VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-80099High· 8.8PoC
2w ago

Several Newfold plugins are vulnerable to Authentication Bypass

Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` f…

▾ MidnightNewfold · WP Plugin WebEPSS 2.9%via NVD
CVE-2026-87921High· 7.3PoC
2w ago

A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is the function update_record of the file includes/manage.php. The manipulation of the argument update_catego…

▾ MidnightRizwan17 · inventory-management-systemEPSS 0.43%via NVD
CVE-2026-73786High· 7.5PoC
2w ago

A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack

A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade pe…

▾ MidnightHewlett Packard Enterprise (HPE) · ClearPass Policy Manager (CPPM)EPSS 0.57%via NVD
CVE-2026-22590Critical· 9.1PoC
2w ago

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group)

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 have a remotely triggerable Out-of-Bounds Read whil…

▾ AbyssaleProsima · Fast-DDSEPSS 0.38%via NVD
CVE-2026-86199High· 7.5PoC
2w ago

PocketMine-MP versions before 5.43.1 fail to properly validate the Certificate field during offline login authentication

PocketMine-MP versions before 5.43.1 fail to properly validate the Certificate field during offline login authentication. Unauthenticated players can trigger an uninitialized property access error that crashes the server.

▾ Midnightpmmp · PocketMine-MPEPSS 0.47%via NVD
CVE-2026-86748Medium· 6.1PoC
2w ago

Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint

Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mec…

▾ Twilightsnipeitapp · snipe-itEPSS 0.40%via NVD
CVE-2026-86204Medium· 6.5PoC
2w ago

PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allowing authenticated players to cause denial of service

PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allowing authenticated players to cause denial of service. Attackers can send modal form response packets with massive JSON arrays …

▾ Twilightpmmp · PocketMine-MPEPSS 0.44%via NVD
CVE-2026-87821High· 7.1PoC
2w ago

Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body

Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can…

▾ Midnightlaradashboard · laradashboardEPSS 0.47%via NVD
CVE-2026-87816High· 7.5PoC
2w ago

PasswordPusher before 2.11.1 contains a time-of-check-to-time-of-use race condition in view limit enforcement that allows unauthenticated attackers to bypass expire_after_views limits

PasswordPusher before 2.11.1 contains a time-of-check-to-time-of-use race condition in view limit enforcement that allows unauthenticated attackers to bypass expire_after_views limits. Attackers can send concurrent requests to the show e…

▾ Midnightpglombardo · PasswordPusherEPSS 0.37%via NVD
CVE-2026-14962High· 8.6PoC
2w ago

The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks and extract arbitrary da…

The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks and extract arbitrary da…

▾ MidnightEPSS 0.40%via NVD
CVE-2026-87733Medium· 6.2PoC
2w ago

An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml

An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures…

▾ TwilightOCaml · mirage-crypto-ecEPSS 0.15%via NVD
CVE-2026-87732Medium· 6.2PoC
2w ago

An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml

An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then…

▾ TwilightOCaml · mirage-cryptoEPSS 0.11%via NVD
CVE-2026-87492Critical· 9.6PoC
2w ago

Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 0.44%via NVD
CVE-2026-87491High· 8.8CISA KEV0dayPoC
2w ago

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

▾ Abyssalgoogle · chromeEPSS 3.1%via NVD
CVE-2026-87575Medium· 5.4PoC
2w ago

Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page

Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

▾ Twilightgoogle · chromeEPSS 0.22%via NVD
CVE-2026-53937Medium· 6.2PoC
2w ago

MCP Kotlin SDK is the Kotlin Multiplatform software development kit for the Model Context Protocol

MCP Kotlin SDK is the Kotlin Multiplatform software development kit for the Model Context Protocol. In versions 0.7.0 through 0.12.0, `ReadBuffer.append` in `kotlin-sdk-core/src/commonMain/kotlin/io/modelcontextprotocol/kotlin/sdk/shared…

▾ Twilightmodelcontextprotocol · io.modelcontextprotocol:kotlin-sdkEPSS 0.19%via NVD
CVE-2026-53939Critical· 9.1PoC
2w ago

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE)

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS3…

▾ AbyssalOpenIDC · cjoseEPSS 0.31%via NVD
CVE-2026-53581Critical· 9.0PoC
2w ago

OPNsense is a FreeBSD based firewall and routing platform

OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite a…

▾ Abyssalopnsense · coreEPSS 0.47%via NVD
CVE-2026-77078High· 7.5PoC
2w ago

multer vulnerable to Denial of Service via crafted multipart field names

multer vulnerable to Denial of Service via crafted multipart field names

▾ Midnightmulter · multerEPSS 0.49%via GHSA
CVE-2026-77827High· 7.1PoC
2w ago

Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'

Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80.

▾ MidnightMaono · Maono LinkEPSS 0.16%via NVD
CVE-2026-79588Medium· 4.3PoC
2w ago

U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.

U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.

▾ TwilightEPSS 0.15%via NVD
CVE-2026-78971Medium· 4.6PoC
2w ago

In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.

In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.

▾ TwilightEPSS 0.24%via NVD
CVE-2026-78742Medium· 6.1PoC
2w ago

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-78741Medium· 6.1PoC
2w ago

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-78738Medium· 6.1PoC
2w ago

Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature.

Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-52486Medium· 6.6PoC
2w ago

An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module

An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module

▾ TwilightEPSS 0.09%via NVD
CVE-2026-84869Critical· 9.9CISA KEVPoC
2w ago

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

▾ Hadalconnectwise · screenconnectEPSS 0.92%via NVD
CVE-2026-86808High· 7.3PoC
2w ago

A security vulnerability has been detected in moltis-org moltis up to 20260818.10

A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. …

▾ Midnightmoltis-org · moltisEPSS 0.84%via NVD
CVE-2026-78997Critical· 9.3PoC
2w ago

UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin

UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a spe…

▾ AbyssalEPSS 0.40%via NVD
CVE-2026-28609High· 8.8PoC
2w ago

In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting

In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Midnightgoogle · androidEPSS 0.37%via NVD
CVEs tagged “exploit-available” — page 49 · VulnSea