VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3547 CVEsRSS

CVE-2026-59706Critical· 9.3PoC
2mo ago

mem0 - Unauthenticated Config API Exposure and SSRF via ollama_base_url

mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. Unauthenticated attackers can retrieve stored secrets like …

▾ Abyssalmem0 · mem0EPSS 0.44%via CVEORG
CVE-2026-59705Critical· 9.8PoC
2mo ago

mem0 - OpenMemory API Unauthenticated Access via Memory Endpoints

mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arbitrary user memories by accessing API routers registered without authentication middlewa…

▾ Abyssalmem0 · mem0EPSS 0.80%via CVEORG
CVE-2026-59704High· 7.1PoC
2mo ago

Cap - Missing Access Control in Video AI Metadata Endpoint

Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summaries, and chapters. Authenticated attackers can supply arbitrary video IDs to read sensitiv…

▾ MidnightCap · CapEPSS 0.37%via CVEORG
CVE-2026-59707High· 8.6PoC
2mo ago

LocalAI - Server-Side Request Forgery via POST /models/apply

LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs. The endpoint passes unsanitized gallery URL fields directly to galle…

▾ MidnightLocalAI · LocalAIEPSS 0.48%via CVEORG
CVE-2026-59709Medium· 4.3PoC
2mo ago

Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags

Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attac…

▾ TwilightGhostfolio · GhostfolioEPSS 0.34%via NVD
CVE-2026-56812High· 7.5PoC
2mo ago

Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every…

Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every…

▾ Midnightphoenixframework · phoenixEPSS 0.80%via NVD
CVE-2026-12948NonePoC
2mo ago

A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system c…

A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system c…

▾ TwilightEPSS 0.42%via NVD
CVE-2026-12352Medium· 5.9PoC
2mo ago

This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.

This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.

▾ TwilightEPSS 0.40%via NVD
CVE-2026-14628Medium· 5.3PoC
2mo ago

A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16

A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. Performing a manipulation results in path tr…

▾ TwilightEPSS 0.77%via NVD
CVE-2026-53362NoneCISA KEVPoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloc…

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloc…

▾ TwilightEPSS 0.71%via NVD
CVE-2026-53361High· 7.8PoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). Igor Ushakov reported that unix_gc() could run with gc_in_progress being false if the work is scheduled while running…

In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). Igor Ushakov reported that unix_gc() could run with gc_in_progress being false if the work is scheduled while running…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.23%via NVD
CVE-2026-53360NonePoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use As per the GHCB spec, when using GHCB v2+ require the software scratch area to reside in the GHCB's shared…

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use As per the GHCB spec, when using GHCB v2+ require the software scratch area to reside in the GHCB's shared…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-53359High· 7.8PoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a sha…

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a sha…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS E4S (v.9.4)EPSS 0.17%via NVD
CVE-2026-54424High· 8.4PoC
2mo ago

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. …

▾ MidnightEPSS 0.18%via NVD
CVE-2026-12960Medium· 6.0PoC
2mo ago

An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Secur…

An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Secur…

▾ TwilightASUS · Router appEPSS 0.16%via NVD
CVE-2026-58289Critical· 9.0PoC
2mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ AbyssalMicrosoft · Microsoft Edge (Chromium-based)EPSS 2.0%via CVEORG
CVE-2026-27771High· 8.2PoC
2mo ago

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

▾ MidnightEPSS 1.4%via NVD
CVE-2026-22874Critical· 9.6PoC
2mo ago

Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.

Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.

▾ AbyssalEPSS 0.46%via NVD
CVE-2026-20896Critical· 9.8PoC
2mo ago

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.

▾ AbyssalEPSS 2.8%via NVD
CVE-2026-14620Medium· 4.7PoC
2mo ago

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the …

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the …

▾ TwilightEPSS 0.52%via NVD
CVE-2026-14459High· 8.8PoC
2mo ago

Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: f…

Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: f…

▾ MidnightEPSS 0.21%via NVD
CVE-2026-9547High· 7.4PoC
2mo ago

When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server

When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key ty…

▾ Midnighthaxx · curlEPSS 0.51%via NVD
CVE-2026-9546High· 7.5PoC
2mo ago

A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared

A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURLOPT_REFERER` suppresses the header, the option failed to clear the internal st…

▾ Midnighthaxx · curlEPSS 0.65%via NVD
CVE-2026-9545High· 7.5PoC
2mo ago

In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libc…

In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libc…

▾ Midnighthaxx · curlEPSS 0.41%via NVD
CVE-2026-9080High· 7.3PoC
2mo ago

Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory…

Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory…

▾ Midnighthaxx · curlEPSS 0.49%via NVD
CVE-2026-9079Critical· 9.8PoC⚖ disputed
2mo ago

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

▾ Abyssalhaxx · curlEPSS 0.58%via NVD
CVE-2026-8932High· 7.5PoC
2mo ago

libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to…

libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to…

▾ Midnighthaxx · curlEPSS 0.40%via NVD
CVE-2026-8927Critical· 9.1PoC
2mo ago

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates agains…

▾ Abyssalhaxx · curlEPSS 0.50%via NVD
CVE-2026-8926Critical· 9.1PoC⚖ disputed
2mo ago

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set …

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set …

▾ Abyssalhaxx · curlEPSS 0.44%via NVD
CVE-2026-8925Critical· 9.8PoC
2mo ago

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.

▾ Abyssalhaxx · curlEPSS 1.1%via NVD
CVEs tagged “exploit-available” — page 76 · VulnSea