VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3547 CVEsRSS

CVE-2026-57830NonePoC
2mo ago

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

▾ TwilightEPSS 0.50%via NVD
CVE-2026-57829NonePoC
2mo ago

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-15502Medium· 6.3PoC
2mo ago

A vulnerability was detected in AojiaoZero Antaris 1.0

A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the function _rewardPurchase of the file /ipn.php of the component PayPal IPN Payment Handler. The manipulation of the argument item_number results in sql injection. Th…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-61876High· 8.8PoC
2mo ago

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the…

▾ MidnightEPSS 1.3%via NVD
CVE-2026-56336Medium· 5.3PoC
2mo ago

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. Attackers can enumerate email domains to build mappings…

▾ TwilightCapgo · CapgoEPSS 0.34%via NVD
CVE-2026-56281Low· 3.8PoC
2mo ago

Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request body and interpolated directly into Cloudflare Analytics Engine SQL…

Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request body and interpolated directly into Cloudflare Analytics Engine SQL…

▾ TwilightCapgo · CapgoEPSS 0.33%via NVD
CVE-2026-61447Critical· 10.0PoC
2mo ago

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LL…

▾ AbyssalEPSS 2.5%via NVD
CVE-2026-57827NonePoC
2mo ago

The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

▾ TwilightEPSS 2.3%via NVD
CVE-2026-9282High· 7.5PoC
2mo ago

The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function

The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrar…

▾ MidnightEPSS 2.9%via NVD
CVE-2026-3576High· 7.2PoC
2mo ago

The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0

The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. The ulap.php file acts as an AJAX proxy and is directly acc…

▾ MidnightEPSS 8.8%via NVD
CVE-2026-61459Critical· 9.8PoC
2mo ago

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying re…

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying re…

▾ Abyssalsuyogs · mcp-server-kubernetesEPSS 2.4%via NVD
CVE-2026-49844Medium· 6.3PoC
2mo ago

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.…

▾ TwilightApache Software Foundation · org.apache.logging.log4j:log4j-apiEPSS 0.81%via NVD
CVE-2026-13233NonePoC
2mo ago

Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery

Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issue affects OpenAI Provider versions: from 0.0.0 to 1.1.1, from 1.2.0 to 1.2.2.

▾ TwilightEPSS 0.21%via NVD
CVE-2026-10768NonePoC
2mo ago

Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing

Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.

▾ TwilightEPSS 2.1%via NVD
CVE-2026-57219NonePoC
2mo ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secre…

▾ TwilightEPSS 2.8%via NVD
CVE-2026-57850High· 8.3PoC
2mo ago

RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options …

RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options …

▾ MidnightEPSS 0.50%via NVD
CVE-2026-55781NonePoC
2mo ago

NanaZip is the 7-Zip derivative intended for the modern Windows experience

NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS image handler in NanaZip.Codecs.Archive.Ufs.cpp validates the superblock block size only against the MINBSIZE lower bo…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-21055NonePoC
2mo ago

Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege.

Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege.

▾ TwilightEPSS 0.17%via NVD
CVE-2026-54066High· 7.5PoC
2mo ago

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 2.4%via GHSA
CVE-2026-54069CriticalPoC
2mo ago

SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

▾ Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.58%via GHSA
CVE-2026-54088CriticalPoC
2mo ago

File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)

File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)

▾ Abyssalfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.76%via GHSA
CVE-2026-59148High· 8.8PoC
2mo ago

Mockoon provides way to design and run mock APIs

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runti…

▾ Midnightmockoon · mockoonEPSS 0.26%via NVD
CVE-2026-56292High· 7.5PoC
2mo ago

A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered

A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database access and data leakage.

▾ Midnightacymailing · acymailingEPSS 1.4%via NVD
CVE-2026-56291Critical· 9.8CISA KEV0dayPoC
2mo ago

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

▾ Hadalbalbooa · formsEPSS 15%via NVD
CVE-2026-59702Critical· 9.3PoC
2mo ago

repomix - Server-Side Request Forgery via Unvalidated Repository URLs in POST /api/pack

repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests. The endpoint fails to properly validate http://, https://, and file://…

▾ Abyssalrepomix · repomixEPSS 0.44%via CVEORG
CVE-2026-59703High· 7.5PoC
2mo ago

repomix - Local File Inclusion via file:// URL Scheme in Git Clone Endpoint

repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to read arbitrary local git repositories. The isValidRemoteValue function in src/core/git/gitRemoteParse.ts fails to bl…

▾ Midnightrepomix · repomixEPSS 0.51%via CVEORG
CVE-2026-59262Medium· 6.5PoC
2mo ago

AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace members to retrieve restricted content timelines

AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace members to retrieve restricted content timelines. Attackers can supply arbitrary document GUID…

▾ Twilightaffine · monorepoEPSS 0.41%via NVD
CVE-2026-31309Critical· 9.8PoC
2mo ago

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a c…

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a c…

▾ AbyssalEPSS 0.62%via NVD
CVE-2026-59822High· 8.2CISA KEVPoC
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAut…

▾ Abyssallitellm · litellmEPSS 0.84%via NVD
CVE-2026-57851High· 7.8PoC
2mo ago

MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers

MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by…

▾ MidnightMicro-Star International (MSI) · KernCoreLib64.sysEPSS 0.17%via CVEORG
CVEs tagged “exploit-available” — page 75 · VulnSea