VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-79592High· 7.5PoC
2w ago

An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.

An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.

▾ MidnightEPSS 0.43%via NVD
CVE-2026-88874High· 7.5PoC
2w ago

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin. Live::_getStats() (plugin/Live/Live.php) returns a password…

▾ MidnightWWBN · AVideoEPSS 0.55%via NVD
CVE-2026-87962High· 7.5PoC
2w ago

t-digest versions 3.1 through 3.3 contain a denial of service vulnerability in MergingDigest.fromBytes that fails to validate length and capacity fields from serialized data

t-digest versions 3.1 through 3.3 contain a denial of service vulnerability in MergingDigest.fromBytes that fails to validate length and capacity fields from serialized data. Attackers can supply crafted serialized digests with mismatche…

▾ Midnighttdunning · t-digestEPSS 0.63%via NVD
CVE-2026-88790Medium· 4.8PoC
2w ago

A security vulnerability has been detected in proma-ai Proma up to 0.19.37

A security vulnerability has been detected in proma-ai Proma up to 0.19.37. Affected is the function resolveTargetPath of the file apps/electron/src/main/lib/file-preview-service.ts of the component File Preview Service. Such manipulatio…

▾ Twilightproma-ai · PromaEPSS 0.17%via NVD
CVE-2026-88056High· 8.6PoC
2w ago

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Rendering in @angular/platform-server processe…

▾ Midnightangular · angularEPSS 0.61%via NVD
CVE-2026-88877Critical· 9.8PoC
2w ago

Traefik is a HTTP reverse proxy and load balancer

Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both an authentication annotation and the nginx.ingress.kubernetes.io/from-to-…

▾ Abyssaltraefik · traefikEPSS 0.65%via NVD
CVE-2026-88051High· 7.8PoC
2w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved and size_used_ from a .traineddata model without a c…

▾ Midnighttesseract-ocr · tesseract_ocrEPSS 0.18%via NVD
CVE-2026-88891High· 8.3PoC
2w ago

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboard…

▾ MidnightOpenpanel-dev · openpanelEPSS 0.37%via NVD
CVE-2026-88016High· 7.1PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and l…

▾ Midnightrclone · rcloneEPSS 0.27%via NVD
CVE-2026-88049Medium· 5.5PoC⚖ disputed
2w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left NetworkIO::WriteTimeStep…

▾ Twilighttesseract-ocr · tesseract_ocrEPSS 0.14%via NVD
CVE-2026-88894Medium· 5.4PoC
2w ago

Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target

Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, license and consumable checkout paths, App\Services\Predefine…

▾ Twilightgrokability · snipe-itEPSS 0.26%via NVD
CVE-2026-88058High· 8.6PoC
2w ago

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server se…

▾ Midnightangular · angularEPSS 0.88%via NVD
CVE-2026-87925High· 7.3PoC
2w ago

A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Performing a manipula…

▾ MidnightRizwan17 · inventory-management-systemEPSS 0.43%via NVD
CVE-2026-88048High· 7.1PoC
2w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions. During Fu…

▾ Midnighttesseract-ocr · tesseract_ocrEPSS 0.16%via NVD
CVE-2026-88892Medium· 5.0PoC
2w ago

OpenPanel is an analytics platform

OpenPanel is an analytics platform. In all versions (no patched release available at time of publication), the data importer fetches a caller-supplied URL with plain fetch instead of the project's existing SSRF guard (apps/api/src/utils/…

▾ TwilightOpenpanel-dev · openpanelEPSS 0.28%via NVD
CVE-2026-88050Medium· 5.5PoC
2w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component. UnicharCo…

▾ Twilighttesseract-ocr · tesseract_ocrEPSS 0.14%via NVD
CVE-2026-45769High· 7.5PoC
2w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5,IKEv2 parser state could grow without bounds while storing client transforms. Repeat…

▾ Midnightoisf · suricataEPSS 1.8%via NVD
CVE-2026-36392Medium· 5.4PoC
2w ago

FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scripting (XSS)

FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scripting (XSS). An authenticated administrator can inject arbitrary JavaScript into an item's title, which is stored server-side and executed in the browser of any client use…

▾ TwilightEPSS 0.23%via NVD
CVE-2026-89046High· 8.2PoC
2w ago

zstd-jni: zstd-jni: Information disclosure or denial of service via out-of-bounds read (CVE-2026-89046)

A flaw was found in zstd-jni. This out-of-bounds read vulnerability in the Zstd.getFrameContentSize function occurs because it fails to validate negative srcPosition arguments. A remote attacker can supply negative offset values, bypassing…

▾ MidnightRed Hat · Red Hat Ceph Storage 9EPSS 0.65%via CSAF
CVE-2026-88055Medium· 5.5PoC
2w ago

AnythingLLM: Stored XSS Due to Unescaped Server-Side HTML Concatenation in MetaGenerator

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.16.1 and earlier, the manager role can store meta_page_title or meta_page_favicon through /api/admin/system-…

▾ TwilightMintplex-Labs · anything-llmEPSS 0.28%via CVEORG
CVE-2026-87933High· 8.6PoC
2w ago

cJSON: cJSON: Memory corruption via use after free in cJSONUtils_MergePatch (CVE-2026-87933)

A flaw was found in DaveGamble cJSON. The `cJSONUtils_MergePatch` function in `cJSON_Utils.c` is vulnerable to a use-after-free error. A remote attacker could exploit this memory corruption vulnerability, potentially leading to information…

▾ MidnightRed Hat · Red Hat Satellite 6EPSS 0.53%via CSAF
CVE-2026-88060High· 8.6PoC
2w ago

Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server se…

▾ Midnightangular · angularEPSS 0.76%via CVEORG
CVE-2026-79591High· 7.8PoC
2w ago

A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.

A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.

▾ MidnightEPSS 0.17%via NVD
CVE-2026-79590Medium· 6.5PoC
2w ago

A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0

A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functio…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-71640Critical· 9.1PoC
2w ago

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline

▾ AbyssalEPSS 0.63%via NVD
CVE-2026-88940Medium· 5.3PoC
2w ago

knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to loc…

▾ Twilightknowns-dev · knownsEPSS 0.56%via CVEORG
CVE-2026-88939High· 8.3PoC
2w ago

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project direct…

▾ Midnightknowns-dev · knownsEPSS 0.48%via NVD
CVE-2026-88937High· 8.8PoC
2w ago

knowns through 0.33.0 Path Traversal via Template Engine

knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply malicious templates t…

▾ Midnightknowns-dev · knownsEPSS 0.65%via CVEORG
CVE-2026-45747High· 7.5PoC
2w ago

Suricata lua/tls: null dereference in TlsGetCertInfo

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lu…

▾ MidnightOISF · suricataEPSS 0.39%via CVEORG
CVE-2026-73699High· 7.2PoC
2w ago

FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()

FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a position…

▾ MidnightFileRun · FileRunEPSS 0.78%via CVEORG
CVEs tagged “exploit-available” — page 45 · VulnSea