VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3547 CVEsRSS

CVE-2026-14669High· 8.8PoC
1mo ago

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreS…

▾ Midnightpostgresql · postgresqlEPSS 0.66%via NVD
CVE-2026-14662High· 8.8PoC
1mo ago

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary …

▾ Midnightpostgresql · postgresqlEPSS 0.46%via NVD
CVE-2026-73570High· 8.9CISA KEVPoC
1mo ago

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP …

▾ Abyssalsynacor · zimbra_collaboration_suiteEPSS 12%via NVD
CVE-2026-73519Critical· 9.8PoC
1mo ago

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this va…

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this va…

▾ AbyssalEPSS 1.2%via NVD
CVE-2026-57858High· 8.9PoC
1mo ago

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analyt…

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analyt…

▾ MidnightEPSS 0.37%via NVD
CVE-2026-73296Critical· 9.4PoC
1mo ago

Microsoft UFO open-source framework for intelligent automation across devices and platforms

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed…

▾ AbyssalEPSS 3.7%via NVD
CVE-2026-47717High· 7.5PoC
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabl…

▾ MidnightEPSS 1.4%via NVD
CVE-2026-42018High· 7.5CISA KEVPoC
1mo ago

Anonymous user token generation exposure in JFrog Artifactory

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

▾ Abyssaljfrog · artifactoryEPSS 9.8%via CVEORG
CVE-2026-63297Critical· 9.9PoC
1mo ago

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a tar…

▾ Abyssalcanonical · lxdEPSS 0.34%via NVD
CVE-2026-47227Medium· 6.5PoC
1mo ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, …) corresponds to a module the actor administers. The follow-up "is this specific categor…

▾ TwilightAdmidio · admidioEPSS 0.33%via NVD
CVE-2026-73292High· 8.3PoC
1mo ago

Semaphore UI is a web interface for managing DevOps tools

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-pa…

▾ Midnightsemaphoreui · github.com/semaphoreui/semaphoreEPSS 0.23%via NVD
CVE-2026-54917HighPoC
1mo ago

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

▾ Midnightseaweedfs · github.com/seaweedfs/seaweedfsEPSS 1.6%via OSV
CVE-2026-72744Medium· 6.2PoC
1mo ago

Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the development server's Chrome DevTools workspace endpoint (GET /.well-known/appspecific/com.chrome.devtools.json)

Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the development server's Chrome DevTools workspace endpoint (GET /.well-known/appspecific/com.chrome.devtools.json). The …

▾ TwilightEPSS 0.18%via NVD
CVE-2026-73034Critical· 9.8PoC
1mo ago

DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Pyt…

DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Pyt…

▾ AbyssalEPSS 5.7%via NVD
CVE-2026-71362Critical· 9.1CISA KEVPoC
1mo ago

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue do…

▾ Hadaladobe · commerceEPSS 88%via NVD
CVE-2026-48046Critical· 9.3PoC
1mo ago

Streambert is a cross-platform Electron Desktop App to stream and download video content

Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process d…

▾ Abyssaltruelockmc · streambertEPSS 0.36%via NVD
CVE-2026-20349High· 8.6CISA KEV0dayPoC
1mo ago

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause th…

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause th…

▾ Abyssalcisco · adaptive_security_appliance_softwareEPSS 1.0%via NVD
CVE-2026-73072High· 7.8PoC
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_S…

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.13%via NVD
CVE-2026-46670Critical· 9.8PoC
1mo ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrar…

▾ AbyssalEPSS 2.0%via NVD
CVE-2026-63520High· 8.1PoC
1mo ago

Microsoft SharePoint Server Remote Code Execution Vulnerability

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.96%via CVEORG
CVE-2026-62737High· 7.8PoC
1mo ago

Windows Kernel Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 11 Version 24H2EPSS 0.33%via CVEORG
CVE-2026-62735High· 7.8PoC
1mo ago

Windows HTTP.sys Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-62878Critical· 9.8PoC
1mo ago

Windows DNS Server Remote Code Execution Vulnerability

Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

▾ AbyssalMicrosoft · Windows Server 2012EPSS 0.97%via CVEORG
CVE-2026-65660High· 8.8CISA KEVPoC
1mo ago

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ Abyssalmicrosoft · sharepoint_serverEPSS 2.1%via NVD
CVE-2026-68820High· 7.0CISA KEV0dayPoC
1mo ago

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

▾ AbyssalMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-66804High· 7.8PoC
1mo ago

Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 10 Version 22H2EPSS 0.30%via CVEORG
CVE-2026-62911High· 8.0PoC
1mo ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.69%via CVEORG
CVE-2026-71217High· 7.5PoC
1mo ago

A flaw was found in iperf3

A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This im…

▾ MidnightEPSS 0.82%via NVD
CVE-2026-54984High· 7.8PoC
1mo ago

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.47%via NVD
CVE-2026-49179High· 8.8PoC
1mo ago

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.86%via NVD
CVEs tagged “exploit-available” — page 68 · VulnSea