Tagged “exploit-available”
CVEs tagged exploit-available, newest first.
3547 CVEsRSS
CVE-2026-65591HighPoCn8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
CVE-2016-20096Critical· 9.8PoCLinknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp
Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login e…
CVE-2026-65317High· 8.6PoCVerba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by suppl…
CVE-2026-65056High· 8.2PoCmcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP Filtering
mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only valida…
CVE-2026-65055Medium· 5.3PoCTaiga taiga-back Private Project Member Roster Disclosure via Unauthenticated filters_data Endpoints
Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal workflow configuration of any private project by supplying a project ID to the filters_data…
CVE-2026-65057Critical· 9.3PoCKeep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck
Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthchec…
CVE-2026-65318High· 8.6PoCVerba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled UR…
CVE-2026-65319High· 7.5PoCFeedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/text
Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the aut…
CVE-2026-63764High· 8.6PoCLMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…
LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…
CVE-2026-56819High· 7.5PoCio.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak (CVE-2026-56819)
A flaw was found in Netty, a network application framework. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted HTTP/2 DATA frames to applications that use Netty and have HTTP/2 content decompress…
CVE-2026-58424High· 8.9PoCGitea: Permanent Fork PR Workflow Approval Gate Bypass
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-59891Critical· 9.6PoCCredential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
CVE-2026-63728Medium· 6.3PoCGitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature
Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Spri…
CVE-2026-63769High· 7.7PoCHuginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs
Huginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe inter…
CVE-2026-15588Medium· 5.3PoCA denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticat…
CVE-2026-61736Critical· 9.3PoCLightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
CVE-2026-63828High· 8.4PoCIn the Linux kernel, the following vulnerability has been resolved: apparmor: mediate the implicit connect of TCP fast open sendmsg sendmsg()/sendto() with MSG_FASTOPEN is a combination of connect(2) and write(2): it opens the connecti…
In the Linux kernel, the following vulnerability has been resolved: apparmor: mediate the implicit connect of TCP fast open sendmsg sendmsg()/sendto() with MSG_FASTOPEN is a combination of connect(2) and write(2): it opens the connecti…
CVE-2026-16219Medium· 6.3PoCA flaw has been found in Croogo CMS up to 4.0.7
A flaw has been found in Croogo CMS up to 4.0.7. This affects the function FileManager::isEditable of the file FileManager/src/Utility/FileManager.php of the component Admin File Manager. This manipulation causes path traversal. The atta…
CVE-2026-9147High· 7.8PoCuproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the gen…
CVE-2026-16118High· 7.1PoCA flaw was found in xdgmime
A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data …
CVE-2026-9586Critical· 9.8CISA KEVPoCAn unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into …
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into …
CVE-2026-63030Critical· 9.8CISA KEVPoCWordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…
CVE-2026-60137Medium· 5.9CISA KEVPoCWordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
CVE-2026-9198Critical· 9.8CISA KEVPoCIBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default L…
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default L…
CVE-2026-15013Critical· 9.8PoCThe SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_s…
CVE-2026-47729Medium· 6.5PoCSquid is a caching proxy for the Web
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date i…
CVE-2026-44595Medium· 4.3PoCYamcs is a mission control framework
Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamc…
CVE-2026-55579Critical· 9.8PoCPheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
CVE-2026-59258High· 8.3PoCimmich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions
immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions. Attackers with editor access can dem…
CVE-2026-59255High· 7.1PoCBloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema
BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema. Attackers with valid session tokens…