VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3549 CVEsRSS

CVE-2026-55229High· 7.5PoC
3mo ago

Gotenberg: SSRF via LibreOffice document processing

Gotenberg: SSRF via LibreOffice document processing

▾ Midnightgotenberg · github.com/gotenberg/gotenberg/v8EPSS 1.5%via GHSA
CVE-2026-47103Critical· 9.8PoC
3mo ago

python-statemachine SCXML <data expr> Eval Injection

python-statemachine SCXML <data expr> Eval Injection

▾ Abyssalpython-statemachine · python-statemachineEPSS 1.4%via GHSA
CVE-2026-2604Medium· 5.6PoC
3mo ago

A flaw was found in evolution-data-server

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored…

▾ TwilightGNOME · Evolution Data ServerEPSS 0.28%via NVD
CVE-2026-55198Medium· 6.5PoC
3mo ago

Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles

Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. The _handle_session_export handler in api/routes.py fails …

▾ Twilightnesquena · hermes-webuiEPSS 0.47%via NVD
CVE-2026-55197Medium· 6.5PoC
3mo ago

Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts

Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts. Attackers can bypass profile boundary checks by direc…

▾ Twilightnesquena · hermes-webuiEPSS 0.47%via NVD
CVE-2026-55200High· 8.1PoC
3mo ago

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessiv…

▾ Midnightlibssh2 · libssh2EPSS 0.83%via NVD
CVE-2026-54415High· 8.1PoC
3mo ago

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over…

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over…

▾ MidnightEPSS 0.49%via NVD
CVE-2026-48779High· 7.5PoC
3mo ago

ws is an open source WebSocket client and server for Node.js

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS v…

▾ Midnightws_project · wsEPSS 0.93%via NVD
CVE-2026-42530High· 8.1PoC
3mo ago

NGINX Open Source has a vulnerability in the ngx_http_v3_module module

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially …

▾ Midnightf5 · nginx_gateway_fabricEPSS 1.1%via NVD
CVE-2026-42055High· 8.1PoC
3mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, …

▾ Midnightf5 · dosEPSS 2.4%via NVD
CVE-2026-54761High· 7.1PoC
3mo ago

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

▾ Midnighttraefik · github.com/traefik/traefik/v3EPSS 0.37%via OSV
CVE-2026-54236Medium· 5.3PoC
3mo ago

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router

▾ Twilightvllm · vllmEPSS 0.93%via OSV
CVE-2026-54316MediumPoC
3mo ago

Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch

Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch

▾ Twilightanthropic-ai · @anthropic-ai/claude-codeEPSS 0.52%via GHSA
CVE-2026-49268HighPoC
3mo ago

Apache Shiro: LDAP DN Injection in DefaultLdapRealm

Apache Shiro: LDAP DN Injection in DefaultLdapRealm

▾ Midnightapache · org.apache.shiro:shiro-coreEPSS 0.76%via GHSA
CVE-2025-26240High· 8.4PoC
3mo ago

pdfkit: Path traversal in from_string

pdfkit: Path traversal in from_string

▾ Midnightpdfkit · pdfkitEPSS 0.39%via GHSA
CVE-2026-55450Critical· 9.3PoC
3mo ago

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

▾ Abyssallangflow · langflowEPSS 1.2%via GHSA
CVE-2026-50656High· 7.8PoC
3mo ago

Microsoft Defender Elevation of Privilege Vulnerability

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;.

▾ MidnightMicrosoft · Microsoft Malware Protection EngineEPSS 0.37%via CVEORG
CVE-2026-7273High· 8.8CISA KEVPoC
3mo ago

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via …

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via …

▾ Abyssalzyxel · gs1900-8_firmwareEPSS 2.5%via NVD
CVE-2026-12295Critical· 9.6PoC
3mo ago

Sandbox escape in the DOM: Navigation component

Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

▾ Abyssalmozilla · firefoxEPSS 0.39%via NVD
CVE-2026-46331High· 7.8PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_…

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_…

▾ MidnightLinux · LinuxEPSS 0.20%via NVD
CVE-2026-48519Critical· 9.6PoC
3mo ago

Langflow: Unauthenticated RCE in Shareable Playgrounds

Langflow: Unauthenticated RCE in Shareable Playgrounds

▾ Abyssallangflow · langflowEPSS 0.78%via GHSA
CVE-2026-53753Critical· 9.8PoC
3mo ago

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API

▾ Abyssalcrawl4ai · crawl4aiEPSS 2.9%via GHSA
CVE-2026-54157Critical· 9.0PoC
3mo ago

LobeHub: Unauthenticated SSRF in `/webapi/proxy`

LobeHub: Unauthenticated SSRF in `/webapi/proxy`

▾ Abyssallobehub · @lobehub/lobehubEPSS 1.8%via GHSA
CVE-2026-53755High· 8.6PoC
3mo ago

Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check

Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check

▾ Midnightcrawl4ai · crawl4aiEPSS 1.6%via GHSA
CVE-2026-49468Critical· 9.8PoC
3mo ago

LiteLLM: Authentication Bypass via Host Header Injection

LiteLLM: Authentication Bypass via Host Header Injection

▾ Abyssallitellm · litellmEPSS 0.82%via OSV
CVE-2026-28699High· 8.1PoC
3mo ago

Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication

Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.55%via GHSA
CVE-2026-48853Critical· 9.2PoC
3mo ago

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flow…

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flow…

▾ Abyssalelixir-grpc · grpcEPSS 0.78%via NVD
CVE-2026-48599High· 7.6PoC
3mo ago

Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the qu…

Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the qu…

▾ Midnightelixir-grpc · grpcEPSS 0.34%via NVD
CVE-2026-48854High· 8.7PoC
3mo ago

Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.G…

Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.G…

▾ Midnightelixir-grpc · grpcEPSS 0.45%via NVD
CVE-2026-53571HighPoC
3mo ago

vite: `server.fs.deny` bypass on Windows alternate paths

vite: `server.fs.deny` bypass on Windows alternate paths

▾ Midnightvite · viteEPSS 0.58%via GHSA
CVEs tagged “exploit-available” — page 79 · VulnSea