VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3550 CVEsRSS

CVE-2026-44648High· 7.5PoC
4mo ago

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern relies on cookie-session …

▾ MidnightEPSS 0.38%via NVD
CVE-2026-46385High· 7.5PoC
4mo ago

iskorotkov/avro is a fast Go Avro codec

iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state inside the loop body. Reader.ReadBlockHea…

▾ Midnightiskorotkov · avroEPSS 0.88%via NVD
CVE-2026-32996High· 7.3PoC
4mo ago

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

▾ MidnightVeeam · Backup and ReplicationEPSS 0.17%via NVD
CVE-2026-46817Critical· 9.8CISA KEVPoC
4mo ago

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission)

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with netwo…

▾ Hadaloracle · e-business_suiteEPSS 0.81%via NVD
CVE-2026-48526High· 7.4PoC
4mo ago

PyJWT is a JSON Web Token implementation in Python

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorith…

▾ Midnightpyjwt_project · pyjwtEPSS 0.43%via NVD
CVE-2026-4408Critical· 9.0PoC
4mo ago

A flaw was found in Samba

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution characte…

▾ Abyssalredhat · openshift_container_platformEPSS 1.8%via NVD
CVE-2026-48962High· 7.3PoC
4mo ago

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the par…

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the par…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-48710Medium· 6.5CISA KEVPoC
4mo ago

Starlette is a lightweight ASGI framework/toolkit

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `…

▾ Midnightstarlette · starletteEPSS 7.1%via NVD
CVE-2026-48842High· 8.1PoC
4mo ago

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

▾ MidnightRoundcube · WebmailEPSS 0.89%via NVD
CVE-2026-46300High· 7.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the result…

▾ Midnightlinux · linux_kernelEPSS 2.4%via NVD
CVE-2026-43503High· 8.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SH…

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SH…

▾ Midnightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-5843High· 8.2PoC
4mo ago

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a mod…

▾ Midnightdocker · docker_desktopEPSS 0.18%via NVD
CVE-2026-5817High· 8.2PoC
4mo ago

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import a…

▾ Midnightdocker · docker_desktopEPSS 0.18%via NVD
CVE-2026-9018High· 8.8PoC
4mo ago

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function. This is due to the `wp_ajax_…

▾ MidnightEPSS 0.59%via NVD
CVE-2026-45659High· 8.8CISA KEVPoC
4mo ago

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ Abyssalmicrosoft · sharepoint_serverEPSS 2.7%via NVD
CVE-2026-9277High· 8.1PoC
4mo ago

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line term…

▾ MidnightEPSS 0.95%via NVD
CVE-2026-46595High· 7.1PoC⚖ disputed
4mo ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation (CVE-2026-46595)

A flaw was found in golang.org/x/crypto/ssh. Source-address validation can be skipped when an SSH server configuration uses an authentication callback type other than public key, allowing authorization bypass in misconfigured servers. This…

▾ MidnightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.60%via CSAF
CVE-2026-43502High· 7.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the…

In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the…

▾ Midnightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-8237Medium· 5.3PoC
4mo ago

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any conversation message

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any conversation message. An unauthenticated attacker can enumerate all conversation messages, incl…

▾ Twilightconcretecms · concrete_cmsEPSS 0.74%via NVD
CVE-2026-46645Medium· 4.3PoC
4mo ago

SQLAdmin: Authorization Bypass on `ajax_lookup`

SQLAdmin: Authorization Bypass on `ajax_lookup`

▾ Twilightsqladmin · sqladminEPSS 0.37%via OSV
CVE-2026-43499High· 7.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_…

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_…

▾ Midnightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2026-47102High· 8.8PoC
4mo ago

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user…

▾ Midnightlitellm · litellmEPSS 0.82%via NVD
CVE-2026-47101High· 8.8PoC
4mo ago

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified route…

▾ Midnightlitellm · litellmEPSS 1.3%via NVD
CVE-2026-43501Critical· 9.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr…

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr…

▾ Abyssallinux · linux_kernelEPSS 0.99%via NVD
CVE-2026-9141Critical· 9.8PoC
4mo ago

Taiko AG1000-01A Rev 7.3/8 Authentication Bypass via Web Interface

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that allows unauthenticated attackers to access internal application pages without any sessi…

▾ AbyssalTaiko Network Communications Pte Ltd. · AG1000-01A SMS Alert GatewayEPSS 0.71%via CVEORG
CVE-2026-33137NonePoC
4mo ago

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17…

▾ TwilightEPSS 0.88%via NVD
CVE-2026-30691Medium· 6.1PoC
4mo ago

Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file

Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanitize file content and explicitly casts …

▾ TwilightEPSS 0.31%via NVD
CVE-2026-39047High· 7.5PoC
4mo ago

Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Printing Service (JetDirect) on TCP port 9100

Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Printing Service (JetDirect) on TCP port 9100

▾ MidnightEPSS 0.83%via NVD
CVE-2026-5950Medium· 5.3PoC
4mo ago

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry …

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry …

▾ Twilightisc · bindEPSS 0.80%via NVD
CVE-2026-45584High· 8.1PoC
4mo ago

Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · malware_protection_engineEPSS 0.71%via NVD
CVEs tagged “exploit-available” — page 82 · VulnSea