VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-86190Critical· 9.1PoC
3w ago

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash par…

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash par…

▾ AbyssalWWBN · AVideoEPSS 0.44%via NVD
CVE-2026-86188High· 7.2PoC
3w ago

AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism

AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send craft…

▾ MidnightWWBN · AVideoEPSS 0.43%via NVD
CVE-2026-86186Medium· 6.5PoC
3w ago

AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection

AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to d…

▾ TwilightWWBN · AVideoEPSS 0.30%via NVD
CVE-2025-15647Medium· 5.5PoC
3w ago

CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round outside adjacent triangles

CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round outside adjacent triangles. Attackers can supply nearly-degenera…

▾ Twilightartem-ogre · CDTEPSS 0.28%via NVD
CVE-2026-86177High· 8.8PoC
3w ago

Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands

Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately …

▾ Midnightpterodactyl · panelEPSS 0.58%via NVD
CVE-2026-86175Medium· 6.5PoC
3w ago

NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses

NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backen…

▾ Twilightnetbox-community · netboxEPSS 0.46%via NVD
CVE-2026-86173High· 7.5PoC
3w ago

MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list

MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list. Attackers can …

▾ Midnightmindsdb · mindsdbEPSS 0.65%via NVD
CVE-2026-86123High· 8.7PoC
3w ago

SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts

SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL …

▾ Midnightsqlchat · sqlchatEPSS 0.49%via NVD
CVE-2026-86121Critical· 9.8PoC
3w ago

Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands

Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can r…

▾ Abyssaltrycua · cua-computer-serverEPSS 1.1%via NVD
CVE-2026-86118Medium· 4.3PoC
3w ago

gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans

gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly call the startScan endpoint to force CPU and I/O…

▾ Twilightsentriz · gonicEPSS 0.47%via NVD
CVE-2026-86116Medium· 6.5PoC
3w ago

Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary entries

Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary entries. Attackers can submit requests to POST, PUT, and DEL…

▾ Twilightmetabase · metabaseEPSS 0.43%via NVD
CVE-2026-86113Medium· 6.5PoC
3w ago

BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records

BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records. Attackers can exploit sequential ReadThrough IDs to overwrite …

▾ Twilightbookwyrm-social · bookwyrmEPSS 0.42%via NVD
CVE-2026-86111Medium· 6.5PoC
3w ago

BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs

BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can acce…

▾ Twilightbookwyrm-social · bookwyrmEPSS 0.44%via NVD
CVE-2026-13447Critical· 9.8PoC
3w ago

The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_tok…

The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_tok…

▾ AbyssalEPSS 0.45%via NVD
CVE-2026-52762High· 7.1PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic template feature that can be escalated to confirmed Remote Code Executio…

▾ MidnightYesWiki · yeswikiEPSS 0.78%via NVD
CVE-2026-52766Critical· 9.1PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that arra…

▾ AbyssalYesWiki · yeswikiEPSS 0.58%via NVD
CVE-2026-52767High· 8.2PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify(...)) { throw ..…

▾ MidnightYesWiki · yeswikiEPSS 0.35%via NVD
CVE-2026-52769High· 8.3PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - accepts an HTTP Signature header whose keyId parameter is a URL. H…

▾ MidnightYesWiki · yeswikiEPSS 0.49%via NVD
CVE-2026-52770High· 7.5PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric query / queries filters. For Bazar fields whose value structure is nume…

▾ MidnightYesWiki · yeswikiEPSS 0.47%via NVD
CVE-2026-52772Medium· 5.5PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body contexts, resulting stored XSS in form renders. This issue has b…

▾ TwilightYesWiki · yeswikiEPSS 0.34%via NVD
CVE-2026-52773Medium· 6.1PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. Because MySQL coer…

▾ TwilightYesWiki · yeswikiEPSS 0.59%via NVD
CVE-2026-52774Medium· 6.1PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attributes using strip_tags() only. Because strip_tags() does not escape double quotes, an attacker c…

▾ TwilightYesWiki · yeswikiEPSS 0.66%via NVD
CVE-2026-52775High· 8.8PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject a…

▾ MidnightYesWiki · yeswikiEPSS 0.48%via NVD
CVE-2026-85688Critical· 9.8PoC
3w ago

TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints

TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to re…

▾ AbyssalTEN-framework · ten-frameworkEPSS 2.6%via NVD
CVE-2026-85730High· 8.2PoC
3w ago

smol-toml is a small, fast, and correct TOML parser and serializer

smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop when a value inside an array or inline table is followed by a comment with no trailing newline. In src/util.ts, skipUn…

▾ Midnightsquirrelchat · smol-tomlEPSS 0.52%via NVD
CVE-2026-44402Critical· 9.8PoC
3w ago

Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar arc…

Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar arc…

▾ AbyssalVoltronic Power · SNMP Web ProEPSS 1.3%via NVD
CVE-2026-85408Medium· 4.3PoC
3w ago

A vulnerability was determined in Eleveo Quality Management 9.7.0

A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. This manipulation of the argument create…

▾ TwilightEleveo · Quality ManagementEPSS 0.40%via NVD
CVE-2026-85516High· 7.3PoC
3w ago

code-projects Vehicle Management System busprofile.php sql injection

A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid results in sql injection. It is possibl…

▾ Midnightcode-projects · Vehicle Management SystemEPSS 0.43%via CVEORG
CVE-2026-85402High· 7.3PoC
3w ago

code-projects Doctor Appointment System booking.php sql injection

A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id results in sql injection. The attack may be la…

▾ Midnightcode-projects · Doctor Appointment SystemEPSS 0.43%via CVEORG
CVE-2026-85383Medium· 6.3PoC
3w ago

itsourcecode Sales and Inventory System inv_del.php sql injection

A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_del.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be ex…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via CVEORG
CVEs tagged “exploit-available” — page 57 · VulnSea