VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3545 CVEsRSS

CVE-2026-57124Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and args values that PraisonAIUI passes to Stdi…

▾ AbyssalMervinPraison · PraisonAIEPSS 1.0%via NVD
CVE-2026-57119High· 7.5PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without a workspace allowlist or boundary che…

▾ MidnightMervinPraison · PraisonAIEPSS 0.53%via NVD
CVE-2026-57127Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests when PRAISONAI_API_KE…

▾ AbyssalMervinPraison · PraisonAIEPSS 0.90%via NVD
CVE-2026-56839High· 7.3PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy w…

▾ MidnightMervinPraison · PraisonAIEPSS 0.38%via NVD
CVE-2026-57131Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker…

▾ AbyssalMervinPraison · PraisonAIEPSS 0.97%via NVD
CVE-2026-57130High· 8.1PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteri…

▾ MidnightMervinPraison · praisonaiagentsEPSS 0.46%via NVD
CVE-2026-57132High· 8.2PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERVER_TOKEN authentication. Deployments that use the applica…

▾ MidnightMervinPraison · PraisonAIEPSS 0.51%via NVD
CVE-2026-57125Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-…

▾ AbyssalMervinPraison · PraisonAIEPSS 0.60%via NVD
CVE-2026-57128Medium· 4.3PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/praisonai-agents/praisonaiagents/server/server.py does not consult ServerConfig.auth_token before handling /publish, /events, or /info reques…

▾ TwilightMervinPraison · PraisonAIEPSS 0.25%via NVD
CVE-2026-57129High· 7.5PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(file_path) without traversal, symlink, o…

▾ MidnightMervinPraison · praisonaiagentsEPSS 0.53%via NVD
CVE-2026-53496Medium· 5.3PoC
1w ago

ExifReader is a JavaScript Exif information parser

ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the ISO-BMFF parser in src/image-header-iso-bmff.js, where f…

▾ Twilightmattiasw · ExifReaderEPSS 0.51%via NVD
CVE-2026-54567High· 7.5PoC
1w ago

Flask-Reuploaded provides file uploads for Flask

Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension hel…

▾ Midnightjugmac00 · flask-reuploadedEPSS 0.63%via NVD
CVE-2026-54628High· 8.6PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without …

▾ Midnightjulien040 · anyqueryEPSS 0.60%via NVD
CVE-2026-50006Critical· 9.1PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacke…

▾ Abyssaljulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-47253High· 7.3PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll wi…

▾ Midnightjulien040 · anyqueryEPSS 0.44%via NVD
CVE-2026-55832Medium· 6.1PoC
1w ago

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location from an ONNX model through onnx/src/tens…

▾ Twilightsonos · tractEPSS 0.19%via NVD
CVE-2026-55837Medium· 6.8PoC
1w ago

dbt-mcp is a Model Context Protocol server for interacting with dbt

dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication or Host validation after a user com…

▾ Twilightdbt-labs · dbt-mcpEPSS 0.27%via NVD
CVE-2026-55846Medium· 6.2PoC
1w ago

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve and allure open uses URI.getPath() in Commands.setUpServer() in allure-commandline/src/ma…

▾ Twilightallure-framework · allure2EPSS 0.18%via NVD
CVE-2026-47256Medium· 5.3PoC
1w ago

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter r…

▾ Twilightopen-telemetry · opentelemetry-collector-contribEPSS 0.44%via NVD
CVE-2026-55093Medium· 6.1PoC
1w ago

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1, tract-nnef uses unchecked usize multiplication in nnef/src/tensors.rs read_tensor for attacker-controlled tensor di…

▾ Twilightsonos · tractEPSS 0.18%via NVD
CVE-2026-90498High· 7.3PoC
2w ago

A vulnerability was identified in lenve vhr 1.0-SNAPSHOT

A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. Remote exploitation of the attack is possible. The …

▾ Midnightlenve · vhrEPSS 0.47%via NVD
CVE-2026-90497Low· 3.5PoC
2w ago

A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11

A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the function getTitle of the file application/views/task/add_task.php of the component Task Title Output. Executing a manipulati…

▾ TwilightFengoffice · Feng OfficeEPSS 0.33%via NVD
CVE-2026-90496Medium· 4.7PoC
2w ago

A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11

A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handle…

▾ TwilightFengoffice · Feng OfficeEPSS 0.33%via NVD
CVE-2026-90495High· 7.3PoC
2w ago

A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11

A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class.php of the component Legacy API. Such manipulation of th…

▾ MidnightFengoffice · Feng OfficeEPSS 0.41%via NVD
CVE-2026-90493High· 8.8PoC
2w ago

A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows

A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper acces…

▾ MidnightTonec · Internet Download ManagerEPSS 0.15%via NVD
CVE-2026-90491Medium· 6.3PoC
2w ago

A weakness has been identified in sanjevirau gsubs up to 1.0.3

A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the file renderer/index.js of the component Electron. Executing a manipulation of the argument filename can lead to code inj…

▾ Twilightsanjevirau · gsubsEPSS 0.42%via NVD
CVE-2026-90490Medium· 6.3PoC
2w ago

A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT

A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deserialization. The attack is possible to be carried out remot…

▾ Twilightlenve · vhrEPSS 0.41%via NVD
CVE-2026-90489Low· 3.5PoC
2w ago

A vulnerability was identified in Xuxueli xxl-job up to 3.5.0

A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobinfo/insert. Such manipulation of the argument name/author leads to cross site scripting. The attack can be executed r…

▾ TwilightXuxueli · xxl-jobEPSS 0.33%via NVD
CVE-2026-90488Medium· 6.3PoC
2w ago

A vulnerability was determined in Xuxueli xxl-job up to 3.4.2

A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection.…

▾ TwilightXuxueli · xxl-jobEPSS 0.39%via NVD
CVE-2026-90509High· 7.3PoC
2w ago

A weakness has been identified in dromara orion-visor up to 2.5.7

A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The …

▾ Midnightdromara · orion-visorEPSS 0.50%via NVD
CVEs tagged “exploit-available” — page 39 · VulnSea