Tagged “exploit-available”
CVEs tagged exploit-available, newest first.
3554 CVEsRSS
CVE-2026-2942Critical· 9.8PoCThe ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for…
CVE-2026-33229Critical· 9.8PoCXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the…
CVE-2026-3296Critical· 9.8PoCThe Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata
The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php…
CVE-2026-4406Medium· 4.7PoCThe Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30
The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30. This is due to the `GFCommon::send_js…
CVE-2026-5865High· 8.8PoCType Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-40035Critical· 9.1PoCUnfurl - Werkzeug Debugger Exposure via String Config Parsing
Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-em…
CVE-2026-40036High· 7.5PoCUnfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression
Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of service. Attackers can submit highly compressed payloads via URL parameters to the /json/…
CVE-2026-33865Medium· 5.4PoCMLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface
MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can upload a malicious MLmodel file containing a payload that executes whe…
CVE-2026-33033Medium· 6.5PoCDjango has potential DoS via MultiPartParser through crafted multipart uploads
Django has potential DoS via MultiPartParser through crafted multipart uploads
CVE-2026-39364High· 7.5PoCVite is a frontend tooling framework for JavaScript
Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query par…
CVE-2026-39363High· 7.5PoCVite is a frontend tooling framework for JavaScript
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custo…
CVE-2026-33439Critical· 9.8PoCOpen Access Management (OpenAM) is an access management solution
Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP…
CVE-2025-69515Critical· 9.1PoCAn issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.
An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.
CVE-2025-14857NonePoCAn improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory write command accessible via the physical SPI interface fails to enforce write protection on the pro…
An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory write command accessible via the physical SPI interface fails to enforce write protection on the pro…
CVE-2026-29181High· 7.5PoCOpenTelemetry-Go is the Go implementation of OpenTelemetry
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to ampli…
CVE-2026-34444Critical· 10.0PoCLupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
CVE-2026-34197High· 8.8CISA KEVPoCImproper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web conso…
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web conso…
CVE-2026-4631Critical· 9.8PoCCockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization
Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP r…
CVE-2026-35030Critical· 9.1PoCLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers prod…
CVE-2026-5682Low· 3.7PoCA vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android
A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of the file /api/endpoint of the component com.meesho.supply. Such manipulation leads to risky cryptographic algorithm. T…
CVE-2026-35492Medium· 6.5PoCkedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
CVE-2026-35172High· 7.5PoCDistribution is a toolkit to pack, ship, store, and deliver container content
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: t…
CVE-2026-5530Medium· 6.3PoCA flaw has been found in Ollama up to 0.18.1
A flaw has been found in Ollama up to 0.18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be …
CVE-2026-40072High· 7.2PoCweb3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling
web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling
CVE-2026-32662Medium· 5.3PoCDevelopment and test API endpoints are present that mirror production functionality.
Development and test API endpoints are present that mirror production functionality.
CVE-2026-32646High· 7.5PoCA specific administrative endpoint is accessible without proper authentication, exposing device management functions.
A specific administrative endpoint is accessible without proper authentication, exposing device management functions.
CVE-2026-28767Medium· 5.3PoCA specific administrative endpoint notifications is accessible without proper authentication.
A specific administrative endpoint notifications is accessible without proper authentication.
CVE-2026-28766Critical· 9.3PoCA specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
CVE-2026-25197Critical· 9.1PoCA specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.
A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.
CVE-2025-10681High· 8.6PoCStorage credentials are hardcoded in the mobile app and device firmware
Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not expire within a reasonable amount of time. This vulnerability may grant unauthorized acces…