VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-72711Medium· 6.3PoC
1mo ago

The Lean 4 kernel does not check that the body of an opaque declaration is closed

The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment::add_opaque omits the check_no_metavar_no_fvar call that the definition and theorem paths perform, so a value containing a free variable that …

▾ Twilightleanprover · lean4EPSS 0.18%via NVD
CVE-2026-77635CriticalPoC
1mo ago

CakePHP is a rapid development framework for PHP

CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data i…

▾ Abyssalcakephp · cakephp/cakephpEPSS 0.49%via NVD
CVE-2026-72714Medium· 6.3PoC
1mo ago

Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed

Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed. Local Unset Universe Checking inside a module is expected to last only until the module ends, a…

▾ Twilightrocq-prover · rocqEPSS 0.18%via NVD
CVE-2026-72705Medium· 6.3PoC
1mo ago

The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments

The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments. A fixpoint may pass itself as a higher-order argument to a second fixpoint, which then applies it to a value that is not a subterm …

▾ Twilightrocq-prover · rocqEPSS 0.18%via NVD
CVE-2026-72704Medium· 6.3PoC
1mo ago

The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after that parameter has been changed by transport

The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after that parameter has been changed by transport. A fixpoint may apply a rewrite along an equality between types to its …

▾ Twilightrocq-prover · rocqEPSS 0.18%via NVD
CVE-2026-72703Medium· 6.3PoC
1mo ago

The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls between the different bodies of that fixpoint

The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls between the different bodies of that fixpoint. find_uniform_parameters in kernel/inductive.ml inspects only self-recursive…

▾ Twilightrocq-prover · rocqEPSS 0.18%via NVD
CVE-2020-37268Medium· 6.3PoC
1mo ago

Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in a module type

Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in a module type. Applying a functor inlines the body of the parameter…

▾ Twilightrocq-prover · rocqEPSS 0.18%via NVD
CVE-2026-19874Critical· 9.1PoC
1mo ago

A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players

A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers u…

▾ AbyssalEPSS 0.92%via NVD
CVE-2026-78122High· 7.4PoC
1mo ago

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /cont…

▾ MidnightTecnativa · docker-socket-proxyEPSS 0.31%via NVD
CVE-2026-74586NonePoC
1mo ago

In the Linux kernel, the following vulnerability has been resolved: sctp: clear new_transport when removing a peer sctp_process_asconf_param() stores a newly added peer transport in asoc->new_transport

In the Linux kernel, the following vulnerability has been resolved: sctp: clear new_transport when removing a peer sctp_process_asconf_param() stores a newly added peer transport in asoc->new_transport. After all parameters in the ASCO…

▾ TwilightEPSS 0.73%via NVD
CVE-2026-62382NonePoC
1mo ago

PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic

PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously created push both values are nil…

▾ TwilightEPSS 1.1%via NVD
CVE-2026-66917NonePoC
1mo ago

Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS execution in every visitor's browser.

Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS execution in every visitor's browser.

▾ TwilightEPSS 0.52%via NVD
CVE-2026-66916NonePoC
1mo ago

Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON view

Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON view. When a gallery category is protec…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-77815High· 7.5PoC
1mo ago

to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links

to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory therefore satisfies the containment com…

▾ Midnightzanllp · infinite-image-browsingEPSS 0.51%via NVD
CVE-2026-77814High· 7.5PoC
1mo ago

is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator

is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator. A directory whose name merely begins with an allowed path ther…

▾ Midnightzanllp · infinite-image-browsingEPSS 0.50%via NVD
CVE-2026-53497Medium· 5.3PoC
1mo ago

CrossWatch (CW) is a synchronization engine

CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the other_sessions array, which exposes metadata of all active sessions — including originati…

▾ Twilightcenodude · CrossWatchEPSS 0.40%via NVD
CVE-2026-62316High· 8.8PoC
1mo ago

Microsoft UFO open-source framework for intelligent automation across devices and platforms

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate t…

▾ Midnightmicrosoft · UFOEPSS 0.51%via NVD
CVE-2026-77806Critical· 9.8⚠ ExploitedPoC
1mo ago

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resul…

▾ AbyssalEPSS 4.5%via NVD
CVE-2026-76904Critical· 9.8PoC
1mo ago

GeoTools is an open source Java library that provides tools for geospatial data

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataS…

▾ Abyssalgeotools · org.geotools.jdbc:gt-jdbc-postgisEPSS 2.4%via NVD
CVE-2026-72844Medium· 6.3PoC
1mo ago

The Lean 4 kernel does not verify that the structure named in a projection expression matches the type of the value being projected, and environment::add_inductive in src/kernel/inductive.cpp did not type check the nested inductive appli…

The Lean 4 kernel does not verify that the structure named in a projection expression matches the type of the value being projected, and environment::add_inductive in src/kernel/inductive.cpp did not type check the nested inductive appli…

▾ TwilightEPSS 0.18%via NVD
CVE-2026-72847Medium· 4.6PoC
1mo ago

broot renders each file and directory name in its interactive tree view exactly as read from the filesystem

broot renders each file and directory name in its interactive tree view exactly as read from the filesystem. Names are converted with a plain to_string_lossy() call in src/tree_build/builder.rs and in TreeLine::unprune in src/tree/tree_l…

▾ TwilightCanop · brootEPSS 0.15%via NVD
CVE-2026-72852High· 7.8PoC
1mo ago

hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic

hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic. In src-lib/convolutional_layer.cpp, l.nweights is computed as (c …

▾ Midnighthank-ai · darknetEPSS 0.21%via NVD
CVE-2026-72848High· 8.6PoC
1mo ago

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over …

▾ Midnightlangchain-ai · langchain-communityEPSS 0.60%via NVD
CVE-2026-72846Medium· 6.4PoC
1mo ago

Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsCl…

Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsCl…

▾ Twilightlightdash · lightdashEPSS 0.32%via NVD
CVE-2026-72854Medium· 5.3PoC
1mo ago

msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes its new buffer size using an unchecked size_t addition of the requested size and the amount already used

msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes its new buffer size using an unchecked size_t addition of the requested size and the amount already used. The doubli…

▾ Twilightmsgpack · msgpack-cEPSS 0.16%via NVD
CVE-2026-77066Medium· 5.0PoC
1mo ago

The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation

The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(…

▾ Twilightomnivore-app · omnivoreEPSS 0.25%via NVD
CVE-2026-77067Medium· 5.0PoC
1mo ago

The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper

The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook in packages/api/s…

▾ Twilightomnivore-app · omnivoreEPSS 0.27%via NVD
CVE-2026-73040High· 8.8PoC
1mo ago

Dockge validates a stack name only on the write path

Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$, is reached from save() alone, while the path getter returns path.join(this.serv…

▾ Midnightlouislam · dockgeEPSS 0.94%via NVD
CVE-2026-72860High· 8.5PoC
1mo ago

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares host…

▾ Midnightdecolua · 9routerEPSS 0.38%via NVD
CVE-2026-63382Critical· 9.2PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in…

▾ Abyssallibevent · libeventEPSS 0.78%via NVD
CVEs tagged “exploit-available” — page 64 · VulnSea