VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3550 CVEsRSS

CVE-2026-52782Critical· 9.9PoC
3mo ago

OpenProject is open-source, web-based project management software

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" l…

▾ AbyssalEPSS 0.45%via NVD
CVE-2026-53519Critical· 9.1PoC
3mo ago

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

▾ Abyssalnezhahq · github.com/nezhahq/nezhaEPSS 2.3%via GHSA
CVE-2026-44024Critical· 9.8PoC
3mo ago

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

▾ Abyssalfluentd · fluentdEPSS 1.1%via GHSA
CVE-2026-53266High· 8.8CISA KEVPoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0)

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is i…

▾ Abyssallinux · linux_kernelEPSS 0.65%via NVD
CVE-2025-71338Critical· 10.0PoC
3mo ago

Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory

Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the stor…

▾ Abyssalflowiseai · flowiseEPSS 1.2%via NVD
CVE-2026-40179NonePoC
3mo ago

Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus

Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus

▾ Twilightprometheus · github.com/prometheus/prometheusEPSS 0.31%via OSV
CVE-2026-56223High· 8.7PoC
3mo ago

Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary victim accounts based on email match without validating SSO provider domain authoriz…

Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary victim accounts based on email match without validating SSO provider domain authoriz…

▾ MidnightCapgo · CapgoEPSS 0.40%via NVD
CVE-2026-52924Critical· 9.8PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the association is moved into COOKIE_WAIT during association setup/reconfi…

In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the association is moved into COOKIE_WAIT during association setup/reconfi…

▾ Abyssallinux · linux_kernelEPSS 0.84%via NVD
CVE-2026-52943High· 7.8PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zerocopy reference in pskb_carve helpers pskb_carve_inside_header() and pskb_carve_inside_nonlinear() both copy the old skb_shared_info header…

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zerocopy reference in pskb_carve helpers pskb_carve_inside_header() and pskb_carve_inside_nonlinear() both copy the old skb_shared_info header…

▾ Midnightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-56121Critical· 9.8PoC
3mo ago

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_functi…

▾ AbyssalEPSS 1.4%via NVD
CVE-2026-52923High· 7.8PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range The checkpoint/restore sysctl path can request the next SysV IPC id through ids->next_id

In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range The checkpoint/restore sysctl path can request the next SysV IPC id through ids->next_id. ipc_idr_alloc() currentl…

▾ Midnightlinux · linux_kernelEPSS 0.20%via NVD
CVE-2026-56402Medium· 6.5PoC
3mo ago

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions li…

▾ Twilightnanocoai · nanoclawEPSS 0.38%via NVD
CVE-2026-52806Critical· 9.9PoC
3mo ago

Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge

Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge

▾ Abyssalgogs · gogs.io/gogsEPSS 7.9%via GHSA
CVE-2026-52810HighPoC
3mo ago

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion

▾ Midnightgogs · gogs.io/gogsEPSS 0.43%via GHSA
CVE-2026-52813Critical· 10.0PoC
3mo ago

Gogs has Path Traversal in organization name that results in RCE through Git hooks

Gogs has Path Traversal in organization name that results in RCE through Git hooks

▾ Abyssalgogs · gogs.io/gogsEPSS 1.1%via GHSA
CVE-2026-52815MediumPoC
3mo ago

Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API

Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API

▾ Twilightgogs · gogs.io/gogsEPSS 1.5%via GHSA
CVE-2026-54350Critical· 10.0PoC
3mo ago

Budibase has nonymous NoSQL operator injection via published-app query templates

Budibase has nonymous NoSQL operator injection via published-app query templates

▾ Abyssalbudibase · @budibase/serverEPSS 0.54%via GHSA
CVE-2026-54512High· 8.1PoC
3mo ago

jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)

A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass the PolymorphicTypeValidator (PTV) when polymorphic typing is enabled and a type identifier contains generic parameters. By crafting a malicious ty…

▾ MidnightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 1.00%via CSAF
CVE-2026-54515Medium· 5.3PoC
3mo ago

jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified (CVE-2026-54515)

A flaw was found in jackson-databind. This vulnerability occurs in the data-binding functionality where properties intended to be ignored are incorrectly restored and become writable again. An attacker could potentially exploit this by pro…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.44%via CSAF
CVE-2026-11745High· 8.8PoC
3mo ago

A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-t…

A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-t…

▾ MidnightLY Corporation · Central DogmaEPSS 0.22%via NVD
CVE-2026-11746Critical· 9.4PoC
3mo ago

A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret

A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. …

▾ AbyssalLY Corporation · Central DogmaEPSS 0.23%via NVD
CVE-2026-54293High· 7.5PoC
3mo ago

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path tr…

▾ Midnightnltk · nltkEPSS 0.63%via NVD
CVE-2026-48746Critical· 9.1PoC
3mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API Authenti…

▾ Abyssalvllm · vllmEPSS 1.2%via NVD
CVE-2025-67303High· 7.5PoC
3mo ago

ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)

ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)

▾ Midnightcomfyui-manager · comfyui-managerEPSS 1.4%via GHSA
CVE-2026-56265Critical· 9.8PoC
3mo ago

Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server

Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server

▾ Abyssalcrawl4ai · crawl4aiEPSS 2.6%via GHSA
CVE-2025-71348High· 8.1PoC
3mo ago

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but execut…

▾ Midnightmmaitre314 · picklescanEPSS 0.55%via NVD
CVE-2026-48939Critical· 9.8CISA KEVPoC
3mo ago

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

▾ Hadaljoomlic · icagendaEPSS 20%via NVD
CVE-2026-52910High· 7.8PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below with a repro

In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below with a repro. [0] The repro sets up a UDP reuseport group with a cBPF prog a…

▾ Midnightlinux · linux_kernelEPSS 0.11%via NVD
CVE-2026-54900HighPoC
3mo ago

Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling

Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling

▾ Midnightoj · ojEPSS 0.43%via GHSA
CVE-2026-55255Critical· 9.9CISA KEVPoC
3mo ago

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

▾ Hadallangflow · langflowEPSS 0.89%via GHSA
CVEs tagged “exploit-available” — page 78 · VulnSea