VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3547 CVEsRSS

CVE-2026-65591HighPoC
2mo ago

n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution

n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution

▾ Midnightn8n · n8nEPSS 0.69%via GHSA
CVE-2016-20096Critical· 9.8PoC
2mo ago

Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login e…

▾ AbyssalKunshi Network Technology Co., Ltd. · Linknat VOS3000EPSS 0.67%via CVEORG
CVE-2026-65317High· 8.6PoC
2mo ago

Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass

Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by suppl…

▾ MidnightWeaviate · VerbaEPSS 0.64%via CVEORG
CVE-2026-65056High· 8.2PoC
2mo ago

mcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP Filtering

mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only valida…

▾ Midnightmzxrai · mcp-webresearchEPSS 0.41%via CVEORG
CVE-2026-65055Medium· 5.3PoC
2mo ago

Taiga taiga-back Private Project Member Roster Disclosure via Unauthenticated filters_data Endpoints

Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal workflow configuration of any private project by supplying a project ID to the filters_data…

▾ TwilightTaiga · taiga-backEPSS 0.43%via CVEORG
CVE-2026-65057Critical· 9.3PoC
2mo ago

Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthchec…

▾ Abyssalkeephq · keepEPSS 0.43%via CVEORG
CVE-2026-65318High· 8.6PoC
2mo ago

Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader

Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled UR…

▾ MidnightWeaviate · VerbaEPSS 0.60%via CVEORG
CVE-2026-65319High· 7.5PoC
2mo ago

Feedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/text

Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the aut…

▾ MidnightFeedbin · FeedbinEPSS 0.51%via CVEORG
CVE-2026-63764High· 8.6PoC
2mo ago

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…

▾ Midnightinternlm · lmdeployEPSS 0.51%via NVD
CVE-2026-56819High· 7.5PoC
2mo ago

io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak (CVE-2026-56819)

A flaw was found in Netty, a network application framework. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted HTTP/2 DATA frames to applications that use Netty and have HTTP/2 content decompress…

▾ MidnightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.66%via CSAF
CVE-2026-58424High· 8.9PoC
2mo ago

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.37%via GHSA
CVE-2026-59891Critical· 9.6PoC
2mo ago

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

▾ Abyssalsigstore · @sigstore/ociEPSS 0.47%via GHSA
CVE-2026-63728Medium· 6.3PoC
2mo ago

Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature

Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Spri…

▾ Twilightgitleaks · gitleaksEPSS 0.21%via CVEORG
CVE-2026-63769High· 7.7PoC
2mo ago

Huginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs

Huginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe inter…

▾ Midnighthuginn · huginnEPSS 0.41%via NVD
CVE-2026-15588Medium· 5.3PoC
2mo ago

A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib

A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticat…

▾ TwilightRed Hat · glib2EPSS 0.48%via NVD
CVE-2026-61736Critical· 9.3PoC
2mo ago

LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests

LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests

▾ Abyssallightrag-hku · lightrag-hkuEPSS 1.4%via GHSA
CVE-2026-63828High· 8.4PoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: apparmor: mediate the implicit connect of TCP fast open sendmsg sendmsg()/sendto() with MSG_FASTOPEN is a combination of connect(2) and write(2): it opens the connecti…

In the Linux kernel, the following vulnerability has been resolved: apparmor: mediate the implicit connect of TCP fast open sendmsg sendmsg()/sendto() with MSG_FASTOPEN is a combination of connect(2) and write(2): it opens the connecti…

▾ MidnightEPSS 0.17%via NVD
CVE-2026-16219Medium· 6.3PoC
2mo ago

A flaw has been found in Croogo CMS up to 4.0.7

A flaw has been found in Croogo CMS up to 4.0.7. This affects the function FileManager::isEditable of the file FileManager/src/Utility/FileManager.php of the component Admin File Manager. This manipulation causes path traversal. The atta…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-9147High· 7.8PoC
2mo ago

uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime

uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the gen…

▾ MidnightEPSS 0.22%via NVD
CVE-2026-16118High· 7.1PoC
2mo ago

A flaw was found in xdgmime

A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data …

▾ Midnightxdg · xdgmimeEPSS 0.27%via NVD
CVE-2026-9586Critical· 9.8CISA KEVPoC
2mo ago

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into …

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into …

▾ Hadalsangoma · switchvoxEPSS 19%via NVD
CVE-2026-63030Critical· 9.8CISA KEVPoC
2mo ago

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…

▾ HadalEPSS 10%via NVD
CVE-2026-60137Medium· 5.9CISA KEVPoC
2mo ago

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

▾ MidnightEPSS 5.9%via NVD
CVE-2026-9198Critical· 9.8CISA KEVPoC
2mo ago

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default L…

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default L…

▾ HadalEPSS 29%via NVD
CVE-2026-15013Critical· 9.8PoC
2mo ago

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_s…

▾ AbyssalEPSS 1.5%via NVD
CVE-2026-47729Medium· 6.5PoC
2mo ago

Squid is a caching proxy for the Web

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date i…

▾ Twilightsquid-cache · squidEPSS 2.4%via NVD
CVE-2026-44595Medium· 4.3PoC
2mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamc…

▾ Twilightspaceapplications · yamcsEPSS 1.1%via NVD
CVE-2026-55579Critical· 9.8PoC
2mo ago

Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise

Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise

▾ Abyssalpheditor · pheditor/pheditorEPSS 0.79%via GHSA
CVE-2026-59258High· 8.3PoC
2mo ago

immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions

immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions. Attackers with editor access can dem…

▾ Midnightimmich-app · immichEPSS 0.46%via NVD
CVE-2026-59255High· 7.1PoC
2mo ago

BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema

BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema. Attackers with valid session tokens…

▾ MidnightSpecterOps · BloodHoundEPSS 0.44%via NVD
CVEs tagged “exploit-available” — page 73 · VulnSea