VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3547 CVEsRSS

CVE-2026-89265Medium· 4.3PoC
2w ago

MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint

MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office …

▾ Twilightmoxi624 · MoguBlogEPSS 0.37%via CVEORG
CVE-2026-89260High· 7.5PoC
2w ago

MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback Endpoint

MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an u…

▾ Midnightmoxi624 · MoguBlogEPSS 0.73%via CVEORG
CVE-2026-54165Medium· 6.4PoC
2w ago

Dobase is an open-source, self-hosted workspace with installable tools

Dobase is an open-source, self-hosted workspace with installable tools. Versions prior to 2026.06.03 have a one-click stored DOM-based cross-site scripting (XSS) vulnerability in the public, unauthenticated shared-folder image gallery. A…

▾ Twilightsmgdkngt · dobaseEPSS 0.55%via NVD
CVE-2026-90460High· 7.6PoC
2w ago

An issue was discovered in OpenStack Keystone before 29.0.3

An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or d…

▾ MidnightOpenStack · KeystoneEPSS 0.55%via NVD
CVE-2026-54258Medium· 6.5PoC
2w ago

ZoneMinder is a free, open source closed-circuit television software application

ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to …

▾ TwilightZoneMinder · zoneminderEPSS 0.34%via NVD
CVE-2026-72708High· 7.5PoC
2w ago

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word charact…

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word charact…

▾ MidnightSPIP · SPIPEPSS 0.52%via NVD
CVE-2026-89245Medium· 6.5PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks. Attackers can cra…

▾ TwilightWWBN · AVideoEPSS 0.17%via NVD
CVE-2026-68497High· 7.5PoC
2w ago

jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLD…

jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLD…

▾ MidnightFasterXML · com.fasterxml.jackson.core:jackson-databindEPSS 0.58%via NVD
CVE-2026-89243High· 8.1PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input. Administrators with canAdminUserGroups permi…

▾ MidnightWWBN · AVideoEPSS 0.38%via NVD
CVE-2026-89262High· 7.5PoC
2w ago

MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary commen…

▾ Midnightmoxi624 · MoguBlogEPSS 0.54%via CVEORG
CVE-2026-89251Medium· 6.5PoC
2w ago

AVideo Missing Authorization via AD_Server log.php Wallet Credit

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign vid…

▾ TwilightWWBN · AVideoEPSS 0.18%via CVEORG
CVE-2026-89246Medium· 5.4PoC
2w ago

WWBN AVideo CSV Formula Injection via myComments.download.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection vulnerability in the myComments.download.php endpoint that fails to sanitize spreadsheet formula prefixes in comment text. Authenticated…

▾ TwilightWWBN · AVideoEPSS 0.24%via CVEORG
CVE-2026-89013High· 7.5PoC
2w ago

Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value

Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can…

▾ MidnightDolibarr · DolibarrEPSS 0.50%via NVD
CVE-2026-79396Critical· 9.8PoC
2w ago

Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowi…

Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowi…

▾ AbyssalEPSS 0.58%via NVD
CVE-2026-89261Medium· 6.5PoC
2w ago

MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints

MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints t…

▾ Twilightmoxi624 · MoguBlogEPSS 0.83%via CVEORG
CVE-2026-89241Medium· 6.1PoC
2w ago

WWBN AVideo Reflected XSS via confirmLivePassword.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copies REQUEST_URI into a form action attribute without encoding. Attackers can c…

▾ TwilightWWBN · AVideoEPSS 0.26%via CVEORG
CVE-2026-89012Medium· 6.5PoC
2w ago

Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denyl…

Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denyl…

▾ TwilightDolibarr · DolibarrEPSS 0.46%via NVD
CVE-2026-81861Medium· 5.9PoC
2w ago

CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.

CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.

▾ TwilightSchneider Electric · SCADAPack 47xEPSS 0.54%via NVD
CVE-2026-89252Medium· 6.5PoC
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links. A canStream user can overwrite another user's…

▾ TwilightWWBN · AVideoEPSS 0.31%via NVD
CVE-2026-89256High· 8.7PoC
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML. A video…

▾ MidnightWWBN · AVideoEPSS 0.37%via NVD
CVE-2026-72709Critical· 9.8PoC
2w ago

SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any serve…

SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any serve…

▾ AbyssalSPIP · SPIPEPSS 0.66%via NVD
CVE-2026-89010Critical· 9.8PoC
2w ago

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to …

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to …

▾ AbyssalWAVLINK Technology · WN535M1EPSS 3.2%via NVD
CVE-2026-89257Medium· 5.4PoC
2w ago

AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php

AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php. The endpoint validates only the Category::canCreateCategory() capability and a CSRF nonce before passing the …

▾ TwilightWWBN · AVideoEPSS 0.30%via NVD
CVE-2026-89250High· 7.5PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory. Attackers can reque…

▾ MidnightWWBN · AVideoEPSS 0.50%via NVD
CVE-2026-89240Medium· 6.1PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php. The script interpolates the unauthenticated GET parameter u (which is not…

▾ TwilightWWBN · AVideoEPSS 0.31%via NVD
CVE-2026-77159Medium· 5.5PoC
2w ago

A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function

A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can…

▾ TwilightRed Hat · libvirtEPSS 0.16%via NVD
CVE-2026-71416High· 8.8PoC
2w ago

Headroom compresses data before the data reaches a large language model

Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to …

▾ Midnightheadroomlabs-ai · headroomEPSS 0.22%via NVD
CVE-2026-89147High· 7.5PoC
2w ago

Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections

Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client can conn…

▾ Midnightnet-snmp · Net-SNMPEPSS 0.49%via NVD
CVE-2026-89264Medium· 4.3PoC
2w ago

MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user

MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the re…

▾ Twilightmoxi624 · MoguBlogEPSS 0.37%via NVD
CVE-2026-89263Medium· 5.3PoC
2w ago

MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users

MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote callers can modify the startEmailNotif…

▾ Twilightmoxi624 · MoguBlogEPSS 0.45%via NVD
CVEs tagged “exploit-available” — page 43 · VulnSea