VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3553 CVEsRSS

CVE-2026-40701Medium· 4.8PoC
4mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured wi…

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured wi…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-41293High· 7.3PoC⚖ disputed
4mo ago

tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293)

Apache Tomcat did not validate HTTP/2 request headers, triggering unexpected application behavior, as applications may presume that header values exposed through the Servlet API would be valid.

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream EUS (v. 10.0)EPSS 1.7%via CSAF
CVE-2026-42338Medium· 6.1PoC⚖ disputed
4mo ago

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they…

▾ Twilightbeaugunderson · ip-addressEPSS 0.51%via NVD
CVE-2026-40369High· 7.8PoC
4mo ago

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ MidnightEPSS 0.33%via NVD
CVE-2026-6093Medium· 6.0PoC
4mo ago

Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose records by the meta field.This issue affects corteza: 2024.9.8.

Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose records by the meta field.This issue affects corteza: 2024.9.8.

▾ Twilightcortezaproject · cortezaEPSS 0.28%via NVD
CVE-2026-28995High· 8.8PoC
4mo ago

A logic issue was addressed with improved restrictions

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A…

▾ Midnightapple · ipadosEPSS 0.15%via NVD
CVE-2026-28990High· 7.5PoC
4mo ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. …

▾ Midnightapple · ipadosEPSS 0.52%via NVD
CVE-2026-3609High· 7.8PoC
4mo ago

Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_A…

Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_A…

▾ Midnightwellbia · xigncode3EPSS 0.16%via NVD
CVE-2026-40217High· 8.8PoC
4mo ago

LiteLLM has a sandbox escape in custom-code guardrail

LiteLLM has a sandbox escape in custom-code guardrail

▾ Midnightlitellm · litellmEPSS 3.4%via OSV
CVE-2026-44338High· 7.3PoC
4mo ago

PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution

PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution

▾ Midnightpraisonai · praisonaiEPSS 0.82%via OSV
CVE-2026-6815Medium· 5.9PoC
4mo ago

Casdoor: Arbitrary file write possible through Local File System storage provider

Casdoor: Arbitrary file write possible through Local File System storage provider

▾ Twilightcasdoor · github.com/casdoor/casdoorEPSS 0.59%via OSV
CVE-2026-2614High· 7.5PoC
4mo ago

A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem

A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue…

▾ Midnightlfprojects · mlflowEPSS 3.2%via NVD
CVE-2026-38360Critical· 9.8PoC
4mo ago

dash-uploader has a directory traversal vulnerability

dash-uploader has a directory traversal vulnerability

▾ Abyssaldash-uploader · dash-uploaderEPSS 6.1%via OSV
CVE-2026-8069High· 7.8PoC
4mo ago

PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions

PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigu…

▾ Midnightacer · nitrosenseEPSS 0.17%via NVD
CVE-2026-43284High· 8.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG afte…

▾ Midnightlinux · linux_kernelEPSS 2.5%via NVD
CVE-2026-42271High· 8.8CISA KEVPoC
4mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /m…

▾ Abyssallitellm · litellmEPSS 13%via NVD
CVE-2026-42264High· 7.4PoC
4mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via d…

▾ Midnightaxios · axiosEPSS 0.97%via NVD
CVE-2026-42208Critical· 9.8CISA KEV0dayPoC
4mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query tex…

▾ Hadallitellm · litellmEPSS 5.8%via NVD
CVE-2026-32686Medium· 6.9PoC
4mo ago

Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The decimal library does not bound the exponent on parsed input

Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The decimal library does not bound the exponent on parsed input. Storing a decimal with a very large exponent (e.g. Decim…

▾ Twilightericmj · decimalEPSS 0.34%via NVD
CVE-2026-41674High· 7.5PoC
4mo ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package serializes DocumentType n…

▾ Midnightxmldom · xmldomEPSS 0.65%via NVD
CVE-2026-42216Critical· 9.1PoC
4mo ago

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDM…

▾ Abyssalopenexr · openexrEPSS 0.71%via NVD
CVE-2026-42880Critical· 9.6PoC
4mo ago

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

▾ Abyssalargoproj · github.com/argoproj/argo-cd/v3EPSS 0.56%via OSV
CVE-2026-8080Medium· 5.4PoC
4mo ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS. This issue affects MISP before 2.5.37. A stored cross-site scripting vulnerability exists in t…

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS. This issue affects MISP before 2.5.37. A stored cross-site scripting vulnerability exists in t…

▾ TwilightEPSS 0.24%via NVD
CVE-2026-23870High· 7.5PoC
4mo ago

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following pac…

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following pac…

▾ Midnightfacebook · react-server-dom-parcelEPSS 1.5%via NVD
CVE-2026-20169Medium· 6.4PoC
4mo ago

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router. This vulnerability is…

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router. This vulnerability is…

▾ Twilightcisco · iot_field_network_directorEPSS 0.21%via NVD
CVE-2026-44166MediumPoC
4mo ago

PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade

PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade

▾ Twilightpocketbase · github.com/pocketbase/pocketbaseEPSS 0.32%via OSV
CVE-2026-35397High· 8.8PoC
4mo ago

Jupyter Server is the backend for Jupyter web applications

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whos…

▾ Midnightjupyter · jupyter_serverEPSS 0.67%via NVD
CVE-2026-23479High· 8.8PoC
4mo ago

Redis is an in-memory data structure store

Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is e…

▾ Midnightredis · redisEPSS 1.5%via NVD
CVE-2026-40864Medium· 5.4PoC
4mo ago

JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)

JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)

▾ Twilightjupyterhub · jupyterhubEPSS 0.18%via OSV
CVE-2026-25243High· 8.8PoC
4mo ago

Redis is an in-memory data structure store

Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted seri…

▾ Midnightredis · redisEPSS 3.7%via NVD
CVEs tagged “exploit-available” — page 84 · VulnSea