VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3554 CVEsRSS

CVE-2026-25243High· 8.8PoC
4mo ago

Redis is an in-memory data structure store

Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted seri…

▾ Midnightredis · redisEPSS 3.7%via NVD
CVE-2026-23631High· 8.1PoC
4mo ago

Redis is an in-memory data structure store

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read…

▾ Midnightredis · redisEPSS 2.8%via NVD
CVE-2026-7482Critical· 9.1PoC
4mo ago

Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader

Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader

▾ Abyssalollama · github.com/ollama/ollamaEPSS 0.71%via OSV
CVE-2026-42154High· 7.5PoC
4mo ago

Prometheus is an open-source monitoring system and time series database

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before…

▾ Midnightprometheus · prometheusEPSS 0.89%via NVD
CVE-2026-7669Medium· 5.6PoC
4mo ago

SGLang has an Improper Input Validation/Injection Issue

SGLang has an Improper Input Validation/Injection Issue

▾ Twilightsglang · sglangEPSS 0.42%via OSV
CVE-2026-31694High· 7.8PoC
5mo ago

In the Linux kernel, the following vulnerability has been resolved: fuse: reject oversized dirents in page cache fuse_add_dirent_to_cache() computes a serialized dirent size from the server-controlled namelen field and copies the diren…

In the Linux kernel, the following vulnerability has been resolved: fuse: reject oversized dirents in page cache fuse_add_dirent_to_cache() computes a serialized dirent size from the server-controlled namelen field and copies the diren…

▾ Midnightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-40280Critical· 9.3PoC
5mo ago

Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

▾ Abyssalgotenberg · github.com/gotenberg/gotenberg/v8EPSS 2.1%via OSV
CVE-2026-3833Medium· 6.5PoC
5mo ago

A flaw was found in gnutls

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `perm…

▾ Twilightgnu · gnutlsEPSS 0.89%via NVD
CVE-2026-42031HighPoC
5mo ago

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

▾ Midnightckan · ckanEPSS 2.2%via OSV
CVE-2026-40355Medium· 5.9PoC
5mo ago

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trig…

▾ Twilightmit · kerberos_5EPSS 0.79%via NVD
CVE-2026-42167High· 8.1PoC
5mo ago

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROG…

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROG…

▾ Midnightproftpd · proftpdEPSS 7.3%via NVD
CVE-2026-40858High· 8.8PoC
5mo ago

The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter

The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to t…

▾ Midnightapache · camelEPSS 1.2%via NVD
CVE-2026-40860Critical· 9.8PoC⚖ disputed
5mo ago

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter…

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter…

▾ Abyssalapache · camelEPSS 1.5%via NVD
CVE-2026-33454Critical· 9.4PoC
5mo ago

The Camel-Mail component is vulnerable to Camel message header injection

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not c…

▾ AbyssalRed Hat · Red Hat build of Apache Camel 4 for Quarkus 3EPSS 1.0%via NVD
CVE-2026-40453Critical· 9.9PoC
5mo ago

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) c…

▾ AbyssalRed Hat · OpenShift ServerlessEPSS 1.9%via NVD
CVE-2026-7020Medium· 5.6PoC
5mo ago

Ollama is Vulnerable to Path Traversal

Ollama is Vulnerable to Path Traversal

▾ Twilightollama · github.com/ollama/ollamaEPSS 0.90%via OSV
CVE-2026-6951Critical· 9.8PoC
5mo ago

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the e…

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the e…

▾ Abyssalsimple-git_project · simple-gitEPSS 1.0%via NVD
CVE-2026-30368Medium· 5.4PoC
5mo ago

A client-side authorization flaw in Lightspeed Systems Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthor…

A client-side authorization flaw in Lightspeed Systems Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthor…

▾ TwilightLightspeed · Lightspeed ClassroomEPSS 0.34%via NVD
CVE-2026-41492Critical· 9.8PoC
5mo ago

Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars

Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars

▾ Abyssaldgraph-io · github.com/dgraph-io/dgraph/v25EPSS 2.5%via OSV
CVE-2026-42203HighPoC
5mo ago

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

▾ Midnightlitellm · litellmEPSS 0.66%via OSV
CVE-2026-42044Medium· 6.5PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depend…

▾ Twilightaxios · axiosEPSS 0.86%via NVD
CVE-2026-42043High· 7.2PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to complet…

▾ Midnightaxios · axiosEPSS 0.58%via NVD
CVE-2026-42041Medium· 4.8PoC⚖ disputed
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HT…

▾ Twilightaxios · axiosEPSS 0.81%via NVD
CVE-2026-42039High· 7.5PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process wi…

▾ Midnightaxios · axiosEPSS 0.97%via NVD
CVE-2026-42033High· 7.4PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) sil…

▾ Midnightaxios · axiosEPSS 0.92%via NVD
CVE-2026-41176Critical· 9.8PoC
5mo ago

Rclone is a command-line program to sync files and directories to and from different cloud storage providers

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, includin…

▾ Abyssalrclone · rcloneEPSS 3.2%via NVD
CVE-2026-41179Critical· 9.8PoC
5mo ago

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

▾ Abyssalrclone · github.com/rclone/rcloneEPSS 5.3%via OSV
CVE-2026-6857High· 7.5PoC
5mo ago

A flaw was found in camel-infinispan

A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leadin…

▾ MidnightRed Hat · camel-infinispanEPSS 1.2%via NVD
CVE-2026-31431High· 7.8CISA KEVPoC
5mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in op…

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in op…

▾ Abyssalredhat · openshift_container_platformEPSS 3.4%via NVD
CVE-2026-22016High· 7.5PoC
5mo ago

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, …

▾ Midnightoracle · jreEPSS 0.70%via NVD
CVEs tagged “exploit-available” — page 85 · VulnSea