VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3547 CVEsRSS

CVE-2026-79419High· 8.7PoC
3w ago

A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier

A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao…

▾ Midnightemxtecnologia · gestao_x_business_suiteEPSS 0.38%via NVD
CVE-2026-85604High· 8.8PoC
3w ago

Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter

Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|re…

▾ Midnightgetgrav · gravEPSS 0.86%via NVD
CVE-2026-85599High· 7.2PoC
3w ago

Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping

Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can i…

▾ Midnightgetgrav · grav-plugin-shortcode-coreEPSS 0.26%via NVD
CVE-2026-63464High· 7.7PoC
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/w…

▾ Midnightforgekeep · nebula-meshEPSS 0.46%via NVD
CVE-2026-55512Medium· 5.3PoC
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is reachable without authentication and is registered outside the Web UI rate-limi…

▾ Twilightforgekeep · nebula-meshEPSS 0.60%via NVD
CVE-2026-55513Medium· 5.4PoC
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the server-wide enrollment_token_ttl security setting and per-networ…

▾ Twilightforgekeep · nebula-meshEPSS 0.32%via NVD
CVE-2026-61699High· 8.1PoC
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches an…

▾ Midnightforgekeep · nebula-meshEPSS 0.45%via NVD
CVE-2026-53769Medium· 6.5PoC
3w ago

Avo is a framework to create admin panels for Ruby on Rails apps

Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload…

▾ Twilightavo-hq · avoEPSS 0.42%via NVD
CVE-2026-53760Medium· 5.2PoC
3w ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update operations via GET requests without CSRF token validation. Because…

▾ TwilightAdmidio · admidioEPSS 0.17%via NVD
CVE-2026-85177Medium· 5.4PoC
3w ago

CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system inbox messages

CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system inbox messages. Attackers can update any message's columns includ…

▾ Twilightcrmeb · CRMEBEPSS 0.27%via NVD
CVE-2026-85178High· 7.7PoC
3w ago

Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier

Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owne…

▾ MidnightHelicone · heliconeEPSS 0.41%via NVD
CVE-2026-85378High· 7.3PoC
3w ago

light0011 cms Chapter Controller ChapterController.class.php _initialize authorization

A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/Chapte…

▾ Midnightlight0011 · cmsEPSS 0.52%via CVEORG
CVE-2026-85214High· 8.1PoC
3w ago

vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body

vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body. Attackers can overwrite other users' names, addresses, a…

▾ Midnightlenve · vhrEPSS 0.50%via NVD
CVE-2026-85211High· 7.7PoC
3w ago

Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints

Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying ar…

▾ MidnightHumanSignal · label-studioEPSS 0.41%via NVD
CVE-2026-85183Critical· 9.3PoC
3w ago

Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications

Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitra…

▾ AbyssalAvaiga · taipyEPSS 0.23%via NVD
CVE-2026-85182High· 7.5PoC
3w ago

vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller

vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary account passwords by supplying a target account ID and that account…

▾ Midnightlenve · vhrEPSS 0.44%via NVD
CVE-2026-85093Medium· 6.5PoC
3w ago

Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points

Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers with MEMORY:READ permission can retrieve all users' stored conver…

▾ Twilightcheshire-cat-ai · coreEPSS 0.41%via NVD
CVE-2026-85045High· 7.5PoC
3w ago

Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.29%via NVD
CVE-2026-85048High· 8.3PoC
3w ago

Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: …

▾ Midnightgoogle · chromeEPSS 0.40%via NVD
CVE-2026-85046High· 8.8CISA KEV0dayPoC
3w ago

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 49%via NVD
CVE-2026-84753Critical· 9.8PoC
3w ago

Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.

Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.

▾ AbyssalEPSS 0.56%via NVD
CVE-2026-85210Medium· 4.3PoC
3w ago

Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles

Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filter_criterion parameters …

▾ Twilightoppia · oppiaEPSS 0.34%via NVD
CVE-2026-85179High· 8.5PoC
3w ago

Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints

Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private…

▾ MidnightHumanSignal · label-studioEPSS 0.40%via NVD
CVE-2026-69084Critical· 10.0PoC
3w ago

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

▾ Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 1.6%via GHSA
CVE-2026-69083Critical· 10.0PoC
3w ago

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

▾ Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.47%via GHSA
CVE-2026-53728High· 7.1PoC
3w ago

Medplum is a developer platform that enables development of healthcare apps

Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the external identity provider callback at GET /auth/external accepts attacker-controlled redirect URIs that only need to start with a r…

▾ Midnightmedplum · medplumEPSS 0.20%via NVD
CVE-2026-84809Medium· 6.5PoC
3w ago

Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces

Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can dist…

▾ TwilightTencent · AI-Infra-GuardEPSS 0.57%via NVD
CVE-2026-84810Medium· 6.5PoC
3w ago

claude-skill-antivirus fails to analyze executable files when scanning local skill directories, reading only SKILL.md while ignoring Python source, bytecode, and other artifacts in the scripts directory

claude-skill-antivirus fails to analyze executable files when scanning local skill directories, reading only SKILL.md while ignoring Python source, bytecode, and other artifacts in the scripts directory. Attackers can distribute skills w…

▾ Twilightclaude-world · claude-skill-antivirusEPSS 0.32%via NVD
CVE-2026-84484High· 7.5PoC
3w ago

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the L…

▾ Midnightnasa-jpl · ION-DTNEPSS 0.87%via NVD
CVE-2026-84645High· 8.8PoC
3w ago

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field …

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field …

▾ Midnightjenkins · jenkinsEPSS 0.79%via NVD
CVEs tagged “exploit-available” — page 60 · VulnSea