VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3547 CVEsRSS

CVE-2026-41452Critical· 9.8PoC
1mo ago

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Re…

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Re…

▾ AbyssalEPSS 3.7%via NVD
CVE-2026-8794NonePoC
1mo ago

PaperCut NG/MF contains an observable timing discrepancy in its authentication component

PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts…

▾ TwilightEPSS 0.68%via NVD
CVE-2026-8793NonePoC
1mo ago

PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component

PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks …

▾ TwilightEPSS 0.68%via NVD
CVE-2026-52102Critical· 9.8PoC
1mo ago

An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.

An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.

▾ AbyssalEPSS 2.9%via NVD
CVE-2026-69243High· 7.0PoC
1mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an attack…

▾ MidnightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.44%via NVD
CVE-2026-18577NoneCISA KEV0dayPoC
1mo ago

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

▾ TwilightEPSS 15%via NVD
CVE-2026-65321Critical· 9.8PoC
1mo ago

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS state…

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS state…

▾ AbyssalEPSS 0.77%via NVD
CVE-2026-16540NonePoC
1mo ago

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments a…

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments a…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-9335Medium· 6.5PoC
1mo ago

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` functions bypass the `safe_g…

▾ TwilightEPSS 0.77%via NVD
CVE-2026-18556NoneCISA KEVPoC
1mo ago

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

▾ TwilightEPSS 7.9%via NVD
CVE-2026-67340High· 7.2PoC
1mo ago

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permi…

▾ MidnightEPSS 0.92%via NVD
CVE-2026-15964Critical· 9.8PoC
1mo ago

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_aj…

▾ AbyssalEPSS 0.89%via NVD
CVE-2026-14840NonePoC
1mo ago

The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to byp…

The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to byp…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-13158NonePoC
1mo ago

The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non…

The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-13157NonePoC
1mo ago

The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-su…

The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-su…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-67607Medium· 5.9PoC
1mo ago

LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftpserv.c that allows remote unauthenticated attackers to destabilize or crash the daemon b…

LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftpserv.c that allows remote unauthenticated attackers to destabilize or crash the daemon b…

▾ Twilighthfiref0x · LightFTPEPSS 0.40%via NVD
CVE-2026-62999High· 7.5PoC
1mo ago

Copier is a library and CLI app for rendering project templates

Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an…

▾ Midnightcopier-org · copierEPSS 0.44%via NVD
CVE-2026-68771Critical· 9.8PoC
1mo ago

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserial…

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserial…

▾ AbyssalComfy-Org · ComfyUIEPSS 1.1%via NVD
CVE-2026-68770Critical· 9.8PoC
1mo ago

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, wher…

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, wher…

▾ AbyssalHugging Face · sentence-transformersEPSS 0.91%via NVD
CVE-2026-58048NonePoC
1mo ago

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

▾ TwilightEPSS 0.56%via NVD
CVE-2026-17566Critical· 9.9PoC
1mo ago

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the…

▾ AbyssalEPSS 0.67%via NVD
CVE-2026-17351Critical· 9.0PoC
1mo ago

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TR…

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TR…

▾ AbyssalEPSS 0.48%via NVD
CVE-2026-63223Critical· 9.8PoC
1mo ago

CodeIgniter is a PHP full-stack web framework

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when a…

▾ AbyssalEPSS 0.80%via NVD
CVE-2026-52887Critical· 10.0PoC
1mo ago

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

▾ Abyssalnocobase · @nocobase/plugin-notification-in-app-messageEPSS 0.89%via GHSA
CVE-2026-57862High· 8.5PoC
2mo ago

Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation

Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplying hexadecimal IP address notation in user-controlled URLs. Attackers can submit hexadeci…

▾ MidnightKanboard · KanboardEPSS 0.41%via CVEORG
CVE-2026-66414Medium· 6.1PoC
2mo ago

Leantime Open Redirect in Login Controller via redirectUrl Parameter

Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to redirect authenticated users to arbitrary external sites by manipulating the redirectUrl POST parameter. Attackers ca…

▾ TwilightLeantime · LeantimeEPSS 0.34%via CVEORG
CVE-2026-66421Critical· 9.3PoC
2mo ago

OpenClaw Dashboard Stored XSS via lastMessage Session Field

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript me…

▾ Abyssaltugcantopaloglu · openclaw-dashboardEPSS 0.63%via CVEORG
CVE-2026-59310Critical· 9.8CISA KEVPoC
2mo ago

vCenter directory-traversal vulnerability

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

▾ HadalVMware · Cloud FoundationEPSS 2.6%via CVEORG
CVE-2026-68503Critical· 9.8PoC
2mo ago

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc…

▾ Abyssalgrisuno · LazyOwnEPSS 0.75%via NVD
CVE-2026-44613Medium· 6.1PoC
2mo ago

Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin

Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user …

▾ Twilightapache · zeppelinEPSS 0.39%via NVD
CVEs tagged “exploit-available” — page 71 · VulnSea