VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3550 CVEsRSS

CVE-2026-53571HighPoC
3mo ago

vite: `server.fs.deny` bypass on Windows alternate paths

vite: `server.fs.deny` bypass on Windows alternate paths

▾ Midnightvite · viteEPSS 0.58%via GHSA
CVE-2026-11417High· 7.3PoC
3mo ago

aws-cdk-lib: OS Command Injection in NodejsFunction Bundling

aws-cdk-lib: OS Command Injection in NodejsFunction Bundling

▾ Midnightaws-cdk-lib · aws-cdk-libEPSS 0.99%via GHSA
CVE-2026-45833CriticalPoC
3mo ago

ChromaDB has a code injection vulnerability

ChromaDB has a code injection vulnerability

▾ Abyssalchromadb · chromadbEPSS 0.63%via OSV
CVE-2026-44990Critical· 9.3PoC
3mo ago

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-contro…

▾ Abyssalapostrophecms · sanitize-htmlEPSS 0.69%via NVD
CVE-2026-12143High· 7.5PoC
3mo ago

form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)

form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…

▾ Midnightform-data · form-dataEPSS 0.67%via CVEORG
CVE-2026-50011High· 7.5PoC
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array elemen…

▾ Midnightnetty · nettyEPSS 0.85%via NVD
CVE-2026-45674High· 8.7PoC
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS respon…

▾ Midnightnetty · nettyEPSS 0.36%via NVD
CVE-2026-40987High· 7.1PoC
3mo ago

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration 7.0.0 through 7.…

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration 7.0.0 through 7.…

▾ Midnightvmware · spring_integrationEPSS 0.26%via NVD
CVE-2026-44496High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metac…

▾ Midnightaxios · axiosEPSS 0.97%via NVD
CVE-2026-44488High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected …

▾ Midnightaxios · axiosEPSS 0.93%via NVD
CVE-2026-44486High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticat…

▾ Midnightaxios · axiosEPSS 0.76%via NVD
CVE-2026-48020HighPoC
3mo ago

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

▾ Midnighttraefik · github.com/traefik/traefik/v2EPSS 0.78%via GHSA
CVE-2026-44495High· 7.0PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process h…

▾ Midnightaxios · axiosEPSS 1.0%via NVD
CVE-2026-44494High· 8.7PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depen…

▾ Midnightaxios · axiosEPSS 0.93%via NVD
CVE-2026-44492High· 8.6PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL us…

▾ Midnightaxios · axiosEPSS 0.78%via NVD
CVE-2026-44487High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. Th…

▾ Midnightaxios · axiosEPSS 0.76%via NVD
CVE-2025-71329High· 7.5PoC
3mo ago

image-size: JXL and HEIF parsers allow denial of service through infinite loops

image-size: JXL and HEIF parsers allow denial of service through infinite loops

▾ Midnightimage-size · image-sizeEPSS 0.43%via GHSA
CVE-2026-52759Medium· 5.5PoC
3mo ago

Ghidra < 12.1.1 - Denial of Service via Uncontrolled Memory Allocation in Mach-O Parser

Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attackers to cause denial of service. An attacker can supply a crafted Mach-O binary with an arbitrarily large ncmds lo…

▾ TwilightGhidra · GhidraEPSS 0.16%via CVEORG
CVE-2026-53435High· 8.8PoC
3mo ago

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows t…

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows t…

▾ MidnightJenkins Project · JenkinsEPSS 2.2%via CVEORG
CVE-2026-11837High· 7.3PoC
3mo ago

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys.…

▾ MidnightRed Hat · rhc-worker-playbookEPSS 0.16%via NVD
CVE-2026-46625High· 7.5PoC
3mo ago

JavaScript Cookie is a JavaScript API for handling cookies, client-side

JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, t…

▾ Midnightjs-cookie · javascript_cookieEPSS 0.99%via NVD
CVE-2026-46529High· 7.8PoC
3mo ago

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execut…

▾ MidnightEPSS 0.41%via NVD
CVE-2026-41729High· 8.1PoC
3mo ago

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segm…

▾ Midnightvmware · spring_data_restEPSS 0.40%via NVD
CVE-2026-0273High· 7.2PoC
3mo ago

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have…

▾ Midnightpaloaltonetworks · pan-osEPSS 1.3%via NVD
CVE-2026-53694NonePoC
3mo ago

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.This issue affects Nomachine: before 9.5.7, before 8.23.2.

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.This issue affects Nomachine: before 9.5.7, before 8.23.2.

▾ TwilightEPSS 0.19%via NVD
CVE-2026-48060High· 8.1PoC
3mo ago

Litestar has HTML Injection Through its CSRF Token

Litestar has HTML Injection Through its CSRF Token

▾ Midnightlitestar · litestarEPSS 0.40%via GHSA
CVE-2026-50507Medium· 6.8PoC
3mo ago

Windows BitLocker Security Feature Bypass Vulnerability

Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-49160High· 7.5PoC
3mo ago

HTTP.sys Denial of Service Vulnerability

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 1.2%via CVEORG
CVE-2026-42978High· 7.8PoC
3mo ago

Windows Push Notifications Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 10 Version 1809EPSS 0.20%via CVEORG
CVE-2026-41710Medium· 5.9PoC
3mo ago

An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache

An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, causing all later s…

▾ Twilightbroadcom · spring_retryEPSS 0.37%via NVD
CVEs tagged “exploit-available” — page 80 · VulnSea