VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3554 CVEsRSS

CVE-2026-33626High· 7.5PoC
5mo ago

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

▾ Midnightlmdeploy · lmdeployEPSS 1.5%via GHSA
CVE-2026-41490High· 8.3PoC
5mo ago

Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations

Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations

▾ Midnightdagster-duckdb · dagster-duckdbEPSS 0.45%via OSV
CVE-2026-41242Critical· 9.8PoC
5mo ago

protobufjs compiles protobuf definitions into JavaScript (JS) functions

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decodi…

▾ Abyssalprotobufjs_project · protobufjsEPSS 0.99%via NVD
CVE-2026-40477Critical· 9.0PoC
5mo ago

Thymeleaf is a server-side Java template engine for web and standalone environments

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanism…

▾ Abyssalthymeleaf · thymeleafEPSS 0.94%via NVD
CVE-2026-1880Medium· 5.4PoC
5mo ago

An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a …

An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a …

▾ TwilightASUS · DriverHubEPSS 0.14%via NVD
CVE-2026-0827High· 7.1PoC
5mo ago

During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authentica…

During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authentica…

▾ Midnightlenovo · diagnosticsEPSS 0.21%via NVD
CVE-2026-20180Critical· 9.9PoC
5mo ago

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker mus…

▾ Abyssalcisco · identity_services_engineEPSS 6.0%via NVD
CVE-2026-26179High· 7.8PoC
5mo ago

Windows Kernel Elevation of Privilege Vulnerability

Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 11 version 22H3EPSS 0.33%via CVEORG
CVE-2026-33826High· 8.0PoC
5mo ago

Windows Active Directory Remote Code Execution Vulnerability

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

▾ MidnightMicrosoft · Windows Server 2012 R2EPSS 0.54%via CVEORG
CVE-2026-33825High· 7.8CISA KEVPoC
5mo ago

Microsoft Defender Elevation of Privilege Vulnerability

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

▾ AbyssalMicrosoft · Microsoft Defender Antimalware PlatformEPSS 0.40%via CVEORG
CVE-2026-27912High· 8.0PoC
5mo ago

Windows Kerberos Elevation of Privilege Vulnerability

Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.

▾ MidnightMicrosoft · Windows Server 2012EPSS 0.43%via CVEORG
CVE-2026-32201Medium· 6.5CISA KEV0dayPoC
5mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

▾ MidnightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.98%via CVEORG
CVE-2026-33829Medium· 4.3PoC
5mo ago

Windows Snipping Tool Spoofing Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 2.0%via CVEORG
CVE-2026-33827High· 8.1PoC
5mo ago

Windows TCP/IP Remote Code Execution Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.54%via CVEORG
CVE-2026-33824Critical· 9.8CISA KEVPoC
5mo ago

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

▾ Hadalmicrosoft · windows_10_1607EPSS 1.6%via NVD
CVE-2026-32202Medium· 4.3CISA KEVPoC
5mo ago

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 4.9%via NVD
CVE-2026-32223Medium· 6.8PoC
5mo ago

Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

▾ Twilightmicrosoft · windows_11_24h2EPSS 0.56%via NVD
CVE-2026-39808Critical· 9.8CISA KEVPoC
5mo ago

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…

▾ Hadalfortinet · fortisandboxEPSS 47%via NVD
CVE-2026-2332High· 7.4PoC
5mo ago

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/…

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/…

▾ Midnighteclipse · jettyEPSS 1.3%via NVD
CVE-2026-33555Medium· 4.0PoC
5mo ago

An issue was discovered in HAProxy before 3.3.6

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause des…

▾ Twilighthaproxy · haproxyEPSS 0.58%via NVD
CVE-2026-6111Medium· 6.3PoC
5mo ago

MetaGPT affected by server-side request forgery in metagpt/utils/common.py

MetaGPT affected by server-side request forgery in metagpt/utils/common.py

▾ Twilightmetagpt · metagptEPSS 0.37%via OSV
CVE-2026-32146High· 7.8PoC
5mo ago

Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into f…

Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into f…

▾ Midnightlpil · gleamEPSS 0.22%via NVD
CVE-2026-35204High· 8.6PoC
5mo ago

Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory

Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory

▾ Midnighthelm · helm.sh/helm/v4EPSS 0.19%via OSV
CVE-2026-40242High· 7.2PoC
5mo ago

Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint

Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint

▾ Midnightgetarcaneapp · github.com/getarcaneapp/arcane/backendEPSS 0.72%via OSV
CVE-2026-40151Medium· 5.3PoC
5mo ago

PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS

PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS

▾ Twilightpraisonai · praisonaiEPSS 0.84%via OSV
CVE-2026-40175Medium· 4.8PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inje…

▾ Twilightaxios · axiosEPSS 1.3%via NVD
CVE-2026-5724NonePoC
5mo ago

The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor

The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentication and authorization, but the streaming AdminService/S…

▾ TwilightEPSS 0.66%via NVD
CVE-2026-34486High· 7.5CISA KEVPoC
5mo ago

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …

▾ Abyssalapache · tomcatEPSS 6.6%via NVD
CVE-2025-62718Critical· 9.9PoC⚖ disputed
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a tra…

▾ Abyssalaxios · axiosEPSS 1.2%via NVD
CVE-2026-23869High· 7.5PoC
5mo ago

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.…

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.…

▾ MidnightEPSS 1.6%via NVD
CVEs tagged “exploit-available” — page 86 · VulnSea