VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-53587High· 7.5PoC
1mo ago

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in…

▾ Midnightlibgit2 · libgit2EPSS 0.68%via NVD
CVE-2026-63383High· 8.7PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates u…

▾ Midnightlibevent · libeventEPSS 0.52%via NVD
CVE-2026-63495High· 7.5PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An unauthenti…

▾ Midnightlibevent · libeventEPSS 0.61%via NVD
CVE-2026-63387High· 7.0PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocat…

▾ Midnightlibevent · libeventEPSS 0.45%via NVD
CVE-2026-73258Medium· 6.5PoC
1mo ago

Mongoose is an embedded web server and network library

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing s[b] and s…

▾ Twilightcesanta · mongooseEPSS 0.46%via NVD
CVE-2026-77647Critical· 9.8⚠ ExploitedPoC
1mo ago

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases suc…

▾ AbyssalEPSS 2.5%via NVD
CVE-2026-69836Critical· 10.0PoC
1mo ago

Microsoft Entra ID Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

▾ AbyssalMicrosoft · Microsoft EntraEPSS 1.5%via CVEORG
CVE-2026-72818High· 7.5PoC
1mo ago

The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded

The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Inpu…

▾ Midnightnltk · nltkEPSS 0.74%via NVD
CVE-2026-40345HighPoC
1mo ago

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the deepmerge, deepmergeCustom, deepmergeInto, and deepmergeIntoCustom APIs do not track visited objects or object pairs …

▾ Midnightdeepmerge-ts · deepmerge-tsEPSS 0.52%via NVD
CVE-2026-76850Critical· 9.8PoC
1mo ago

LMDeploy deserializes disaggregated-serving peer messages with pickle

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received…

▾ AbyssalInternLM · lmdeployEPSS 1.3%via NVD
CVE-2026-76883Medium· 4.7PoC
1mo ago

Heap-based Buffer Overflow in Wireshark

Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ TwilightWireshark Foundation · WiresharkEPSS 0.14%via CVEORG
CVE-2026-76882Medium· 4.7PoC
1mo ago

Out-of-bounds Read in Wireshark

Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ TwilightWireshark Foundation · WiresharkEPSS 0.14%via CVEORG
CVE-2026-76884Low· 3.1PoC
1mo ago

Buffer Over-read in Wireshark

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ TwilightWireshark Foundation · WiresharkEPSS 0.33%via CVEORG
CVE-2026-76888Low· 3.1PoC
1mo ago

Heap-based Buffer Overflow in Wireshark

RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ TwilightWireshark Foundation · WiresharkEPSS 0.33%via CVEORG
CVE-2026-68554Low· 2.3PoC
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append attributes after MESSAGE-INTEGRITY to an authenticated STUN request on plain UDP or TCP, adjust the STUN header length, …

▾ Twilightcoturn · coturnEPSS 0.19%via NVD
CVE-2026-45274Medium· 6.9PoC
1mo ago

MyBooks is anebook management web server also known as Talebook

MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.post handler for POST /api/user/sign_up in webserver/handlers/user.py does not enforce the ALLOW_REGISTER configuration flag, even though …

▾ TwilightPoxenStudio · talebookEPSS 0.71%via NVD
CVE-2026-48711High· 7.0PoC
1mo ago

SSHFS is a network filesystem client for connecting to SSH servers

SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracketed mount source such as [-oProxyCommand=CMD]:/path and find_base_path() removes the brackets, leaving a host value t…

▾ Midnightlibfuse · sshfsEPSS 0.24%via NVD
CVE-2026-68553High· 7.1PoC
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string() validation…

▾ Midnightcoturn · coturnEPSS 0.48%via NVD
CVE-2026-55194Critical· 9.8PoC
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint …

▾ Abyssalfreerdp · freerdpEPSS 0.62%via NVD
CVE-2026-45741High· 7.5PoC
1mo ago

Gotenberg is a Docker-powered stateless API for PDF files

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not reject the 2002::/16 6to4 prefix, the 64:ff9b::/96 and 64:ff9b:1::/48 NAT64 prefixes, the fec…

▾ Midnightgotenberg · gotenbergEPSS 0.37%via NVD
CVE-2026-19490Critical· 9.8CISA KEVPoC
1mo ago

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

▾ Hadalcitrix · netscaler_application_delivery_controllerEPSS 7.0%via NVD
CVE-2026-53546Critical· 9.6PoC
1mo ago

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket accepts a user-controlled hostConfig.id and src/backend/ssh/host-resolver.ts resolves th…

▾ AbyssalTermix-SSH · TermixEPSS 0.46%via NVD
CVE-2026-62672Medium· 6.0PoC
1mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and function in system/config/security.yaml, and GravExtension::regexReplace() passes an editor-controlled pattern directly to preg_replace(). Wh…

▾ Twilightgetgrav · gravEPSS 0.38%via NVD
CVE-2026-44253Medium· 4.9PoC
1mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3.9.0 until 4.14.5 and 5.0.0-beta2, the Wazuh cluster protocol in framework/wazuh/core/cluster/common.py allows an authenticated cluster n…

▾ Twilightwazuh · wazuhEPSS 0.61%via NVD
CVE-2026-71960Critical· 9.1PoC
1mo ago

Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting…

Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting…

▾ AbyssalShenzhen Cudy Technology Co., Ltd. · WR3000 2.0EPSS 0.53%via NVD
CVE-2026-75616Medium· 6.8PoC
1mo ago

An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations

An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation…

▾ Twilighttp-link · archer_c20_firmwareEPSS 2.8%via NVD
CVE-2026-55087Medium· 6.1PoC
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into HTML, JavaScript, and CSS under /admi…

▾ Twilightep_etherpad-lite · ep_etherpad-liteEPSS 0.58%via NVD
CVE-2026-75626Critical· 9.3PoC
1mo ago

SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata

SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute script…

▾ Abyssalsmicallef · spiderfootEPSS 0.33%via NVD
CVE-2026-75625Critical· 9.0PoC
1mo ago

Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation

Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent p…

▾ Abyssaluber · krakenEPSS 0.24%via NVD
CVE-2026-75627Critical· 9.8PoC
1mo ago

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administra…

▾ Abyssalbastillion-io · BastillionEPSS 0.84%via NVD
CVEs tagged “exploit-available” — page 65 · VulnSea