · pimcoreEPSS 0.41%via NVD
CVE-2026-57126High· 8.5PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extr…

▾ MidnightMervinPraison · PraisonAIEPSS 0.38%via NVD
CVE-2026-57120Medium· 6.5PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime assembly of blocklisted dunder names and allows str.format or str.format_map to resolve dotted fields through C-level att…

▾ TwilightMervinPraison · praisonaiagentsEPSS 0.56%via NVD
CVEs tagged “exploit-available” — page 38 · VulnSea