VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-85625High· 8.1PoC
3w ago

sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where

sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where. The $where operation compiles a string value into a function using new Function …

▾ Midnightcrcn · sift.jsEPSS 0.73%via NVD
CVE-2026-6958High· 7.8PoC
3w ago

Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that allows low-privileged local attackers to execute arbitrary code as SYSTEM by exploiting a m…

Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that allows low-privileged local attackers to execute arbitrary code as SYSTEM by exploiting a m…

▾ MidnightInvicti Security Corp. · AcunetixEPSS 0.18%via NVD
CVE-2026-80118High· 7.1PoC
3w ago

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users thr…

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users thr…

▾ MidnightPassMark Software · PerformanceTestEPSS 0.17%via NVD
CVE-2026-80113High· 7.1PoC
3w ago

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to clear arbitrary bits at …

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to clear arbitrary bits at …

▾ MidnightPassMark Software · PerformanceTestEPSS 0.16%via NVD
CVE-2026-53758High· 8.7PoC
3w ago

Emlog is an open source website building system

Emlog is an open source website building system. In versions 2.6.29 and prior, article content is processed by Parsedown without enabling safe mode, which means raw HTML including <script> tags embedded in Markdown is passed through unes…

▾ Midnightemlog · emlogEPSS 0.44%via NVD
CVE-2026-85612High· 7.5PoC
3w ago

OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation

OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the…

▾ MidnightOpenpanel-dev · openpanelEPSS 0.41%via NVD
CVE-2026-85769Medium· 6.5PoC
3w ago

A flaw was found in libtpms, a library that provides software TPM 2.0 emulation

A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized sk…

▾ TwilightRed Hat · libtpmsEPSS 0.42%via NVD
CVE-2026-78839High· 8.1PoC
3w ago

An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading a crafted .phar file.

An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading a crafted .phar file.

▾ MidnightEPSS 0.55%via NVD
CVE-2026-75439High· 7.5PoC
3w ago

An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component

An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component

▾ MidnightEPSS 0.76%via NVD
CVE-2026-71625Critical· 9.8PoC
3w ago

An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component

An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component

▾ AbyssalEPSS 0.74%via NVD
CVE-2026-71622High· 7.4PoC
3w ago

SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component

SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component

▾ MidnightEPSS 0.45%via NVD
CVE-2026-50894Critical· 9.8PoC
3w ago

easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted fil…

easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted fil…

▾ AbyssalEPSS 0.86%via NVD
CVE-2026-78849Medium· 5.4PoC
3w ago

Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file

Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file

▾ TwilightEPSS 0.50%via NVD
CVE-2026-75430Critical· 9.8PoC
3w ago

PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port

PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.

▾ AbyssalEPSS 1.2%via NVD
CVE-2026-75431Critical· 9.1PoC
3w ago

PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication

PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.

▾ AbyssalEPSS 1.1%via NVD
CVE-2026-75429Critical· 9.8PoC
3w ago

PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer

PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer

▾ AbyssalEPSS 0.98%via NVD
CVE-2022-35499High· 7.1PoC
3w ago

In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.

In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.

▾ MidnightEPSS 0.29%via NVD
CVE-2022-35497Medium· 5.4PoC
3w ago

In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting affecting the external document viewer endpoint.

In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting affecting the external document viewer endpoint.

▾ TwilightEPSS 0.26%via NVD
CVE-2026-85197High· 7.6PoC
3w ago

A flaw was found in libsoup

A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using …

▾ MidnightRed Hat · libsoup3EPSS 0.27%via NVD
CVE-2026-85613High· 8.2PoC
3w ago

OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL

OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL. Attackers can host malicio…

▾ MidnightOpenpanel-dev · openpanelEPSS 0.40%via NVD
CVE-2026-85621Medium· 6.5PoC
3w ago

LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feishu adapters

LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feishu adapters. The webhook route (/api/agent/webhooks/:platform) is unauthenticated by design and delegates verification to each a…

▾ Twilightlobehub · lobehubEPSS 0.20%via NVD
CVE-2026-85607High· 8.8PoC
3w ago

Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/routerTrpc/message.ts and conversation.clearMessages in server/rou…

Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/routerTrpc/message.ts and conversation.clearMessages in server/rou…

▾ Midnightblinkospace · blinkoEPSS 0.69%via NVD
CVE-2026-85513Medium· 6.3PoC
3w ago

StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management

A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_user_query_param_is_provided of the file st2api/st2api/controllers/v1/actionexecutions.py of the component NoOp RBAC ba…

▾ TwilightStackStorm · st2EPSS 0.43%via CVEORG
CVE-2026-85626High· 7.5PoC
3w ago

git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validation

git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validation. Attackers can inject git command-line options like --output= …

▾ Midnightcyanheads · git-mcp-serverEPSS 0.48%via NVD
CVE-2026-79426High· 7.2PoC
3w ago

An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request.

An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request.

▾ MidnightEPSS 0.53%via NVD
CVE-2026-86091High· 7.1PoC
3w ago

ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings

ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endp…

▾ Midnightntop · ntopngEPSS 0.52%via NVD
CVE-2026-80116High· 7.8PoC
3w ago

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configur…

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configur…

▾ MidnightPassMark Software · PerformanceTestEPSS 0.17%via NVD
CVE-2026-85699High· 7.5PoC
3w ago

jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops

jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal…

▾ Midnightjina-ai · readerEPSS 0.48%via NVD
CVE-2026-85694High· 8.1PoC
3w ago

LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content

LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code throu…

▾ Midnightlavague-ai · LaVagueEPSS 0.94%via NVD
CVE-2026-85684Critical· 9.1PoC
3w ago

marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter

marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers can supply filenames containing directory traversal sequence…

▾ Abyssaldatalab-to · markerEPSS 1.1%via NVD
CVEs tagged “exploit-available” — page 58 · VulnSea