VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3550 CVEsRSS

CVE-2026-45498Medium· 4.0CISA KEV0dayPoC
4mo ago

Microsoft Defender Denial of Service Vulnerability

Microsoft Defender Denial of Service Vulnerability

▾ Midnightmicrosoft · defender_antimalware_platformEPSS 1.3%via NVD
CVE-2026-20223Critical· 10.0PoC
4mo ago

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability …

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability …

▾ Abyssalcisco · secure_workloadEPSS 0.83%via NVD
CVE-2026-2587Critical· 9.6PoC
4mo ago

A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler

A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a co…

▾ AbyssalEPSS 0.67%via NVD
CVE-2026-2586Critical· 9.1PoC
4mo ago

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands wi…

▾ AbyssalEPSS 0.83%via NVD
CVE-2026-8836Critical· 9.8PoC
4mo ago

A vulnerability was found in lwIP up to 2.2.1

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParamet…

▾ AbyssalEPSS 1.6%via NVD
CVE-2026-8838Critical· 9.8PoC
4mo ago

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate t…

▾ Abyssalredshift-connector · redshift-connectorEPSS 0.80%via NVD
CVE-2026-45829Critical· 10.0PoC
4mo ago

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_c…

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_c…

▾ AbyssalEPSS 1.0%via NVD
CVE-2026-20685Medium· 6.5PoC
4mo ago

An attacker in a privileged network position may be able to leak sensitive information

An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue is fixed in PCC Release 5E290.3.

▾ Twilightapple · private_cloud_computeEPSS 0.27%via NVD
CVE-2026-2652High· 8.6PoC
4mo ago

MLflow: unauthenticated access to certain FastAPI routes

MLflow: unauthenticated access to certain FastAPI routes

▾ Midnightmlflow · mlflowEPSS 1.4%via OSV
CVE-2026-45736Medium· 4.4PoC
4mo ago

ws is an open source WebSocket client and server for Node.js

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability i…

▾ Twilightws_project · wsEPSS 0.68%via NVD
CVE-2026-46333High· 7.1PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can c…

In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can c…

▾ Midnightlinux · linux_kernelEPSS 0.51%via NVD
CVE-2026-44673High· 7.5PoC
4mo ago

libyang is a YANG data modeling language library

libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attack…

▾ MidnightCESNET · libyangEPSS 0.95%via NVD
CVE-2026-45401High· 8.5PoC
4mo ago

Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)

Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)

▾ Midnightopen-webui · open-webuiEPSS 0.33%via OSV
CVE-2026-45316Low· 3.5PoC
4mo ago

Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)

Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)

▾ Twilightopen-webui · open-webuiEPSS 0.26%via OSV
CVE-2026-45397Medium· 5.3PoC
4mo ago

Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure

Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure

▾ Twilightopen-webui · open-webuiEPSS 0.81%via OSV
CVE-2026-20224High· 8.6PoC
4mo ago

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have va…

▾ MidnightEPSS 1.0%via NVD
CVE-2026-7168Medium· 5.3PoC
4mo ago

Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wr…

Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wr…

▾ Twilighthaxx · curlEPSS 0.59%via NVD
CVE-2026-6276High· 7.5PoC⚖ disputed
4mo ago

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…

▾ Midnighthaxx · curlEPSS 0.35%via NVD
CVE-2026-6253Medium· 5.9PoC
4mo ago

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy nee…

▾ Twilighthaxx · curlEPSS 0.75%via NVD
CVE-2026-5773High· 7.5PoC
4mo ago

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connectio…

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connectio…

▾ Midnighthaxx · curlEPSS 0.66%via NVD
CVE-2026-42945High· 8.1PoC
4mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expre…

▾ Midnightf5 · dosEPSS 3.4%via NVD
CVE-2026-42584High· 7.3PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If …

▾ Midnightnetty · nettyEPSS 0.72%via NVD
CVE-2026-42581Medium· 5.8PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Conten…

▾ Twilightnetty · nettyEPSS 0.68%via NVD
CVE-2026-42579High· 7.5PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirec…

▾ Midnightnetty · nettyEPSS 0.85%via NVD
CVE-2026-42578High· 7.5PoC⚖ disputed
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() …

▾ Midnightnetty · nettyEPSS 1.2%via NVD
CVE-2026-44579High· 7.5PoC
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through cr…

▾ Midnightvercel · next.jsEPSS 0.76%via NVD
CVE-2026-44578High· 8.6PoC
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted…

▾ Midnightvercel · next.jsEPSS 1.9%via NVD
CVE-2026-42587High· 7.5PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb at…

▾ Midnightnetty · nettyEPSS 1.0%via NVD
CVE-2026-40701Medium· 4.8PoC
4mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured wi…

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured wi…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-41293High· 7.3PoC⚖ disputed
4mo ago

tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293)

Apache Tomcat did not validate HTTP/2 request headers, triggering unexpected application behavior, as applications may presume that header values exposed through the Servlet API would be valid.

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream EUS (v. 10.0)EPSS 1.7%via CSAF
CVEs tagged “exploit-available” — page 83 · VulnSea