VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-28618High· 8.8PoC
2w ago

In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow

In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Midnightgoogle · androidEPSS 0.38%via NVD
CVE-2026-49881High· 7.8PoC
2w ago

In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code

In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interact…

▾ Midnightgoogle · androidEPSS 0.10%via NVD
CVE-2026-86674Medium· 6.3PoC
2w ago

A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is the function session_start of the file login.php. The manipulation results in session fix…

▾ Twilightningzichun · Student Management SystemEPSS 0.38%via NVD
CVE-2026-86675Medium· 6.3PoC
2w ago

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/us_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely.…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-82537High· 8.8PoC
2w ago

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execute denied shell commands by exploiting a word-boundary mismatch in comment handling between the approval gate's shell parser and bash

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execute denied shell commands by exploiting a word-boundary mismatch in comment handling between the approval gate's shell parser and bash. At…

▾ MidnightRooCodeInc · Roo-CodeEPSS 0.47%via NVD
CVE-2026-86716High· 7.3PoC
2w ago

A vulnerability was determined in Cesanta mJS up to 1.26

A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. …

▾ MidnightCesanta · mJSEPSS 0.57%via NVD
CVE-2026-86673High· 7.3PoC
2w ago

A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connec…

▾ Midnightningzichun · Student Management SystemEPSS 0.47%via NVD
CVE-2026-86672Medium· 5.3PoC
2w ago

A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to info…

▾ Twilightningzichun · Student Management SystemEPSS 0.48%via NVD
CVE-2026-86670Low· 3.7PoC
2w ago

A flaw has been found in aircheng-org iWebShop-5 up to 5.15

A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to passwo…

▾ Twilightaircheng-org · iWebShop-5EPSS 0.38%via NVD
CVE-2026-86669High· 7.3PoC
2w ago

A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15

A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possib…

▾ Midnightaircheng-org · iWebShop-5EPSS 0.69%via NVD
CVE-2026-85880High· 7.8CISA KEV0dayPoC
2w ago

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

▾ Abyssalmicrosoft · windows_10_1607EPSS 3.6%via NVD
CVE-2026-83991Medium· 5.5PoC
2w ago

Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.

Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.30%via NVD
CVE-2026-81963High· 7.8CISA KEV0dayPoC
2w ago

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

▾ Abyssalmicrosoft · windows_11_23h2EPSS 0.39%via NVD
CVE-2026-69451High· 7.1PoC
2w ago

Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network.

Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.57%via NVD
CVE-2026-69328High· 7.8PoC
2w ago

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.46%via NVD
CVE-2026-86668Medium· 4.3PoC
2w ago

A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15

A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site…

▾ Twilightaircheng-org · iWebShop-5EPSS 0.47%via NVD
CVE-2026-86667Medium· 4.7PoC
2w ago

A weakness has been identified in aircheng-org iWebShop-5 up to 5.15

A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of the argument Search causes sql injection. The attack is possi…

▾ Twilightaircheng-org · iWebShop-5EPSS 0.35%via NVD
CVE-2026-54611Medium· 5.5PoC
2w ago

InstantCMS is a free and open source content management system

InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possi…

▾ Twilightinstantsoft · icms2EPSS 0.66%via NVD
CVE-2026-48707Low· 3.1PoC
2w ago

InstantCMS is a free and open source content management system

InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "up…

▾ Twilightinstantsoft · icms2EPSS 0.27%via NVD
CVE-2026-86510Critical· 9.9PoC
2w ago

A vulnerability has been found in D-Link DIR-822A A_101

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The ex…

▾ AbyssalD-Link · DIR-822AEPSS 0.51%via NVD
CVE-2026-79570Critical· 9.8PoC
2w ago

mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data

mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

▾ AbyssalEPSS 0.47%via NVD
CVE-2026-52307Medium· 5.4PoC
2w ago

An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the title field.

An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the title field.

▾ TwilightEPSS 0.29%via NVD
CVE-2026-79569Critical· 9.8PoC
2w ago

Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore

Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

▾ AbyssalEPSS 0.47%via NVD
CVE-2026-86840Critical· 9.1PoC
2w ago

The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution

The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying …

▾ AbyssalBitfrost.io · BifrostEPSS 0.42%via NVD
CVE-2026-86666High· 7.3PoC
2w ago

A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15

A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function upload_json/uploadFile of the file controllers/pic.php. The manipulation results in unrestricted upload. The attack can be executed remot…

▾ Midnightaircheng-org · iWebShop-5EPSS 0.54%via NVD
CVE-2026-56101Medium· 5.3PoC
2w ago

OpenBSD before commit 1ee99df contains an inverted comparison vulnerability in the ieee80211_michael_mic_failure() function within sys/net80211/ieee80211_crypto_tkip.c that allows unauthenticated attackers within RF range to trigger deni…

OpenBSD before commit 1ee99df contains an inverted comparison vulnerability in the ieee80211_michael_mic_failure() function within sys/net80211/ieee80211_crypto_tkip.c that allows unauthenticated attackers within RF range to trigger deni…

▾ TwilightOpenBSD · OpenBSDEPSS 0.60%via NVD
CVE-2026-86718High· 7.1PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by maki…

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by maki…

▾ MidnightWWBN · AVideoEPSS 0.20%via NVD
CVE-2026-79574Critical· 9.8PoC
2w ago

An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.

An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.

▾ AbyssalEPSS 0.69%via NVD
CVE-2026-86727High· 7.5PoC
2w ago

AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication

AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers ca…

▾ MidnightWWBN · AVideoEPSS 0.53%via NVD
CVE-2026-86725High· 7.1PoC
2w ago

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records.…

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records.…

▾ MidnightWWBN · AVideoEPSS 0.35%via NVD
CVEs tagged “exploit-available” — page 50 · VulnSea