VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-48813LowPoC
1mo ago

Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code

Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Inj…

▾ Twilightflawfinder · flawfinderEPSS 0.44%via NVD
CVE-2026-69116Medium· 6.1PoC
1mo ago

FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives

FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives. Attackers can inject malicious scripts through markdown sources or chat messages that execute in the Electron render…

▾ Twilightxpf0000 · FlyEnvEPSS 0.34%via NVD
CVE-2026-69114Medium· 6.5PoC
1mo ago

Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers that fail to scope message queries to the requested channel

Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers that fail to scope message queries to the requested channel. Authenticated users with MAN…

▾ TwilightSpacebar Server · Spacebar ServerEPSS 0.39%via NVD
CVE-2026-73033Medium· 6.5PoC
1mo ago

Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integrity.lib.php that allows authenticated administrators to delete arbitrary files by supplyi…

Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integrity.lib.php that allows authenticated administrators to delete arbitrary files by supplyi…

▾ TwilightSucuri · sucuri-wordpress-pluginEPSS 0.93%via NVD
CVE-2026-44401Medium· 4.8PoC
1mo ago

Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious JavaScript URIs by supplying unsanitiz…

Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious JavaScript URIs by supplying unsanitiz…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-72733Critical· 9.9PoC
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription builds database restore shell pipelines from the user-controlled databaseName and backupFile fields witho…

▾ AbyssalDokploy · dokployEPSS 0.72%via NVD
CVE-2026-68138High· 7.8PoC
1mo ago

In the Linux kernel, the following vulnerability has been resolved: net/sched: serialize qdisc_rtab_list against concurrent get/put qdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly linked list qdisc_rtab_list and …

In the Linux kernel, the following vulnerability has been resolved: net/sched: serialize qdisc_rtab_list against concurrent get/put qdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly linked list qdisc_rtab_list and …

▾ MidnightRed Hat · Red Hat Enterprise Linux 9EPSS 0.28%via NVD
CVE-2026-18464NonePoC
1mo ago

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated a…

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated a…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-15038NonePoC
1mo ago

The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated att…

The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated att…

▾ TwilightEPSS 0.76%via NVD
CVE-2026-67620High· 7.7PoC
1mo ago

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba …

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba …

▾ MidnightEPSS 0.46%via NVD
CVE-2026-70561Medium· 6.5PoC
1mo ago

TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by supplying an integer attachment ID to the a…

TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by supplying an integer attachment ID to the a…

▾ TwilightTestLinkOpenSourceTRMS · TestLinkEPSS 0.37%via NVD
CVE-2026-17594Medium· 4.9PoC
1mo ago

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scope…

▾ Twilightsonatype · nexus_repository_managerEPSS 0.74%via NVD
CVE-2026-49343Medium· 5.9PoC
1mo ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a resource-exhaustion flaw that leaks bounded throttler slots on error paths. In syncDataT…

▾ Twilightklever-io · klever-goEPSS 0.41%via NVD
CVE-2026-62295High· 7.5PoC
1mo ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arra…

▾ Midnighthapifhir · org.hl7.fhir.coreEPSS 0.49%via NVD
CVE-2026-12261Medium· 6.5PoC
1mo ago

A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning

A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead of packa…

▾ Twilightnltk · nltkEPSS 0.21%via NVD
CVE-2026-47243Critical· 9.2PoC
1mo ago

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the runtime-rs standalone virtio-fs path is vulnerable to a guest-root t…

▾ Abyssalkata-containers · kata-containersEPSS 0.20%via NVD
CVE-2026-61808Critical· 9.8PoC
1mo ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to rea…

▾ AbyssalEPSS 2.5%via NVD
CVE-2026-37171Medium· 5.9PoC
1mo ago

A lack of tenant separation in SuperTokens Inc

A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.

▾ TwilightEPSS 0.31%via NVD
CVE-2026-19264Critical· 9.8PoC
1mo ago

Postiz is an open-source social media scheduling tool

Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that direct…

▾ AbyssalEPSS 1.0%via NVD
CVE-2026-19195High· 7.8PoC
1mo ago

A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39

A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack ne…

▾ MidnightEPSS 0.16%via NVD
CVE-2026-19193High· 7.8PoC
1mo ago

A flaw has been found in Jiangmin Antivirus 21

A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to…

▾ MidnightEPSS 0.16%via NVD
CVE-2026-71851Critical· 9.0PoC
1mo ago

crypto-js is a JavaScript library of crypto standards

crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded …

▾ Abyssalcrypto-js · crypto-jsEPSS 0.55%via NVD
CVE-2026-71557Medium· 6.3PoC
1mo ago

go-git is an extensible git implementation library written in pure Go

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciou…

▾ Twilightgo-git · github.com/go-git/go-git/v5EPSS 0.41%via NVD
CVE-2026-70559High· 7.5PoC
1mo ago

Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no sessio…

Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no sessio…

▾ MidnightEPSS 0.45%via NVD
CVE-2026-5430Critical· 10.0CISA KEVPoC
1mo ago

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leadin…

▾ Hadalwso2 · api_control_planeEPSS 0.59%via NVD
CVE-2026-70556Medium· 4.3PoC
1mo ago

Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint handled by Zotlabs\Module\Authorize::post() that allows unauthenticated attackers to register arbitrary OAuth2 applica…

Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint handled by Zotlabs\Module\Authorize::post() that allows unauthenticated attackers to register arbitrary OAuth2 applica…

▾ TwilightHubzilla · HubzillaEPSS 0.19%via NVD
CVE-2026-70638High· 7.8PoC
1mo ago

llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflo…

llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflo…

▾ Midnightggml · llama.cppEPSS 0.23%via NVD
CVE-2026-53976Critical· 9.1PoC
1mo ago

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorksp…

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorksp…

▾ AbyssalEPSS 2.6%via NVD
CVE-2026-18649High· 7.5PoC
1mo ago

A flaw was found in the GStreamer gst-plugins-good package

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, u…

▾ MidnightRed Hat · gstreamer1-plugins-goodEPSS 0.96%via NVD
CVE-2026-7867High· 7.8PoC
1mo ago

A flaw was found in udisks2

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker…

▾ MidnightRed Hat · udisksEPSS 0.17%via NVD
CVEs tagged “exploit-available” — page 69 · VulnSea