VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-66418Critical· 9.3PoC
2mo ago

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, whi…

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, whi…

▾ Abyssaltugcantopaloglu · openclaw-dashboardEPSS 0.63%via NVD
CVE-2026-47858High· 8.0PoC
2mo ago

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclips…

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclips…

▾ Midnightbroadcom · spring_toolsEPSS 0.33%via NVD
CVE-2026-66066CriticalPoC
2mo ago

Action Pack is a framework for handling and responding to web requests

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload …

▾ Abyssalactivestorage · activestorageEPSS 2.1%via NVD
CVE-2026-67595High· 8.1PoC
2mo ago

VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser th…

▾ Midnightwebreinvent · vaahcmsEPSS 0.76%via CVEORG
CVE-2026-59243Critical· 9.8PoC
2mo ago

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and lo…

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and lo…

▾ Abyssalapache · apache-airflow-providers-fabEPSS 0.64%via NVD
CVE-2026-64560High· 7.8PoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sy…

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sy…

▾ MidnightLinux · LinuxEPSS 0.18%via NVD
CVE-2026-14266High· 7.80dayPoC
2mo ago

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this …

▾ Abyssal7-zip · 7-zipEPSS 0.74%via NVD
CVE-2026-20316Medium· 5.3CISA KEV0dayPoC
2mo ago

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within…

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within…

▾ Midnightcisco · secure_firewall_management_centerEPSS 35%via NVD
CVE-2026-66748High· 8.8PoC
2mo ago

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the…

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the…

▾ MidnightEPSS 1.1%via NVD
CVE-2026-66412Medium· 6.5PoC
2mo ago

Leantime all versions prior to and 3.6.2 Broken Access Control via tickets.getMilestone JSON-RPC

Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by supplying arbitrary integer milestone IDs to the tickets.getMileston…

▾ TwilightLeantime · LeantimeEPSS 0.41%via CVEORG
CVE-2026-63077Critical· 9.8CISA KEVPoC
2mo ago

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

▾ HadalJetBrains · TeamCityEPSS 9.8%via CVEORG
CVE-2026-66396High· 8.4PoC
2mo ago

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor pe…

▾ Midnightsiyuan-note · siyuanEPSS 0.54%via NVD
CVE-2026-66395Critical· 9.6PoC
2mo ago

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HT…

▾ Abyssalsiyuan-note · siyuanEPSS 0.56%via NVD
CVE-2026-43760High· 8.6PoC
2mo ago

An access issue was addressed with improved access restrictions

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may be able to access user-sensitive data.

▾ Midnightapple · macosEPSS 0.41%via NVD
CVE-2026-42016High· 8.1CISA KEVPoC
2mo ago

Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

▾ Abyssaljfrog · artifactoryEPSS 8.6%via CVEORG
CVE-2026-64531High· 7.8PoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: op…

▾ MidnightEPSS 0.19%via NVD
CVE-2026-63720High· 7.5PoC
2mo ago

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded n…

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded n…

▾ MidnightEPSS 0.74%via NVD
CVE-2026-66012Critical· 10.0PoC
2mo ago

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, i…

▾ Abyssalsiyuan-note · siyuanEPSS 0.76%via NVD
CVE-2026-66010Medium· 6.1PoC
2mo ago

DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING

DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attri…

▾ Twilightcure53 · DOMPurifyEPSS 0.30%via CVEORG
CVE-2026-66005Medium· 6.3PoC
2mo ago

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-…

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-…

▾ Twilightjanhq · janEPSS 0.33%via NVD
CVE-2026-63765High· 8.2PoC
2mo ago

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing au…

▾ Midnightchatwoot · chatwootEPSS 0.70%via NVD
CVE-2026-65606Critical· 9.6PoC
2mo ago

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts t…

▾ Abyssalsiyuan-note · siyuanEPSS 0.79%via NVD
CVE-2026-65605Critical· 9.6PoC
2mo ago

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied wh…

▾ Abyssalsiyuan-note · siyuanEPSS 0.79%via NVD
CVE-2026-65919High· 7.5PoC
2mo ago

Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation

Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. A…

▾ Midnightmeshery · mesheryEPSS 2.1%via NVD
CVE-2026-15630Critical· 9.9PoC
2mo ago

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

▾ AbyssalCasdoor · CasdoorEPSS 0.34%via NVD
CVE-2026-65918High· 7.1PoC
2mo ago

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or trunc…

▾ Midnightlinuxfoundation · torchvisionEPSS 0.45%via NVD
CVE-2026-64600High· 7.8PoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapp…

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapp…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS E4S (v.9.4)EPSS 0.16%via NVD
CVE-2026-65013High· 8.8PoC
2mo ago

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API…

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API…

▾ Midnightonlook · repoEPSS 0.52%via NVD
CVE-2026-16232Critical· 9.1CISA KEV0dayPoC
2mo ago

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successfu…

▾ Hadalcheckpoint · multi-domain_security_managementEPSS 78%via NVD
CVE-2026-59941MediumPoC
2mo ago

Dompdf: Uncontrolled resource consumption based on declared BMP dimensions

Dompdf: Uncontrolled resource consumption based on declared BMP dimensions

▾ Twilightdompdf · dompdf/dompdfEPSS 0.64%via GHSA
CVEs tagged “exploit-available” — page 72 · VulnSea