VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3547 CVEsRSS

CVE-2026-86179Medium· 5.3PoC
3w ago

A flaw has been found in code-projects Daily Expense Manager 1.0

A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information di…

▾ Twilightcode-projects · Daily Expense ManagerEPSS 0.53%via NVD
CVE-2026-86172Medium· 6.3PoC
3w ago

A vulnerability was detected in DefaultFuction CRM 1.0.0

A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the a…

▾ TwilightDefaultFuction · CRMEPSS 0.32%via NVD
CVE-2026-86171Medium· 6.3PoC
3w ago

A security vulnerability has been detected in DefaultFuction CRM 1.0.0

A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed fro…

▾ TwilightDefaultFuction · CRMEPSS 0.32%via NVD
CVE-2026-86170Medium· 6.3PoC
3w ago

A weakness has been identified in DefaultFuction CRM 1.0.0

A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried…

▾ TwilightDefaultFuction · CRMEPSS 0.32%via NVD
CVE-2026-86168High· 7.3PoC
3w ago

A security flaw has been discovered in code-projects Content Management System 1.0

A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can b…

▾ Midnightcode-projects · Content Management SystemEPSS 0.43%via NVD
CVE-2026-86167Critical· 9.9PoC
3w ago

A vulnerability was identified in Tenda HG10 300001138

A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remot…

▾ AbyssalTenda · HG10EPSS 2.7%via NVD
CVE-2026-86166High· 8.8PoC
3w ago

A vulnerability was determined in Tenda HG10 300001138

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer …

▾ MidnightTenda · HG10EPSS 0.85%via NVD
CVE-2026-86165Critical· 9.8PoC
3w ago

A vulnerability was found in Tenda HG10 300001138

A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be …

▾ AbyssalTenda · HG10EPSS 1.1%via NVD
CVE-2026-86164Medium· 6.3PoC
3w ago

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of the argument ID results in sql injection. The attack may be perfor…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-86163Medium· 6.3PoC
3w ago

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carr…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-86218Critical· 9.8CISA KEVPoC
3w ago

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

▾ Hadaln-able · n-centralEPSS 13%via NVD
CVE-2026-86162High· 7.3PoC
3w ago

A vulnerability was determined in SourceCodester Online Voting System 1.0

A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack can b…

▾ MidnightSourceCodester · Online Voting SystemEPSS 0.43%via NVD
CVE-2026-86161High· 7.3PoC
3w ago

A vulnerability was found in SourceCodester Online Voting System 1.0

A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of the argument ID results in sql injection. Remote…

▾ MidnightSourceCodester · Online Voting SystemEPSS 0.43%via NVD
CVE-2026-86160High· 7.3PoC
3w ago

A vulnerability has been found in SourceCodester Online Voting System 1.0

A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of the argument ID leads to sql injection. The attack ma…

▾ MidnightSourceCodester · Online Voting SystemEPSS 0.43%via NVD
CVE-2026-86159High· 7.3PoC
3w ago

A flaw has been found in SourceCodester Online Voting System 1.0

A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. Th…

▾ MidnightSourceCodester · Online Voting SystemEPSS 0.43%via NVD
CVE-2026-75816Critical· 9.8PoC
3w ago

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or owners…

▾ AbyssalEPSS 0.91%via NVD
CVE-2026-86151Critical· 9.1PoC
3w ago

A vulnerability was detected in Tenda CP3 27.5.57.101

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection…

▾ AbyssalTenda · CP3EPSS 2.9%via NVD
CVE-2026-86206Medium· 6.9PoC
3w ago

A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs

A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4

▾ TwilightN-able · N-centralEPSS 1.1%via NVD
CVE-2026-86060Critical· 9.8CISA KEVPoC
3w ago

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requ…

▾ Hadalmikrotik · routerosEPSS 1.8%via NVD
CVE-2026-67281High· 7.5PoC
3w ago

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare…

▾ Midnightmikrotik · routerosEPSS 0.73%via NVD
CVE-2026-67279Medium· 6.5CISA KEVPoC
3w ago

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the…

▾ Midnightmikrotik · routerosEPSS 1.0%via NVD
CVE-2026-67278Critical· 9.1PoC⚖ disputed
3w ago

MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication

MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication. Because its trust store includes an e=3 root CA, an attacker controllin…

▾ Abyssalmikrotik · routerosEPSS 0.25%via NVD
CVE-2026-67277High· 8.2CISA KEVPoC
3w ago

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits a…

▾ Abyssalmikrotik · routerosEPSS 1.6%via NVD
CVE-2026-67276High· 8.1PoC
3w ago

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supp…

▾ Midnightmikrotik · routerosEPSS 6.5%via NVD
CVE-2026-86207High· 7.7PoC
3w ago

An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

▾ MidnightN-able · N-centralEPSS 1.3%via NVD
CVE-2026-82752Medium· 5.9PoC
3w ago

Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose length constraint should bound it. Ash measures string length with Elixir's …

Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose length constraint should bound it. Ash measures string length with Elixir's …

▾ Twilightash-project · ashEPSS 0.18%via NVD
CVE-2026-86196High· 8.7PoC
3w ago

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can s…

▾ Midnightgetgrav · grav-plugin-apiEPSS 0.43%via NVD
CVE-2026-86195High· 8.7PoC
3w ago

grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super

grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super. …

▾ Midnightgetgrav · grav-plugin-apiEPSS 0.39%via NVD
CVE-2026-86193High· 8.7PoC
3w ago

grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts

grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch passwor…

▾ Midnightgetgrav · grav-plugin-apiEPSS 0.36%via NVD
CVE-2026-86191Medium· 4.3PoC
3w ago

SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visi…

SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visi…

▾ Twilightsiyuan-note · siyuanEPSS 0.28%via NVD
CVEs tagged “exploit-available” — page 56 · VulnSea