VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3549 CVEsRSS

CVE-2026-8926Critical· 9.1PoC⚖ disputed
2mo ago

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set …

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set …

▾ Abyssalhaxx · curlEPSS 0.44%via NVD
CVE-2026-8925Critical· 9.8PoC
2mo ago

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.

▾ Abyssalhaxx · curlEPSS 1.1%via NVD
CVE-2026-8924Critical· 9.1PoC⚖ disputed
2mo ago

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmit…

▾ Abyssalhaxx · curlEPSS 0.66%via NVD
CVE-2026-8458Medium· 6.5PoC
2mo ago

libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different "services". libcurl features a pool of recent connections so that subsequent requests …

libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different "services". libcurl features a pool of recent connections so that subsequent requests …

▾ Twilighthaxx · curlEPSS 0.37%via NVD
CVE-2026-8286High· 8.1PoC
2mo ago

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

▾ Midnighthaxx · curlEPSS 0.52%via NVD
CVE-2026-12064High· 7.5PoC
2mo ago

When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl

When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initi…

▾ Midnighthaxx · curlEPSS 0.40%via NVD
CVE-2026-11856Critical· 9.8PoC⚖ disputed
2mo ago

Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongl…

Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongl…

▾ Abyssalhaxx · curlEPSS 0.69%via NVD
CVE-2026-11564Critical· 9.1PoC
2mo ago

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store af…

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store af…

▾ Abyssalhaxx · curlEPSS 0.43%via NVD
CVE-2026-11352High· 7.5PoC
2mo ago

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them tow…

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them tow…

▾ Midnighthaxx · curlEPSS 0.71%via NVD
CVE-2026-10536Critical· 9.8PoC⚖ disputed
2mo ago

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates…

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates…

▾ Abyssalhaxx · curlEPSS 0.60%via NVD
CVE-2026-54998High· 8.8PoC
2mo ago

Microsoft Exchange Online Elevation of Privilege Vulnerability

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Exchange OnlineEPSS 0.78%via CVEORG
CVE-2026-49352Critical· 9.8PoC
2mo ago

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

▾ Abyssal9router · 9routerEPSS 0.60%via GHSA
CVE-2026-9558Critical· 9.9PoC
2mo ago

Mautic has Server-Side Template Injection (SSTI) in Theme Templates

Mautic has Server-Side Template Injection (SSTI) in Theme Templates

▾ Abyssalmautic · mautic/coreEPSS 0.79%via GHSA
CVE-2026-9809High· 7.6PoC
2mo ago

Mautic has Stored Cross-Site Scripting (XSS) in Projects Component

Mautic has Stored Cross-Site Scripting (XSS) in Projects Component

▾ Midnightmautic · mautic/coreEPSS 0.29%via GHSA
CVE-2026-9811Medium· 5.4PoC
2mo ago

Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector

Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector

▾ Twilightmautic · mautic/coreEPSS 0.23%via GHSA
CVE-2026-50181High· 7.1PoC
2mo ago

Langroid: Path traversal in the file tools allows read/write outside configured current directory

Langroid: Path traversal in the file tools allows read/write outside configured current directory

▾ Midnightlangroid · langroidEPSS 0.18%via GHSA
CVE-2026-58592High· 8.3PoC
2mo ago

Ladybird before commit 2f9dc7e contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader

Ladybird before commit 2f9dc7e contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported into a WebAssembly module via the ESM path, WebAssemblyModule.cpp pa…

▾ MidnightLadybirdBrowser · LadybirdEPSS 0.55%via NVD
CVE-2026-57516High· 8.8PoC
2mo ago

Ray < 2.56.0 Unsafe Deserialization RCE via WebDataset Reader

Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_webdataset() function. The _default_dec…

▾ MidnightAnyscale, Inc · RayEPSS 0.86%via CVEORG
CVE-2026-14382Critical· 9.6PoC
2mo ago

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 0.34%via NVD
CVE-2026-46680High· 7.8PoC
2mo ago

containerd is an open-source container runtime

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leadi…

▾ Midnightlinuxfoundation · containerdEPSS 0.16%via NVD
CVE-2026-12243High· 7.5PoC
3mo ago

nltk: NLTK: Information disclosure via path traversal vulnerability (CVE-2026-12243)

A flaw was found in NLTK. An attacker can exploit a path traversal vulnerability by providing specially crafted input to `nltk.data.load()` or `nltk.data.find()`. This allows the attacker to read arbitrary files accessible to the Python pr…

▾ MidnightRed Hat · Red Hat OpenShift AI 3.4via CSAF
CVE-2026-14164High· 7.5PoC
3mo ago

A double free issue has been identified in libarchive's RAR5 reader

A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent proc…

▾ MidnightRed Hat · libarchiveEPSS 0.73%via NVD
CVE-2026-58014High· 7.3PoC
3mo ago

A flaw was found in GLib

A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a deni…

▾ Midnightgnome · glibEPSS 0.72%via NVD
CVE-2026-58011Medium· 6.5PoC
3mo ago

A flaw was found in GLib

A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This …

▾ Twilightgnome · glibEPSS 0.82%via NVD
CVE-2026-8023High· 7.5PoC
3mo ago

Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory

Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory. Before this fix, both …

▾ Midnightzephyrproject · zephyrEPSS 0.87%via NVD
CVE-2026-50229Medium· 6.1PoC
3mo ago

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55,…

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55,…

▾ Twilightapache · tomcatEPSS 4.1%via NVD
CVE-2026-56290Critical· 9.8CISA KEVPoC
3mo ago

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

▾ Hadaljoomlack · page_builder_ckEPSS 31%via NVD
CVE-2026-44840High· 7.5PoC
3mo ago

Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query

Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query

▾ Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.49%via GHSA
CVE-2026-49048NonePoC
3mo ago

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.

▾ TwilightEPSS 0.56%via NVD
CVE-2026-49869Critical· 10.0CISA KEVPoC
3mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Bec…

▾ Hadalkestra · kestraEPSS 2.1%via NVD
CVEs tagged “exploit-available” — page 77 · VulnSea