VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3547 CVEsRSS

CVE-2026-73698High· 7.2PoC
2w ago

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php…

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php…

▾ MidnightFileRun · FileRunEPSS 0.62%via NVD
CVE-2026-89045Medium· 4.0PoC
2w ago

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read method…

▾ Twilightluben · zstd-jniEPSS 0.18%via NVD
CVE-2026-89043High· 7.4PoC
2w ago

passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending

passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SA…

▾ Midnightkrakenjs · passport-saml-encryptedEPSS 0.31%via CVEORG
CVE-2026-85543Medium· 4.3PoC
2w ago

Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.

Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.

▾ TwilightHikvision · Wi-Fi series cameraEPSS 0.27%via NVD
CVE-2026-88898Medium· 6.5PoC
2w ago

AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces

AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published…

▾ TwilightAppFlowy-IO · AppFlowy-CloudEPSS 0.39%via NVD
CVE-2026-64838High· 8.3PoC
2w ago

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequenc…

▾ MidnightICEcoder · icecoder/icecoderEPSS 0.52%via NVD
CVE-2026-88876High· 7.5PoC
2w ago

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling get…

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling get…

▾ MidnightWWBN · AVideoEPSS 0.44%via NVD
CVE-2026-88869Critical· 9.3PoC
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated at…

▾ AbyssalWWBN · AVideoEPSS 0.53%via NVD
CVE-2026-88867High· 8.7PoC
2w ago

WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability

WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability. objects/categoryAddNew.json.php passes the POST parameters `name` and `iconClass` to Cate…

▾ MidnightWWBN · AVideoEPSS 0.37%via NVD
CVE-2026-88866High· 8.7PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers …

▾ MidnightWWBN · AVideoEPSS 0.45%via NVD
CVE-2026-88864Critical· 9.1PoC
2w ago

Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST

Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassin…

▾ AbyssalCap-go · capgo.appEPSS 0.37%via NVD
CVE-2026-88862High· 8.8PoC
2w ago

Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header

Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied num…

▾ MidnightCap-go · capgo.appEPSS 0.44%via NVD
CVE-2026-88861High· 8.3PoC
2w ago

Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication)

Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC…

▾ MidnightCap-go · capgo.appEPSS 0.52%via NVD
CVE-2026-77771High· 7.5PoC
2w ago

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can …

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can …

▾ MidnightEPSS 0.32%via NVD
CVE-2026-77770Critical· 10.0PoC
2w ago

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visit…

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visit…

▾ AbyssalEPSS 0.44%via NVD
CVE-2026-18351Critical· 9.8PoC
2w ago

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type valid…

▾ Abyssaladdonsorg · Drag and Drop File Upload for Elementor FormsEPSS 1.0%via NVD
CVE-2026-87926Medium· 4.3PoC
2w ago

A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a manipulation of the a…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.47%via NVD
CVE-2026-49836Medium· 4.6PoC
2w ago

psd-tools: arbitrary file write via smart-object filename

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled …

▾ Twilightpsd-tools · psd-toolsEPSS 0.19%via CVEORG
CVE-2026-71801Critical· 9.8PoC
2w ago

An issue was discovered in s-pms SPMS-Server through v1.0

An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A r…

▾ AbyssalEPSS 0.79%via NVD
CVE-2026-87875Medium· 4.3PoC
2w ago

Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound

The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backen…

▾ TwilightRed Hat · cups-mainEPSS 0.39%via CVEORG
CVE-2026-79516Medium· 4.0PoC
2w ago

An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted input.

An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted input.

▾ TwilightEPSS 0.13%via CVEORG
CVE-2026-75308Medium· 6.1PoC
2w ago

yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS)

yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other executable files.

▾ TwilightEPSS 0.25%via CVEORG
CVE-2026-71616Medium· 6.2PoC
2w ago

An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to cause a denial of service via the function gf_route_media_complete_object()

An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to cause a denial of service via the function gf_route_media_complete_object(). Fixed in 3c4e6c5b3e0c6fa9b16d55599701a08354538fab.

▾ TwilightEPSS 0.16%via CVEORG
CVE-2026-71614High· 8.4PoC
2w ago

An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the src/media_tools/dvb_mpe.c, descriptorTime_slice_fec_identifier() and gf_m2ts_ipdatagram_reader() components

An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the src/media_tools/dvb_mpe.c, descriptorTime_slice_fec_identifier() and gf_m2ts_ipdatagram_reader() components. Fixed in 0e409339…

▾ MidnightEPSS 0.22%via CVEORG
CVE-2026-87734High· 7.5PoC
2w ago

An issue was discovered in the utcp package before 0.0.6 for OCaml

An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.

▾ MidnightOCaml · utcpEPSS 0.51%via CVEORG
CVE-2026-87810Medium· 5.3PoC
2w ago

Siyuan before v3.8.2 Information Disclosure via fullTextSearchBlock

Siyuan before v3.8.2 contains an information disclosure vulnerability in the POST /api/search/fullTextSearchBlock endpoint that filters private blocks from results but returns unfiltered match counts. Unauthenticated publish-mode readers…

▾ Twilightsiyuan-note · siyuanEPSS 0.34%via CVEORG
CVE-2026-87795High· 8.2PoC
2w ago

com.github.luben/zstd-jni: zstd-jni: Out-of-bounds read in ZstdDictCompress constructor leads to denial of service (CVE-2026-87795)

A flaw was found in zstd-jni. This vulnerability occurs due to insufficient validation of offset and length parameters within the `ZstdDictCompress` constructor. An attacker can exploit this by providing untrusted values, leading to an out…

▾ MidnightRed Hat · Red Hat Ceph Storage 9EPSS 0.63%via CSAF
CVE-2026-87997Medium· 4.3PoC
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/chat/completions and POST /api/v1/chat/completions in backend/open_webui/main.py copied a client-supplied folder_id…

▾ Twilightopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-87016High· 8.1PoC
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that…

▾ Midnightopenwebui · open_webuiEPSS 0.60%via NVD
CVE-2026-79515Medium· 4.3PoC
2w ago

An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file.

An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file.

▾ TwilightEPSS 0.40%via NVD
CVEs tagged “exploit-available” — page 46 · VulnSea