VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-89009Critical· 9.1PoC
2w ago

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to th…

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to th…

▾ AbyssalWAVLINK Technology · WN535M1EPSS 1.0%via NVD
CVE-2026-89255High· 8.7PoC
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated att…

▾ MidnightWWBN · AVideoEPSS 0.37%via NVD
CVE-2026-89253High· 8.7PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/user.php) stores the value and save() val…

▾ MidnightWWBN · AVideoEPSS 0.37%via NVD
CVE-2026-89248Medium· 5.3PoC
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php. When the WebRTC plugin is present, any unauthenticated remote user can request /plugin/WebR…

▾ TwilightWWBN · AVideoEPSS 0.50%via NVD
CVE-2026-89247Medium· 6.1PoC
2w ago

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled. The script e…

▾ TwilightWWBN · AVideoEPSS 0.36%via NVD
CVE-2026-89242High· 7.2PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation. Unauthenticated …

▾ MidnightWWBN · AVideoEPSS 0.28%via NVD
CVE-2026-89148Medium· 5.4PoC
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Because the endpoint is not a *.json.php script, AVideo's automatic CSRF guard (autoCSRFGuard()/forbidIfIsUntrustedRequ…

▾ TwilightWWBN · AVideoEPSS 0.16%via NVD
CVE-2026-86793Critical· 9.8PoC
2w ago

SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling…

SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling…

▾ AbyssalSGLang · SGLangEPSS 0.77%via NVD
CVE-2026-89160Low· 3.7PoC
2w ago

PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.

PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.

▾ Twilightpcre · pcre2EPSS 0.27%via NVD
CVE-2026-89157Medium· 5.7PoC
2w ago

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.

▾ Twilightpcre · pcre2EPSS 0.28%via NVD
CVE-2026-50018Medium· 6.5PoC
2w ago

Hoverfly is an open source API simulation tool

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP con…

▾ TwilightSpectoLabs · hoverflyEPSS 0.54%via NVD
CVE-2026-54072Critical· 9.3PoC
2w ago

Authorizer is an open-source, self-hostable authentication and authorization server

Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` …

▾ Abyssalauthorizerdev · authorizerEPSS 0.46%via NVD
CVE-2026-49865Medium· 5.3PoC
2w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is lat…

▾ Twilightkimai · kimaiEPSS 0.35%via NVD
CVE-2026-88053High· 7.8PoC
2w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadIntTemplates in src/classify/intproto.cpp reads NumClassPruners, NumClasses, and NumProtoSets from the TESSDATA_INTTEMP component of a crafted .trainedda…

▾ Midnighttesseract-ocr · tesseract_ocrEPSS 0.18%via NVD
CVE-2026-88018Critical· 9.8PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any …

▾ Abyssalrclone · rcloneEPSS 0.75%via NVD
CVE-2026-89086Critical· 9.1PoC
2w ago

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

▾ AbyssalOCaml · joseEPSS 0.28%via NVD
CVE-2026-0303Low· 2.4PoC
2w ago

A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

▾ TwilightPalo Alto Networks · Checkov by Prisma CloudEPSS 0.19%via NVD
CVE-2026-88872High· 7.1PoC
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sendin…

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sendin…

▾ MidnightWWBN · AVideoEPSS 0.19%via NVD
CVE-2026-88054Medium· 5.5PoC
2w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL, or NT_REVERSED laye…

▾ Twilighttesseract-ocr · tesseract_ocrEPSS 0.15%via NVD
CVE-2026-88899Critical· 9.8PoC
2w ago

knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header

knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project roo…

▾ Abyssalknowns-dev · knownsEPSS 0.81%via CVEORG
CVE-2026-88062Critical· 9.5PoC
2w ago

OmniRoute ACP Custom-Agent Remote Code Execution (RCE)

OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand v…

▾ Abyssaldiegosouzapw · OmniRouteEPSS 1.4%via CVEORG
CVE-2026-88924High· 7.0PoC
2w ago

Gvfs: gvfs-admin socket ownership race permits local root

A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory…

▾ MidnightGNOME · gvfsEPSS 0.11%via CVEORG
CVE-2026-88871Medium· 4.3PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint. The script …

▾ TwilightWWBN · AVideoEPSS 0.18%via NVD
CVE-2026-88044Critical· 9.1PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 const…

▾ Abyssalrclone · rcloneEPSS 0.56%via NVD
CVE-2026-88015Medium· 5.3PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.De…

▾ Twilightrclone · rcloneEPSS 0.51%via NVD
CVE-2026-88013Low· 3.7PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in backen…

▾ Twilightrclone · rcloneEPSS 0.19%via NVD
CVE-2026-88045High· 7.5PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentL…

▾ Midnightrclone · rcloneEPSS 0.63%via NVD
CVE-2025-57231High· 7.5PoC
2w ago

Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local files via a POST Request in a public url.

Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local files via a POST Request in a public url.

▾ MidnightEPSS 1.8%via NVD
CVE-2026-88938Medium· 6.5PoC
2w ago

knowns through 0.33.0 Path Traversal via code.find MCP tool

knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the host. Attackers can supply absolute paths or relative traversal seque…

▾ Twilightknowns-dev · knownsEPSS 0.48%via CVEORG
CVE-2026-73694High· 7.2PoC
2w ago

FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition

FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input to reach an exec() sink uns…

▾ MidnightFileRun · FileRunEPSS 2.2%via CVEORG
CVEs tagged “exploit-available” — page 44 · VulnSea