VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-82285High· 8.2PoC
1mo ago

BISHENG Unauthenticated Server-Side Request Forgery via Workflow Report Callback

bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions or host filtering. Unauthenticated att…

▾ Midnightdataelement · bishengEPSS 0.54%via CVEORG
CVE-2026-82288High· 7.5PoC
1mo ago

Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext

Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated a…

▾ MidnightAUTOMATIC1111 · stable-diffusion-webuiEPSS 0.41%via NVD
CVE-2026-82289High· 7.4PoC
1mo ago

Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host with a git., gitlab., or github

Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host with a git., gitlab., or github. prefix regardless of known-hosts list membership. Attackers can submit URLs with attacker-controlled host…

▾ Midnightcoderamp-labs · gitingestEPSS 0.31%via NVD
CVE-2026-82286High· 8.6PoC
1mo ago

gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path

gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-direc…

▾ MidnightBuilderIO · gpt-crawlerEPSS 0.52%via NVD
CVE-2026-82284High· 8.1PoC
1mo ago

Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints

Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation his…

▾ MidnightQuivrHQ · quivrEPSS 0.30%via NVD
CVE-2026-82283High· 8.1PoC
1mo ago

VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations

VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and delete arbitrary conversations and messages by s…

▾ MidnightVoltAgent · @voltagent/server-coreEPSS 0.30%via NVD
CVE-2026-82280High· 7.1PoC
1mo ago

Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier

Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite sy…

▾ MidnightQuivrHQ · quivrEPSS 0.25%via NVD
CVE-2026-82279High· 8.1PoC
1mo ago

HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions

HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename …

▾ Midnighthyperdxio · hyperdxEPSS 0.33%via NVD
CVE-2026-82278High· 8.8PoC
1mo ago

BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code

BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can submit crafted Code node definitions to the POST /api/v…

▾ Midnightdataelement · bishengEPSS 0.74%via NVD
CVE-2026-82276Medium· 5.3PoC
1mo ago

StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override execute() directly instead of implementing executeWithoutPassword()

StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override execute() directly instead of implementing executeWithoutPassword(). Attackers can access six unauthenticated endpoints o…

▾ TwilightStarRocks · starrocksEPSS 0.38%via NVD
CVE-2026-82275High· 7.5PoC
1mo ago

Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories

Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. Attackers can supply absolute file paths to the unauthenticated Gradio interface to read…

▾ MidnightQwenLM · qwen-agentEPSS 0.46%via NVD
CVE-2026-82274Medium· 4.7PoC
1mo ago

Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback endpoint that treats the state query parameter as a redirect URL

Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback endpoint that treats the state query parameter as a redirect URL. Attackers can craft malicious requests to redirect us…

▾ Twilighttwentyhq · twentyEPSS 0.28%via NVD
CVE-2026-82273Medium· 6.5PoC
1mo ago

Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration

Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration. Authenticated attackers can enumerate all threads via GE…

▾ Twilightmastra-ai · @mastra/serverEPSS 0.38%via NVD
CVE-2026-82271Medium· 6.5PoC
1mo ago

R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations

R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename…

▾ TwilightSciPhi-AI · r2rEPSS 0.27%via NVD
CVE-2026-82269High· 8.1PoC
1mo ago

Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware

Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their ac…

▾ Midnightgophish · gophishEPSS 0.38%via NVD
CVE-2026-82268High· 7.5PoC
1mo ago

Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation

Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated …

▾ MidnightQwenLM · qwen-agentEPSS 0.35%via NVD
CVE-2026-82291High· 8.1PoC
1mo ago

HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication

HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visit…

▾ Midnightheyform · heyformEPSS 0.55%via NVD
CVE-2026-82290Medium· 5.3PoC
1mo ago

Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints

Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attackers can delete or modify other users' feedback by supplying arbitrary feedback identifiers, corrupting human-rating …

▾ TwilightChainlit · chainlitEPSS 0.34%via NVD
CVE-2026-81578Critical· 9.8CISA KEVPoC
1mo ago

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions pri…

▾ Hadalpapercut · papercut_mfEPSS 4.5%via NVD
CVE-2026-82078Critical· 9.4CISA KEVPoC
1mo ago

PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against …

▾ HadalPaperCut · PaperCut MF/NGEPSS 3.8%via CVEORG
CVE-2026-78071High· 7.5PoC
1mo ago

Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.

Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.

▾ Midnightdigital-peak.com · DP Calendar extension for JoomlaEPSS 0.42%via NVD
CVE-2026-50979High· 8.1PoC
1mo ago

A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter

A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter

▾ MidnightEPSS 1.9%via NVD
CVE-2026-68929NonePoC
1mo ago

FastGPT is an open-source LLM platform for building AI applications on a knowledge base

FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeChat (iLink) share-channel endpoints authorize requests using only the public shareId, with no authenticated iden…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-82090NonePoC
1mo ago

Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.  JavaScript code can alter the application state via native bridge methods.

Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.  JavaScript code can alter the application state via native bridge methods.

▾ TwilightEPSS 0.44%via NVD
CVE-2026-50980Medium· 6.1PoC
1mo ago

Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record

Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record

▾ TwilightEPSS 0.40%via NVD
CVE-2026-82263Medium· 6.8PoC
1mo ago

Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter

Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbit…

▾ Twilightlogto-io · logtoEPSS 0.46%via NVD
CVE-2026-80724High· 8.8PoC
1mo ago

In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becoming writable vmclock_miscdev_mmap() rejects writable mappings of the shared vmclock ABI page with -EROFS, but leaves…

In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becoming writable vmclock_miscdev_mmap() rejects writable mappings of the shared vmclock ABI page with -EROFS, but leaves…

▾ MidnightLinux · LinuxEPSS 0.18%via NVD
CVE-2026-56100High· 8.1PoC
1mo ago

SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected int…

SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected int…

▾ MidnightSpringBlade · SpringBladeEPSS 0.53%via NVD
CVE-2026-55584High· 7.5PoC
1mo ago

phpSysInfo is a customizable PHP script that displays system information

phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A…

▾ Midnightphpsysinfo · phpsysinfo/phpsysinfoEPSS 1.9%via NVD
CVE-2026-55511Critical· 9.1PoC
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fil…

▾ Abyssalyamcs · org.yamcs:yamcs-coreEPSS 0.68%via NVD
CVEs tagged “exploit-available” — page 62 · VulnSea