VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3546 CVEsRSS

CVE-2026-90504High· 7.3PoC
2w ago

A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46

A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The a…

▾ Midnightvvbbnn00 · WARP-Clash-APIEPSS 0.65%via NVD
CVE-2026-90502Low· 3.5PoC
2w ago

A vulnerability was detected in stilleshan ServerStatus 1.0/2.0

A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/main.cpp of the component Stats Generation. Performing a manipulation of the argument custom results in cross site sc…

▾ Twilightstilleshan · ServerStatusEPSS 0.33%via NVD
CVE-2026-90501Medium· 6.3PoC
2w ago

A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT

A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. …

▾ Twilightlenve · vhrEPSS 0.35%via NVD
CVE-2026-90500Medium· 6.3PoC
2w ago

A weakness has been identified in lenve vhr 1.0-SNAPSHOT

A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upl…

▾ Twilightlenve · vhrEPSS 0.35%via NVD
CVE-2026-90499Medium· 5.4PoC
2w ago

A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT

A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of the file /hr/pass of the component Password Update Handler. The manipulation of the argument hrid results in improper…

▾ Twilightlenve · vhrEPSS 0.38%via NVD
CVE-2026-90774High· 7.5PoC
2w ago

rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks

rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header …

▾ Midnightorhun · rustypasteEPSS 0.56%via NVD
CVE-2026-90772High· 7.6PoC
2w ago

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerro…

▾ Midnightamundsen-io · amundsen-frontendEPSS 0.36%via NVD
CVE-2026-90771Low· 3.7PoC⚖ disputed
2w ago

joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code

joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the retur…

▾ Twilighthapijs · joiEPSS 0.39%via NVD
CVE-2026-90769High· 7.7PoC
2w ago

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata,…

▾ Midnightlfnovo · open-notebookEPSS 0.41%via NVD
CVE-2026-90767Medium· 6.5PoC
2w ago

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with opti…

▾ Twilightfroxlor · FroxlorEPSS 0.43%via NVD
CVE-2026-90562High· 8.1PoC
2w ago

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace t…

▾ Midnightlangbot-app · LangBotEPSS 0.73%via NVD
CVE-2026-90516High· 7.3PoC
2w ago

A vulnerability was found in SourceCodester School Registration and Fee System 1.0

A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql inj…

▾ MidnightSourceCodester · School Registration and Fee SystemEPSS 0.43%via NVD
CVE-2026-90515High· 7.3PoC
2w ago

A vulnerability was determined in SourceCodester School Registration and Fee System 1.0

A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead …

▾ MidnightSourceCodester · School Registration and Fee SystemEPSS 0.43%via NVD
CVE-2026-90514High· 7.3PoC
2w ago

A vulnerability has been found in SourceCodester School Registration and Fee System 1.0

A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. It is poss…

▾ MidnightSourceCodester · School Registration and Fee SystemEPSS 0.43%via NVD
CVE-2026-90511Medium· 6.3PoC
2w ago

A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea

A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface…

▾ TwilightGongShengyue · OnlineBooksEPSS 0.32%via NVD
CVE-2026-90510High· 8.3PoC
2w ago

A security vulnerability has been detected in dromara orion-visor up to 2.5.7

A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/jav…

▾ Midnightdromara · orion-visorEPSS 0.50%via NVD
CVE-2026-90508Low· 3.4PoC
2w ago

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Pe…

▾ TwilightChengdu Qilu Technology · LudashiEPSS 0.16%via NVD
CVE-2026-90507Medium· 6.3PoC
2w ago

A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46

A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such ma…

▾ Twilightvvbbnn00 · WARP-Clash-APIEPSS 0.38%via NVD
CVE-2026-90506Medium· 5.0PoC
2w ago

A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46

A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts an unknown function of the component Save Account Job. This manipulation causes race condition. The attack may be init…

▾ Twilightvvbbnn00 · WARP-Clash-APIEPSS 0.25%via NVD
CVE-2026-90505Medium· 5.0PoC
2w ago

A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46

A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the function doUpdateLicenseKey. The manipulation results in race condition. The attack can be launched remotely. The attac…

▾ Twilightvvbbnn00 · WARP-Clash-APIEPSS 0.25%via NVD
CVE-2026-90782Medium· 5.3PoC
2w ago

S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificati…

S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificati…

▾ TwilightSysterel · S2OPCEPSS 0.57%via NVD
CVE-2026-90781Medium· 4.4PoC
2w ago

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long cont…

▾ TwilightALSA Project · alsa-libEPSS 0.17%via NVD
CVE-2026-90777High· 8.8PoC
2w ago

ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files

ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code dur…

▾ Midnightespnet · espnetEPSS 0.73%via NVD
CVE-2026-90776High· 7.5PoC
2w ago

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separ…

▾ Midnightnodemailer · nodemailerEPSS 0.68%via NVD
CVE-2026-90524High· 7.3PoC
2w ago

A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09

A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation resul…

▾ Midnightjaychouchannel · Tourism-Management-SystemEPSS 0.69%via NVD
CVE-2026-90523High· 7.3PoC
2w ago

A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09

A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java o…

▾ Midnightjaychouchannel · Tourism-Management-SystemEPSS 0.50%via NVD
CVE-2026-90522High· 7.3PoC
2w ago

A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d

A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manip…

▾ Midnightjaychouchannel · Tourism-Management-SystemEPSS 0.50%via NVD
CVE-2026-90521Medium· 6.3PoC
2w ago

A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132

A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipul…

▾ Twilightjaychouchannel · Tourism-Management-SystemEPSS 0.39%via NVD
CVE-2026-90520Medium· 6.3PoC
2w ago

A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64

A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization I…

▾ Twilightjaychouchannel · Tourism-Management-SystemEPSS 0.37%via NVD
CVE-2026-90519Medium· 6.3PoC
2w ago

A weakness has been identified in PHPGurukul Bank Locker Management System 1.0

A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remo…

▾ TwilightPHPGurukul · Bank Locker Management SystemEPSS 0.37%via NVD
CVEs tagged “exploit-available” — page 40 · VulnSea