VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3547 CVEsRSS

CVE-2026-55549Medium· 6.5PoC
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from GET /auth/authorize into yamcs-core/src/main/resources/auth/templates/authorize.html without adequate HTML escaping b…

▾ Twilightyamcs · org.yamcs:yamcs-coreEPSS 1.3%via NVD
CVE-2026-10036High· 8.8PoC
1mo ago

SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enu…

SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enu…

▾ MidnightEPSS 0.46%via NVD
CVE-2026-80209Medium· 4.3PoC
1mo ago

The updateWorkspace handler in mods/identity/src/workspaces/createUpdateWorkspace.ts in Fonoster through 0.22.7 invokes the gRPC callback with PERMISSION_DENIED when createIsWorkspaceMember reports that the caller is not a member of the …

The updateWorkspace handler in mods/identity/src/workspaces/createUpdateWorkspace.ts in Fonoster through 0.22.7 invokes the gRPC callback with PERMISSION_DENIED when createIsWorkspaceMember reports that the caller is not a member of the …

▾ Twilightfonoster · fonosterEPSS 0.39%via NVD
CVE-2026-80207Medium· 5.3PoC
1mo ago

APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false

APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is validated, and the nginx gatewa…

▾ Twilightapitable · apitableEPSS 0.35%via NVD
CVE-2026-47883Medium· 6.1PoC
1mo ago

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6…

▾ Twilightvmware · spring_frameworkEPSS 0.26%via NVD
CVE-2026-47884Critical· 9.8PoC
1mo ago

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spr…

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spr…

▾ Abyssalvmware · spring_frameworkEPSS 0.60%via NVD
CVE-2026-25250Medium· 6.0PoC
1mo ago

EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable."

EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable."

▾ Twilighteazsolution · EazyFixEPSS 0.16%via NVD
CVE-2026-80179Medium· 5.9PoC
1mo ago

Jwcrypto: jwcrypto: denial of service via malformed jwe tokens

A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memor…

▾ TwilightRed Hat · ansible-automation-platform-24/controller-rhel8EPSS 0.41%via CVEORG
CVE-2026-76639High· 8.8PoC
1mo ago

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to…

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to…

▾ MidnightEPSS 0.67%via NVD
CVE-2026-37067Medium· 5.3PoC
1mo ago

Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request.

Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request.

▾ TwilightEPSS 0.34%via NVD
CVE-2026-80521High· 7.8PoC
1mo ago

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: …

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: …

▾ MidnightLinux · LinuxEPSS 0.17%via NVD
CVE-2026-60004Critical· 9.8CISA KEV0dayPoC
1mo ago

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

▾ HadalGitea · GiteaEPSS 24%via CVEORG
CVE-2026-80428Critical· 9.8PoC
1mo ago

ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication end…

ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication end…

▾ AbyssalEPSS 4.5%via NVD
CVE-2026-26211Medium· 4.8PoC
1mo ago

Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without output encoding

Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without output encoding. The value is emitted in three places on that page: the content attribute of the description meta element…

▾ TwilightEPSS 0.36%via NVD
CVE-2026-78903Low· 3.1PoC
1mo ago

Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page

Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

▾ TwilightGoogle · ChromeEPSS 0.29%via CVEORG
CVE-2026-56096Medium· 6.3PoC
1mo ago

The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries

The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthenticated attacker can use this syntax to e…

▾ TwilightTYPO3 · apache-solr-for-typo3/solrEPSS 0.43%via NVD
CVE-2026-64705Medium· 5.5PoC
1mo ago

A buffer overflow was addressed with improved bounds checking

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or wri…

▾ Twilightapple · macosEPSS 0.17%via NVD
CVE-2026-79776Medium· 5.3PoC⚖ disputed
1mo ago

rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler

rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full p…

▾ Twilightrclone · rcloneEPSS 0.43%via NVD
CVE-2026-80051Medium· 5.9PoC
1mo ago

github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its declared type

github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its declared type. The built-in coerceString and coerceBool functions (scalars.go) accept input whose type does not match…

▾ Twilightgraphql-go project · github.com/graphql-go/graphqlEPSS 0.18%via NVD
CVE-2026-59984Medium· 5.5PoC
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32…

▾ TwilightAcademySoftwareFoundation · openexrEPSS 0.17%via NVD
CVE-2026-62862Critical· 9.1PoC
1mo ago

Typebot is an open-source chatbot builder

Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless email magic-link authentication is vulnerable to login-code brute forcing that leads to account takeover. The email p…

▾ AbyssalbaptisteArno · typebot.ioEPSS 0.53%via NVD
CVE-2026-63072High· 7.5PoC
1mo ago

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-b…

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-b…

▾ Midnightopenssl · opensslEPSS 1.0%via NVD
CVE-2026-59985Medium· 5.5PoC
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32…

▾ TwilightAcademySoftwareFoundation · openexrEPSS 0.17%via NVD
CVE-2026-44476Medium· 6.3PoC
1mo ago

Doorkeeper is an OAuth 2 provider for Ruby on Rails

Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain …

▾ Twilightdoorkeeper-gem · doorkeeper-openid_connectEPSS 0.56%via NVD
CVE-2026-39113Medium· 4.0PoC
1mo ago

Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11…

Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11…

▾ TwilightEPSS 0.19%via NVD
CVE-2026-56705Critical· 9.8PoC
1mo ago

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP…

▾ AbyssalEPSS 0.90%via NVD
CVE-2026-49757CriticalPoC
1mo ago

AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

▾ Abyssalash_authentication · ash_authenticationEPSS 0.68%via GHSA
CVE-2026-76071Critical· 9.8PoC
1mo ago

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod…

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod…

▾ AbyssalEPSS 1.4%via NVD
CVE-2026-76070Critical· 9.8PoC
1mo ago

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login hand…

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login hand…

▾ AbyssalEPSS 1.3%via NVD
CVE-2026-67602Critical· 9.1PoC
1mo ago

phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism

phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is keyed by lookup valu…

▾ AbyssalEPSS 0.64%via NVD
CVEs tagged “exploit-available” — page 63 · VulnSea