VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-82209High· 8.2PoC⚖ disputed
3w ago

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Do…

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Do…

▾ Midnighthaxx · curlEPSS 0.37%via NVD
CVE-2026-82208High· 7.5PoC⚖ disputed
3w ago

With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns

With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns. A certificate trusted by the cached sto…

▾ Midnighthaxx · curlEPSS 0.41%via NVD
CVE-2026-80255High· 7.5PoC
3w ago

A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag

A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent …

▾ Midnighthaxx · curlEPSS 0.48%via NVD
CVE-2026-80231High· 7.5PoC⚖ disputed
3w ago

A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.

A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.

▾ Midnighthaxx · curlEPSS 0.90%via NVD
CVE-2026-80230High· 7.5PoC⚖ disputed
3w ago

When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections establishe…

When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections establishe…

▾ Midnighthaxx · curlEPSS 0.37%via NVD
CVE-2026-19931Critical· 9.8PoC⚖ disputed
3w ago

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previo…

▾ Abyssalhaxx · curlEPSS 0.75%via NVD
CVE-2026-18924Critical· 9.1PoC⚖ disputed
3w ago

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

▾ Abyssalhaxx · curlEPSS 0.58%via NVD
CVE-2026-13608High· 7.4PoC⚖ disputed
3w ago

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a …

▾ Midnighthaxx · curlEPSS 0.48%via NVD
CVE-2026-86283High· 7.1PoC
3w ago

MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL)

MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action corr…

▾ MidnightMISP · MISPEPSS 0.37%via NVD
CVE-2026-86217Medium· 5.3PoC
3w ago

A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0

A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information …

▾ Twilightcode-projects · Hotel and Tourism Reservation in PHPEPSS 0.53%via NVD
CVE-2026-86216Medium· 4.3PoC
3w ago

A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0

A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument room leads to cross site scripting. The …

▾ Twilightcode-projects · Hotel and Tourism Reservation in PHPEPSS 0.47%via NVD
CVE-2026-86215Medium· 4.3PoC
3w ago

A vulnerability was identified in Mstfakts College-Management-System

A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation of the argument log_out leads to sessio…

▾ TwilightMstfakts · College-Management-SystemEPSS 0.36%via NVD
CVE-2026-86259High· 7.5PoC
3w ago

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url he…

▾ MidnightTHU-MAIC · OpenMAICEPSS 0.42%via NVD
CVE-2026-86214High· 7.3PoC
3w ago

A vulnerability was determined in Mstfakts College-Management-System

A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possible to initiate the…

▾ MidnightEPSS 0.65%via NVD
CVE-2026-86213High· 7.3PoC
3w ago

A vulnerability was found in Mstfakts College-Management-System

A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of the argument book_name/book_author re…

▾ MidnightMstfakts · College-Management-SystemEPSS 0.43%via NVD
CVE-2026-86257Medium· 5.4PoC⚖ disputed
3w ago

wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas

wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or ex…

▾ Twilightwger-project · wgerEPSS 0.28%via NVD
CVE-2026-86256Medium· 5.4PoC
3w ago

wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py)

wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view redirects to the user-supplied 'next' GET param…

▾ Twilightwger-project · wgerEPSS 0.23%via NVD
CVE-2026-86254Medium· 6.8PoC
3w ago

wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer comparison instead of the is_same_gym() helper, allowing gym staff…

wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer comparison instead of the is_same_gym() helper, allowing gym staff…

▾ Twilightwger-project · wgerEPSS 0.37%via NVD
CVE-2026-86252Medium· 5.3PoC
3w ago

h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns

h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type di…

▾ Twilighth3js · h3EPSS 0.36%via NVD
CVE-2026-86251Medium· 5.9PoC
3w ago

h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility

h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path containing double-encoded dot sequences (e.g. %252e%252e) to be decoded to %2e%2e, which survives r…

▾ Twilighth3js · h3EPSS 0.43%via NVD
CVE-2026-86212Medium· 4.3PoC
3w ago

A vulnerability has been found in Open5GS 2.7.7/2.8.0

A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-86205Medium· 5.4PoC
3w ago

h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname

h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname. Attackers can craft a same-origin URL with a double-slash …

▾ Twilighth3js · h3EPSS 0.27%via NVD
CVE-2026-86211High· 7.3PoC
3w ago

A flaw has been found in rabindralamsal inventory-management-system 1.0.0

A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of the argument username/password can lead to sql injection. T…

▾ Midnightrabindralamsal · inventory-management-systemEPSS 0.41%via NVD
CVE-2026-86210High· 7.3PoC
3w ago

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_user_account.php. Such manipulation of the argument ID lea…

▾ MidnightSourceCodester · Class and Exam Timetabling SystemEPSS 0.43%via NVD
CVE-2026-86209High· 7.3PoC
3w ago

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of the argument ID causes sql injection. The attack may be initiated …

▾ MidnightSourceCodester · Class and Exam Timetabling SystemEPSS 0.43%via NVD
CVE-2026-86208High· 7.3PoC
3w ago

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation of the argument ID results in sql injection. The attack can b…

▾ MidnightSourceCodester · Class and Exam Timetabling SystemEPSS 0.43%via NVD
CVE-2026-86183Medium· 5.3PoC
3w ago

A vulnerability was identified in diem-project diem up to 5.1.3

A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the arg…

▾ Twilightdiem-project · diemEPSS 0.57%via NVD
CVE-2026-86182Medium· 4.3PoC
3w ago

A vulnerability was determined in diem-project diem up to 5.1.3

A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmConsole. This manipulation of the argument…

▾ Twilightdiem-project · diemEPSS 0.23%via NVD
CVE-2026-86181Low· 3.5PoC
3w ago

A vulnerability was found in code-projects Task Management System 1.0

A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component User Profile Update. The manipulation of the argument ln…

▾ Twilightcode-projects · Task Management SystemEPSS 0.36%via NVD
CVE-2026-86180High· 7.3PoC
3w ago

A vulnerability has been found in code-projects Task Management System In PHP 1.0

A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to …

▾ Midnightcode-projects · Task Management System In PHPEPSS 0.43%via NVD
CVEs tagged “exploit-available” — page 55 · VulnSea