VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3546 CVEsRSS

CVE-2026-90517Medium· 5.3PoC
2w ago

A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0

A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack ma…

▾ TwilightPHPGurukul · Bank Locker Management SystemEPSS 0.57%via NVD
CVE-2026-90582Medium· 5.3PoC
2w ago

A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0

A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consum…

▾ Twilightevanchiu · serverless-todoEPSS 0.70%via NVD
CVE-2026-90581Medium· 6.3PoC
2w ago

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote explo…

▾ Twilightcym1102 · nginxWebUIEPSS 0.41%via NVD
CVE-2026-90579High· 7.3PoC
2w ago

A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2

A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing a…

▾ Midnightcheshire-cat-ai · Cheshire Cat AIEPSS 0.65%via NVD
CVE-2026-90578Medium· 5.3PoC
2w ago

A flaw has been found in GPAC up to f1219cde

A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack is restricted to local e…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-90577Medium· 5.3PoC
2w ago

A vulnerability was detected in GPAC up to f1219cde

A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffe…

▾ TwilightEPSS 0.18%via NVD
CVE-2026-90576Low· 3.3PoC
2w ago

A security vulnerability has been detected in GPAC up to f1219cde

A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to null pointer dereference. The…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-90575Low· 3.7PoC
2w ago

A weakness has been identified in PHPGurukul Small CRM 4.0

A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. I…

▾ TwilightPHPGurukul · Small CRMEPSS 0.48%via NVD
CVE-2026-90574Medium· 6.3PoC
2w ago

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/emp_transac.php?action=add. The manipulation of the argument firstname results in sql injection. The …

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-90573Low· 3.3PoC
2w ago

A vulnerability was identified in GPAC up to f1219cde

A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference. Local access is …

▾ TwilightEPSS 0.17%via NVD
CVE-2026-90572Medium· 4.7PoC
2w ago

A vulnerability was determined in davenardella snap7 up to 1.4.3

A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opUpload of the file src/core/s7_micro_client.cpp. Executing a manipulation of the argument DataLen can lead to mem…

▾ Twilightdavenardella · snap7EPSS 0.42%via NVD
CVE-2026-90566High· 7.3PoC
2w ago

A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registratio…

▾ MidnightRizwan17 · inventory-management-systemEPSS 0.47%via NVD
CVE-2026-90565Medium· 5.3PoC
2w ago

A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid resul…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.53%via NVD
CVE-2026-90526High· 7.3PoC
2w ago

A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0

A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Re…

▾ MidnightSourceCodester · School Registration and Fee SystemEPSS 0.43%via NVD
CVE-2026-90525Medium· 6.3PoC
2w ago

A weakness has been identified in itsourcecode Sales and Inventory System 1.0

A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The atta…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2025-64059Low· 1.8PoC
2w ago

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.

▾ Twilightgetgrav · GravEPSS 0.30%via NVD
CVE-2026-90601High· 7.3PoC
2w ago

A vulnerability was found in getzep graphiti up to 0.30.2

A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launche…

▾ Midnightgetzep · graphitiEPSS 0.69%via NVD
CVE-2026-90600Medium· 6.3PoC
2w ago

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated rem…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-90599Medium· 4.3PoC
2w ago

A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2

A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-site request forg…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.24%via NVD
CVE-2026-90598Medium· 6.3PoC
2w ago

A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2

A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipu…

▾ Twilightjaygajera17 · E-commerce-project-springBootEPSS 0.39%via NVD
CVE-2026-90597Medium· 6.3PoC
2w ago

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/sup_edit1.php. Such manipulation of the argument ID leads to sql injection. The att…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-90596Medium· 6.5PoC
2w ago

A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit

A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be c…

▾ TwilightEPSS 0.58%via NVD
CVE-2026-90595Medium· 6.3PoC
2w ago

A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0

A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation res…

▾ Twilightwxiaoqi · Spring-Cloud-PlatformEPSS 0.37%via NVD
CVE-2026-90594Medium· 6.3PoC
2w ago

A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0

A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Servic…

▾ Twilightwxiaoqi · Spring-Cloud-PlatformEPSS 0.37%via NVD
CVE-2026-90584Medium· 5.3PoC
2w ago

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component Fragmentation Handler. Executing a manipulation c…

▾ TwilightTooTallNate · Java-WebSocketEPSS 0.72%via NVD
CVE-2026-90583Medium· 4.3PoC
2w ago

A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf

A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulatio…

▾ Twilightkagisearch · smallwebEPSS 0.49%via NVD
CVE-2026-37008High· 8.1PoC
2w ago

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's co…

▾ MidnightCrewAI · CrewAIEPSS 0.16%via NVD
CVE-2026-35867Low· 3.1PoC
2w ago

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able …

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able …

▾ TwilightLB-LINK · AC1900 firmwareEPSS 1.0%via NVD
CVE-2026-81648Critical· 10.0PoC
2w ago

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on …

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on …

▾ AbyssalEPSS 0.50%via NVD
CVE-2026-90580Medium· 6.3PoC
2w ago

A vulnerability was found in FlowiseAI Flowise up to 3.0.2

A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of th…

▾ Twilightflowiseai · flowiseEPSS 0.41%via NVD
CVEs tagged “exploit-available” — page 41 · VulnSea