VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3549 CVEsRSS

CVE-2026-45504High· 8.8PoC
3mo ago

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · exchange_serverEPSS 0.78%via NVD
CVE-2026-25089Critical· 9.8CISA KEVPoC
3mo ago

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …

▾ Hadalfortinet · fortisandboxEPSS 76%via NVD
CVE-2026-8467CriticalPoC
3mo ago

PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground

PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground

▾ Abyssalphoenix_storybook · phoenix_storybookEPSS 2.1%via GHSA
CVE-2026-48030Critical· 9.9PoC
3mo ago

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

▾ Abyssalpheditor · pheditor/pheditorEPSS 7.5%via GHSA
CVE-2026-45447High· 8.8PoC
3mo ago

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remo…

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remo…

▾ Midnightopenssl · opensslEPSS 4.0%via NVD
CVE-2026-46316Critical· 9.3PoC⚖ disputed
3mo ago

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each()…

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each()…

▾ Abyssallinux · linux_kernelEPSS 0.20%via NVD
CVE-2026-42536High· 7.5PoC
3mo ago

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…

▾ Midnightapache · http_serverEPSS 2.7%via NVD
CVE-2026-46275High· 7.8PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths Vulnerabilities leading to Use-After-Free (UAF) and Null Pointer Dereference (NPD) conditions…

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths Vulnerabilities leading to Use-After-Free (UAF) and Null Pointer Dereference (NPD) conditions…

▾ MidnightEPSS 0.13%via NVD
CVE-2026-45034CriticalPoC
3mo ago

PHPSpreadsheet has a patch bypass for CVE-2026-34084

PHPSpreadsheet has a patch bypass for CVE-2026-34084

▾ Abyssalphpoffice · phpoffice/phpspreadsheetEPSS 0.46%via GHSA
CVE-2026-41567High· 7.2PoC
3mo ago

Moby is an open source container framework

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, …

▾ Midnightmoby · moby/v2/daemonEPSS 0.17%via NVD
CVE-2026-8037Critical· 9.6CISA KEVPoC
3mo ago

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…

▾ Hadalprogress · connection_manager_for_objectscaleEPSS 77%via NVD
CVE-2026-26824Medium· 6.5PoC
3mo ago

libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser

libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the Master Sector Allocation Table (MSAT) in read_MSAT() is not fully initialized before being consumed b…

▾ Twilightlibxls_project · libxlsEPSS 0.45%via NVD
CVE-2026-43965Medium· 5.6PoC
3mo ago

Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content. Package keys read from build/packages/packages.toml by LocalPackages::read_from_disc a…

Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content. Package keys read from build/packages/packages.toml by LocalPackages::read_from_disc a…

▾ TwilightGleam · gleamEPSS 0.19%via NVD
CVE-2026-42795Medium· 5.1PoC
3mo ago

Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball. The file collection helpers (gleam_files, native_files, private_files) in compiler-cli/…

Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball. The file collection helpers (gleam_files, native_files, private_files) in compiler-cli/…

▾ TwilightGleam · gleamEPSS 0.17%via NVD
CVE-2026-32685Medium· 4.6PoC
3mo ago

Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory. The documentation.pages entries from gleam.toml are incorporat…

Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory. The documentation.pages entries from gleam.toml are incorporat…

▾ TwilightGleam · gleamEPSS 0.19%via NVD
CVE-2026-47117Critical· 9.8PoC
3mo ago

OpenMed vulnerable to remote code injection through privacy-filter model loading path

OpenMed vulnerable to remote code injection through privacy-filter model loading path

▾ Abyssalopenmed · openmedEPSS 1.3%via OSV
CVE-2026-48596Low· 3.7PoC
3mo ago

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-tesla tesla allows HTTP header injection via Tesla.Multipart.add_content_type_param/2. Tesla.Multipart.add_content_typ…

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-tesla tesla allows HTTP header injection via Tesla.Multipart.add_content_type_param/2. Tesla.Multipart.add_content_typ…

▾ Twilightelixir-tesla · teslaEPSS 0.35%via NVD
CVE-2026-48595Medium· 5.9PoC⚖ disputed
3mo ago

Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedirects strips security-sensitive headers on cross-origin re…

Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedirects strips security-sensitive headers on cross-origin re…

▾ Twilightelixir-tesla · teslaEPSS 0.67%via NVD
CVE-2026-48597Medium· 5.9PoC⚖ disputed
3mo ago

Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint. Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing …

Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint. Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing …

▾ Twilightelixir-tesla · teslaEPSS 0.63%via NVD
CVE-2026-48598Low· 3.7PoC
3mo ago

Improper Encoding or Escaping of Output vulnerability in elixir-tesla tesla allows multipart part header injection via unescaped Content-Disposition parameter values. Tesla.Multipart.part_headers_for_disposition/1 interpolates each disp…

Improper Encoding or Escaping of Output vulnerability in elixir-tesla tesla allows multipart part header injection via unescaped Content-Disposition parameter values. Tesla.Multipart.part_headers_for_disposition/1 interpolates each disp…

▾ Twilightelixir-tesla · teslaEPSS 0.34%via NVD
CVE-2026-27145Medium· 6.5PoC
3mo ago

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SA…

▾ TwilightGo standard library · crypto/x509EPSS 0.59%via NVD
CVE-2024-52011High· 8.3PoC
3mo ago

launch-editor allows users to open files with line numbers in editor from Node.js

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on W…

▾ MidnightEPSS 0.51%via NVD
CVE-2026-0009High· 7.8PoC
3mo ago

In multiple locations, there is a possible tapjacking due to a logic error in the code

In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Midnightgoogle · androidEPSS 0.09%via NVD
CVE-2026-10290High· 7.3PoC
3mo ago

A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0

A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument t…

▾ MidnightEPSS 0.32%via NVD
CVE-2026-0091High· 7.8PoC
3mo ago

In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user

In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…

▾ Midnightgoogle · androidEPSS 0.07%via NVD
CVE-2026-45729Medium· 4.3PoC
3mo ago

Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine

Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer dereference in SvgLoader::run() allows any caller that passes untrusted SVG data to Picture::load() to crash the process w…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-46243High· 7.1PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that …

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that …

▾ Midnightlinux · linux_kernelEPSS 0.20%via NVD
CVE-2026-46242High· 7.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside t…

In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside t…

▾ Midnightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-46372High· 8.5PoC
4mo ago

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern exposes /api/search/searx…

▾ MidnightEPSS 1.0%via NVD
CVE-2026-44648High· 7.5PoC
4mo ago

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern relies on cookie-session …

▾ MidnightEPSS 0.38%via NVD
CVEs tagged “exploit-available” — page 81 · VulnSea