VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3116 CVEsRSS

CVE-2026-94138Medium· 6.6PoC
2d ago

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation of the argument mac result…

TwilightChengdu Feiyuxing Technology · Feiyu Star RouterEPSS 2.1%via NVD
CVE-2026-94129High· 8.8PoC
2d ago

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results…

MidnightBioStar · VALKYRIE AURORAEPSS 0.12%via NVD
CVE-2026-94128High· 8.8PoC
2d ago

A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500

A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-…

MidnightBioStar · VIVID LED DJEPSS 0.13%via NVD
CVE-2026-94110High· 7.3PoC
2d ago

A security vulnerability has been detected in QCMS up to 6.0.6

A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulation of the argument ID leads to sql in…

MidnightEPSS 0.26%via NVD
CVE-2026-94101Critical· 9.9PoC
2d ago

A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246

A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It…

AbyssalNetcore · NBR200V2EPSS 0.45%via NVD
CVE-2026-94103Medium· 4.7PoC
2d ago

A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2

A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2. This impacts the function eval of the file roocms/site_pagePHP.php of the component Frontend Rendering. Such manipulation of the argument content leads to code injection.…

TwilightEPSS 0.24%via NVD
CVE-2026-94100Critical· 9.9PoC
2d ago

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX…

AbyssalNetcore · NBR200V2EPSS 0.46%via NVD
CVE-2026-94099Critical· 9.9PoC
2d ago

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results…

AbyssalNetcore · NBR200V2EPSS 1.7%via NVD
CVE-2026-94098Critical· 9.1PoC
2d ago

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING…

AbyssalNetcore · NBR200V2EPSS 2.4%via NVD
CVE-2026-94096Critical· 9.9PoC
2d ago

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4…

AbyssalNetcore · NBR200V2EPSS 1.7%via NVD
CVE-2026-94095Critical· 9.9PoC
2d ago

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the a…

AbyssalNetcore · NBR200V2EPSS 1.7%via NVD
CVE-2026-55071High· 8.4PoC
2d ago

MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design

MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled input directly into a Stata command stri…

MidnightSepineTam · mcp-for-stataEPSS 0.42%via NVD
CVE-2026-94094Medium· 4.3PoC
3d ago

A flaw has been found in OpenClaw up to 2026.9.5

A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the component Canvas Host Route. Executing a manipulation can lead to denial of servic…

TwilightEPSS 0.27%via NVD
CVE-2026-94093Medium· 6.3PoC
3d ago

A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0

A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/load_replay_buffer/VecNormalize.load of the file save_util.py. Such manipulation leads to deserialization. It is possi…

TwilightDLR-RM · stable-baselines3EPSS 0.26%via NVD
CVE-2026-94091Medium· 5.5PoC
3d ago

A weakness has been identified in piskvorky gensim up to 4.4.0

A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Loader. This manipulation of the argument fname causes deserialization. It is po…

Twilightpiskvorky · gensimEPSS 0.19%via NVD
CVE-2026-94089Critical· 10.0PoC
3d ago

A vulnerability was determined in D-Link DIR-868L 2.01b05

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lea…

AbyssalD-Link · DIR-868LEPSS 0.98%via NVD
CVE-2026-94051Medium· 6.3PoC
3d ago

A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d

A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNode of the file local_servers/pdf-tools-mcp/pdf_tools_mcp/server.py of the compo…

Twilight0717376 · cowork_benchEPSS 0.21%via NVD
CVE-2026-94049Medium· 4.3PoC
3d ago

A flaw has been found in 06ketan slideshot up to 4.4.0

A flaw has been found in 06ketan slideshot up to 4.4.0. This impacts the function render_slides of the file packages/cli/src/renderer.ts. This manipulation of the argument htmlPath causes path traversal. The attack is possible to be carr…

Twilight06ketan · slideshotEPSS 0.32%via NVD
CVE-2026-94048Medium· 6.6PoC
3d ago

A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0

A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege man…

TwilightCodeAstro · QR Code Attendance Management SystemEPSS 0.23%via NVD
CVE-2026-94047Medium· 6.3PoC
3d ago

A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32

A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32. The impacted element is the function importTemplate of the file src/services/templateService.ts of the component Template Import Endpoint. The manipulation lea…

Twilightsamanhappy · MCPHubEPSS 0.41%via NVD
CVE-2026-94046Medium· 4.3PoC
3d ago

A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8

A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8. The affected element is the function get_file_snippet of the file getFileSnippet.ts of the component MCP Tool. Executing a manipulation of the argument projectRootPat…

Twilight0215AndrewFeng · ACE-MCPEPSS 0.45%via NVD
CVE-2026-94043Medium· 5.3PoC
3d ago

A vulnerability was determined in Free5GC up to 4.2.3

A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go of the component Gmm Handler. This manipulation causes race condition. Th…

TwilightEPSS 0.34%via NVD
CVE-2026-94042Medium· 6.3PoC
3d ago

A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c

A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/add_table.php. The manipulation of the argument table/membe…

TwilightAdithyaYelloju · Restaurant Management SystemEPSS 0.19%via NVD
CVE-2026-88854Critical· 9.3PoC
3d ago

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with …

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with …

AbyssalOrdaSoft.com · com_osgallery_lightEPSS 0.34%via NVD
CVE-2026-94041Medium· 6.3PoC
3d ago

A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c

A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some unknown functionality of the file admin/add_menu.php. The manipulation of the ar…

TwilightAdithyaYelloju · Restaurant-Management-SystemEPSS 0.20%via NVD
CVE-2026-94038High· 7.3PoC
3d ago

A security vulnerability has been detected in NonceGeek dim-sum-app

A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the file deno/main.tsx of the component Deno Backend. Such manipulation of the argument supabase_url leads to server-si…

MidnightNonceGeek · dim-sum-appEPSS 0.30%via NVD
CVE-2026-94037Medium· 4.3PoC
3d ago

A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405

A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405. This affects the function ControlFlowNode of the file main.py of the component analyze_csv_data MCP tool. This manipulation of…

Twilight00Kisumi00 · mcp-file-analyzerEPSS 0.33%via NVD
CVE-2026-94036High· 8.8PoC
3d ago

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results…

MidnightD-Link · DIR-X1860EPSS 0.47%via NVD
CVE-2026-94033Low· 3.5PoC
3d ago

A vulnerability has been found in SourceCodester Drug Recommendation System 1.0

A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of the file /drug_recommender/Admin/add_user of the component User Management. Such manipulation of the argument txt…

TwilightSourceCodester · Drug Recommendation SystemEPSS 0.20%via NVD
CVE-2026-94032Medium· 6.3PoC
3d ago

A flaw has been found in itsourcecode Leave Management System 1.0

A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part of the file /module/department/index.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack re…

Twilightitsourcecode · Leave Management SystemEPSS 0.20%via NVD
CVEs tagged “exploit-available” — page 7 · VulnSea