VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-65400Critical· 9.8CISA KEVPoC
1mo ago

An authentication issue was addressed with improved state management

An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to…

▾ Hadalapple · macosEPSS 1.2%via NVD
CVE-2026-64640NonePoC
1mo ago

Apache Polaris did not consistently validate storage locations supplied during table and view registration.

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration…

▾ Twilightapache-polaris · apache-polarisEPSS 0.49%via OSV
CVE-2026-71554Medium· 5.3PoC
1mo ago

h2 is a pure-Python implementation of a HTTP/2 protocol stack

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the co…

▾ Twilighth2 · h2EPSS 0.42%via NVD
CVE-2026-20200High· 8.8PoC
1mo ago

Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privi…

▾ MidnightCisco · Cisco Unified Computing System (Standalone)EPSS 0.73%via CVEORG
CVE-2026-66747Critical· 9.8PoC
1mo ago

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at b…

▾ AbyssalZbtlink · CPE2801 FirmwareEPSS 0.79%via NVD
CVE-2025-70962High· 7.5PoC
1mo ago

Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control

Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-18907High· 7.5PoC
1mo ago

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

▾ MidnightEPSS 0.91%via NVD
CVE-2026-20303Critical· 9.9PoC
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that …

▾ AbyssalEPSS 0.49%via NVD
CVE-2026-71211High· 7.1PoC
1mo ago

MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim

MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy…

▾ Midnightmlflow · mlflowEPSS 0.29%via NVD
CVE-2026-71209High· 7.5PoC
1mo ago

audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F…

audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F…

▾ MidnightEPSS 1.9%via NVD
CVE-2026-71206High· 8.3PoC
1mo ago

Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database

Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocat…

▾ MidnightEPSS 0.37%via NVD
CVE-2026-71205Medium· 6.5PoC
1mo ago

changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements…

changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements…

▾ TwilightEPSS 0.27%via NVD
CVE-2026-71204Medium· 6.2PoC
1mo ago

changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.

changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.

▾ TwilightEPSS 0.32%via NVD
CVE-2026-71203Medium· 5.3PoC
1mo ago

changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get method …

changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get method …

▾ TwilightEPSS 0.31%via NVD
CVE-2026-70376Critical· 9.6PoC
1mo ago

Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin…

Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin…

▾ AbyssalEPSS 0.20%via NVD
CVE-2026-69703Critical· 9.8PoC
1mo ago

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that i…

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that i…

▾ AbyssalmaximeAmini · Atals-LivreEPSS 0.58%via NVD
CVE-2026-69704Medium· 6.5PoC
1mo ago

Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion helper function

Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion helper function. Attackers can inject malicious SQL synta…

▾ TwilightmaximeAmini · Atals-LivreEPSS 0.33%via NVD
CVE-2026-69098Critical· 9.8PoC
1mo ago

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type_…

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type_…

▾ AbyssalEPSS 0.91%via NVD
CVE-2026-0163Critical· 9.8PoC
1mo ago

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi…

▾ Abyssalgoogle · androidEPSS 0.38%via NVD
CVE-2026-70619High· 8.8PoC
1mo ago

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session auth…

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session auth…

▾ Midnightodysseus-dev · odysseusEPSS 0.66%via NVD
CVE-2026-64564Critical· 9.8PoC⚖ disputed
1mo ago

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport …

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport …

▾ AbyssalRed Hat · Red Hat Enterprise Linux 9EPSS 1.4%via NVD
CVE-2026-64563High· 7.8PoC
1mo ago

In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths when resuming a walk. When iter->walker.tbl is valid, it re-valida…

In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths when resuming a walk. When iter->walker.tbl is valid, it re-valida…

▾ MidnightRed Hat · Red Hat Enterprise Linux 9EPSS 0.12%via NVD
CVE-2026-64561High· 8.8PoC
1mo ago

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU…

▾ MidnightEPSS 0.35%via NVD
CVE-2026-70481Medium· 5.4PoC
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checki…

▾ Twilightopenwebui · open_webuiEPSS 0.43%via NVD
CVE-2026-69263Critical· 9.8PoC
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH…

▾ Abyssalflowiseai · flowiseEPSS 0.66%via NVD
CVE-2026-69251High· 8.8PoC
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig…

▾ Midnightflowiseai · flowiseEPSS 2.7%via NVD
CVE-2026-67599High· 7.2PoC
1mo ago

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated …

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated …

▾ MidnightEPSS 2.4%via NVD
CVE-2026-18718High· 7.0PoC
1mo ago

Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path

Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a vict…

▾ MidnightNational Security Agency · GhidraEPSS 0.17%via NVD
CVE-2026-64827Critical· 9.8PoC
1mo ago

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current…

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current…

▾ AbyssalTelenia Software · TVoxEPSS 0.83%via NVD
CVE-2026-67598High· 7.4PoC
1mo ago

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitra…

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitra…

▾ MidnightEPSS 0.26%via NVD
CVEs tagged “exploit-available” — page 70 · VulnSea