VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3547 CVEsRSS

CVE-2026-75898High· 8.5PoC
1mo ago

RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py)

RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template …

▾ Midnightinfiniflow · ragflowEPSS 0.39%via NVD
CVE-2026-53959Medium· 6.5PoC
1mo ago

4gaBoards is a boards system for realtime project management

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account information for every user through GET /api/users and retrieve arbitrary accounts through GET /api…

▾ TwilightEPSS 0.44%via NVD
CVE-2026-50142High· 7.5PoC
1mo ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequen…

▾ MidnightEPSS 0.66%via NVD
CVE-2026-74046Medium· 4.9PoC
1mo ago

Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.py that allows authenticated cluster peers to exhaust memory by supplying a malicious synchronization archive without…

Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.py that allows authenticated cluster peers to exhaust memory by supplying a malicious synchronization archive without…

▾ Twilightwazuh · wazuhEPSS 0.58%via NVD
CVE-2026-74039Medium· 6.5PoC
1mo ago

Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POS…

Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POS…

▾ Twilightwazuh · wazuhEPSS 0.56%via NVD
CVE-2026-74038High· 7.1PoC
1mo ago

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." through the enrollment port

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." through the enrollment port. Attackers …

▾ Midnightwazuh · wazuhEPSS 0.55%via NVD
CVE-2026-75904Low· 3.3PoC
1mo ago

libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp

libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte static arr…

▾ TwilightKonstanty Bialkowski · libmodplugEPSS 0.17%via NVD
CVE-2026-75855High· 8.7PoC
1mo ago

ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, allowing authenticated root users to write and delete arbitrary files outside the configure…

ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, allowing authenticated root users to write and delete arbitrary files outside the configure…

▾ MidnightEPSS 0.55%via NVD
CVE-2026-75827High· 8.8PoC
1mo ago

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config acces…

▾ Midnightgetgrav · getgrav/gravEPSS 0.86%via NVD
CVE-2026-75107Medium· 5.4PoC
1mo ago

Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates

Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates. Attackers with form authoring privileges can inject arbitrary HT…

▾ Twilightgetgrav · gravEPSS 0.24%via NVD
CVE-2026-24301High· 8.8PoC
1mo ago

Microsoft Copilot Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

▾ MidnightMicrosoft · Copilot WebEPSS 4.1%via CVEORG
CVE-2026-18963Critical· 9.1PoC
1mo ago

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the passwo…

▾ AbyssalRed Hat · rhbk/keycloak-operator-bundleEPSS 3.2%via NVD
CVE-2021-43716Critical· 9.8PoC
1mo ago

Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20

Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB.

▾ AbyssalEPSS 0.34%via NVD
CVE-2026-19501High· 8.8PoC
1mo ago

CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute sp…

CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute sp…

▾ MidnightEPSS 0.56%via NVD
CVE-2026-74945Medium· 6.5PoC
1mo ago

Information disclosure in the Graphics: Text component

Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.44%via NVD
CVE-2026-74943Critical· 9.8PoC⚖ disputed
1mo ago

Use-after-free in the Graphics: ImageLib component

Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ Abyssalmozilla · firefoxEPSS 0.61%via NVD
CVE-2026-74936Critical· 9.8PoC⚖ disputed
1mo ago

Use-after-free in the JavaScript: WebAssembly component

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ Abyssalmozilla · firefoxEPSS 0.59%via NVD
CVE-2026-55224HighPoC
1mo ago

MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall

MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall

▾ Midnightmineadmin · mineadmin/mineadminvia GHSA
CVE-2026-17106High· 7.8PoC
1mo ago

github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction (CVE-2026-17106)

A flaw was found in moby/go-archive. The tar extraction routines in the component do not properly restrict filesystem operations to the intended destination directory. An attacker who controls the contents of an archive can exploit this by…

▾ MidnightRed Hat · Red Hat Edge Manager 1.2EPSS 0.44%via CSAF
CVE-2026-63642MediumPoC
1mo ago

MagicMirror² is an open source modular smart mirror platform

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in defaultmodules/newsfeed/node_helper.js accepts the CHECK_ARTICLE_URL notification through the unauthenticated Socket.IO namespace /newsfeed…

▾ Twilightmagicmirror · magicmirrorEPSS 0.50%via NVD
CVE-2026-75104Medium· 5.5PoC
1mo ago

Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory

Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or…

▾ Twilighthuggingface · transformersEPSS 0.29%via NVD
CVE-2026-75110Critical· 9.8PoC
1mo ago

MemOS is a memory operating system for LLMs and AI agents

MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset, the is_internal_reques…

▾ AbyssalMemTensor · MemOSEPSS 0.66%via NVD
CVE-2026-75109High· 7.1PoC
1mo ago

Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers

Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrupt other users' workloads by terminating, pausing, or unpausing tasks they do not own.

▾ Midnightdetermined-ai · determinedEPSS 0.29%via NVD
CVE-2026-75479High· 7.5PoC
1mo ago

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens …

▾ Midnightjeecgboot · jimureportEPSS 0.46%via NVD
CVE-2026-75106Critical· 9.1PoC
1mo ago

OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission

OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full sub…

▾ AbyssalOpnForm · OpnFormEPSS 0.40%via NVD
CVE-2026-75481High· 8.8PoC
1mo ago

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its…

▾ Midnightskypilot-org · skypilotEPSS 0.36%via NVD
CVE-2026-75482High· 7.5PoC
1mo ago

SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassin…

SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassin…

▾ MidnightSWE-agent · SWE-agentEPSS 0.76%via NVD
CVE-2026-75103High· 8.8PoC
1mo ago

Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password

Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and c…

▾ Midnightcrawlab-team · crawlabEPSS 0.43%via NVD
CVE-2026-75108Medium· 5.4PoC
1mo ago

Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe and wake assets they are not granted access to

Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe and wake assets they are not granted access to. Attackers can call these endpoints with …

▾ Twilightnext-terminal · next-terminalEPSS 0.29%via NVD
CVE-2026-71518High· 7.5PoC
1mo ago

Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants

Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute …

▾ MidnightEPSS 0.51%via NVD
CVEs tagged “exploit-available” — page 66 · VulnSea