VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-13585High· 8.2PoC
2mo ago

Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive …

Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive …

▾ MidnightASUS · System Control Interface v3EPSS 0.16%via NVD
CVE-2026-15709High· 7.5PoC
2mo ago

A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension

A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer si…

▾ MidnightRed Hat · libsoup3EPSS 0.88%via NVD
CVE-2026-15711High· 7.5PoC
2mo ago

A vulnerability was found in libsoup's WebSocket frame parsing implementation

A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a pa…

▾ MidnightRed Hat · libsoup3EPSS 0.74%via NVD
CVE-2026-12478Medium· 4.8PoC
2mo ago

The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected

The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked fram…

▾ TwilightRed Hat · libsoup3EPSS 0.39%via NVD
CVE-2026-49176High· 7.8PoC
2mo ago

Windows WalletService Elevation of Privilege Vulnerability

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-54992High· 8.4PoC
2mo ago

Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.34%via CVEORG
CVE-2026-54107High· 8.8PoC
2mo ago

Windows Win32k Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.21%via CVEORG
CVE-2026-50338High· 8.2PoC
2mo ago

Azure Spring Apps Elevation of Privilege Vulnerability

Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Spring AppsEPSS 0.52%via CVEORG
CVE-2026-56164Medium· 5.3CISA KEV0dayPoC
2mo ago

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 1.0%via CVEORG
CVE-2026-56155High· 7.8CISA KEV0dayPoC
2mo ago

Active Directory Federation Services Elevation of Privilege Vulnerability

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

▾ AbyssalMicrosoft · Windows 10 Version 1607EPSS 0.35%via CVEORG
CVE-2026-50522Critical· 9.8CISA KEVPoC
2mo ago

Microsoft SharePoint Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

▾ HadalMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 3.0%via CVEORG
CVE-2026-47301High· 8.8PoC
2mo ago

Configuration Manager Elevation of Privilege Vulnerability

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Configuration ManagerEPSS 0.78%via CVEORG
CVE-2026-50343High· 7.8PoC
2mo ago

Microsoft Install Service Elevation of Privilege Vulnerability

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 10 Version 1809EPSS 0.30%via CVEORG
CVE-2026-50416Low· 3.3PoC
2mo ago

Win32k Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.46%via CVEORG
CVE-2026-50369High· 8.8PoC
2mo ago

Windows Remote Desktop Services Elevation of Privilege Vulnerability

Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.70%via CVEORG
CVE-2026-50402High· 7.8PoC
2mo ago

NTFS Elevation of Privilege Vulnerability

Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50657Medium· 4.7PoC
2mo ago

Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability

Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.

▾ TwilightMicrosoft · Microsoft Defender for Endpoint for MacEPSS 0.40%via CVEORG
CVE-2026-54121High· 8.8PoC
2mo ago

Active Directory Certificate Services Elevation of Privilege Vulnerability

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.78%via CVEORG
CVE-2026-55040Critical· 9.1CISA KEVPoC
2mo ago

Microsoft SharePoint Server Security Feature Bypass Vulnerability

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

▾ HadalMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 18%via CVEORG
CVE-2026-56852High· 7.5PoC
2mo ago

Infinite loop on invalid input in golang.org/x/text

Infinite loop on invalid input in golang.org/x/text

▾ Midnightx · golang.org/x/textEPSS 0.47%via OSV
CVE-2026-58644Critical· 9.8CISA KEVPoC
2mo ago

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

▾ Hadalmicrosoft · sharepoint_serverEPSS 16%via NVD
CVE-2026-58635High· 7.8PoC
2mo ago

Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

▾ Midnightmicrosoft · windows_10_1809EPSS 0.32%via NVD
CVE-2026-54433High· 7.2PoC
2mo ago

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by…

▾ Midnightroundcube · webmailEPSS 0.31%via NVD
CVE-2026-34348Medium· 6.5PoC
2mo ago

Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

▾ Twilightmicrosoft · windows_10_1809EPSS 1.00%via NVD
CVE-2026-50131High· 8.6PoC
2mo ago

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

▾ Midnightfedify · @fedify/fedifyEPSS 0.42%via GHSA
CVE-2026-61462High· 8.6PoC
2mo ago

mcp-gitlab Path Traversal via job_id Parameter

mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to e…

▾ Midnightzereight · mcp-gitlabEPSS 0.51%via CVEORG
CVE-2026-61463High· 8.8PoC
2mo ago

Shiori Authenticated Privilege Escalation via PATCH /api/v1/auth/account

Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can escalate to administrator by submitting a crafted P…

▾ Midnightgo-shiori · shioriEPSS 0.52%via CVEORG
CVE-2026-62239Medium· 6.6PoC
2mo ago

FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating symlinks or filter…

FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating symlinks or filter…

▾ TwilightDao-AILab · flash-attentionEPSS 0.16%via NVD
CVE-2026-62240High· 7.4PoC
2mo ago

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the secur…

▾ Midnightcrewai · crewaiEPSS 0.52%via NVD
CVE-2026-60121Critical· 9.8PoC
2mo ago

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument …

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument …

▾ Abyssalvitec · flamingoEPSS 3.3%via NVD
CVEs tagged “exploit-available” — page 74 · VulnSea