VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-49249High· 7.1PoC
3w ago

Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications

Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, BorutaIdentityWeb.UserSettingsController.update/2 atomizes every key of…

▾ Midnightmalach-it · boruta-serverEPSS 0.40%via NVD
CVE-2026-18504Medium· 5.4PoC
3w ago

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

▾ Twilightfastify · fastifyEPSS 0.31%via GHSA
CVE-2026-52832Medium· 4.9PoC
3w ago

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio Dashboard exposes POST /api/functions without authentication by default (NOP auth mode). The spec.handler field (e.g., mymodule:…

▾ Twilightnuclio · github.com/nuclio/nuclioEPSS 0.56%via NVD
CVE-2026-83549High· 7.8CISA KEV0dayPoC
3w ago

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…

▾ Abyssalsonicwall · sma8200vEPSS 11%via NVD
CVE-2026-84361HighPoC
3w ago

Composer is a dependency Manager for the PHP language

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url…

▾ Midnightcomposer · composer/composerEPSS 0.55%via NVD
CVE-2026-75604Critical· 9.0PoC
3w ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently esc…

▾ Abyssalnext · nextEPSS 2.3%via NVD
CVE-2026-71981High· 8.8PoC
3w ago

Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object graph in the back_query GET parameter of the logout ha…

Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object graph in the back_query GET parameter of the logout ha…

▾ MidnightEPSS 0.97%via NVD
CVE-2023-54391Critical· 9.8PoC
3w ago

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configure…

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configure…

▾ AbyssalEPSS 3.0%via NVD
CVE-2026-69664High· 8.7PoC
3w ago

Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hex…

Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hex…

▾ MidnightErlang · otpEPSS 0.95%via NVD
CVE-2026-65643High· 8.8PoC
3w ago

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

▾ Midnightcpanel · cpanelEPSS 0.88%via NVD
CVE-2026-58191Medium· 6.5PoC
3w ago

Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

▾ Twilightappium · @appium/base-driverEPSS 0.56%via GHSA
CVE-2026-82875Medium· 5.5PoC
4w ago

ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace

ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace. Authenticated users can e…

▾ TwilightToolJet · ToolJetEPSS 0.22%via NVD
CVE-2026-82870Critical· 9.6PoC
4w ago

ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases

ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing or…

▾ AbyssalToolJet · ToolJetEPSS 0.43%via NVD
CVE-2026-82876High· 8.2PoC
4w ago

Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage

Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can generate arbitrary RSA key pairs, sign modified firmw…

▾ MidnightPhison Electronics Corporation · PS3111-S11 Controller FirmwareEPSS 0.12%via NVD
CVE-2026-82662Medium· 6.5PoC
4w ago

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth…

▾ Twilightnodemailer · nodemailerEPSS 0.19%via NVD
CVE-2026-82661Medium· 5.4PoC
4w ago

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF se…

▾ Twilightnodemailer · nodemailerEPSS 0.26%via NVD
CVE-2026-82872Critical· 9.1PoC
4w ago

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another w…

▾ AbyssalToolJet · ToolJetEPSS 0.51%via NVD
CVE-2026-82871High· 7.7PoC
4w ago

ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data

ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. Attackers can supply arbitrary organization IDs in URL…

▾ MidnightToolJet · ToolJetEPSS 0.41%via NVD
CVE-2026-82882High· 8.8PoC
4w ago

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint w…

▾ Midnightdevtron-labs · devtronEPSS 0.57%via NVD
CVE-2026-72001High· 8.1PoC
4w ago

Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any protected resource by supplying an attacker-controlled URL parameter to the share-link authentication endpoint tha…

Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any protected resource by supplying an attacker-controlled URL parameter to the share-link authentication endpoint tha…

▾ MidnightEPSS 0.49%via NVD
CVE-2026-56718High· 7.5PoC
4w ago

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path trav…

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path trav…

▾ MidnightEPSS 0.94%via NVD
CVE-2026-82547Medium· 6.5PoC
4w ago

A vulnerability was found in Linux Foundation Magma 1.9.0

A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Complete Message Handler. The manipulation results in improper authent…

▾ TwilightLinux Foundation · MagmaEPSS 0.76%via NVD
CVE-2026-82639High· 7.5PoC
4w ago

NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key

NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching …

▾ MidnightChatGPTNextWeb · NextChatEPSS 0.51%via NVD
CVE-2026-82638High· 7.5PoC
4w ago

jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery

jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresse…

▾ Midnightjina-ai · readerEPSS 0.50%via NVD
CVE-2026-82637Medium· 5.3PoC
4w ago

browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_pat…

browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_pat…

▾ Twilightbrowser-use · web-uiEPSS 0.41%via NVD
CVE-2026-82539Critical· 9.1PoC
4w ago

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory …

▾ AbyssalEPSS 0.83%via NVD
CVE-2026-82457High· 7.8PoC
1mo ago

su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero

su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that trun…

▾ Midnightncopa · su-execEPSS 0.18%via NVD
CVE-2026-82456Critical· 10.0PoC
1mo ago

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface…

▾ Abyssalargoproj-labs · argocd-mcpEPSS 1.7%via NVD
CVE-2026-82265Medium· 6.5PoC
1mo ago

Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information

Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations…

▾ Twilightopenzipkin · zipkinEPSS 0.45%via NVD
CVE-2026-82017High· 7.6PoC
1mo ago

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and u…

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and u…

▾ MidnightIGEL · IGEL OS 12EPSS 0.21%via NVD
CVEs tagged “exploit-available” — page 61 · VulnSea