VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3554 CVEsRSS

CVE-2026-2942Critical· 9.8PoC
5mo ago

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for…

▾ AbyssalEPSS 1.1%via NVD
CVE-2026-33229Critical· 9.8PoC
5mo ago

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the…

▾ Abyssalxwiki · xwikiEPSS 1.2%via NVD
CVE-2026-3296Critical· 9.8PoC
5mo ago

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php…

▾ AbyssalEPSS 3.0%via NVD
CVE-2026-4406Medium· 4.7PoC
5mo ago

The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30

The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30. This is due to the `GFCommon::send_js…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-5865High· 8.8PoC
5mo ago

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.45%via NVD
CVE-2026-40035Critical· 9.1PoC
5mo ago

Unfurl - Werkzeug Debugger Exposure via String Config Parsing

Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-em…

▾ Abyssalobsidianforensics · dfir-unfurlEPSS 0.72%via CVEORG
CVE-2026-40036High· 7.5PoC
5mo ago

Unfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression

Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of service. Attackers can submit highly compressed payloads via URL parameters to the /json/…

▾ Midnightobsidianforensics · dfir-unfurlEPSS 0.79%via CVEORG
CVE-2026-33865Medium· 5.4PoC
5mo ago

MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface

MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can upload a malicious MLmodel file containing a payload that executes whe…

▾ Twilightlfprojects · mlflowEPSS 0.30%via NVD
CVE-2026-33033Medium· 6.5PoC
5mo ago

Django has potential DoS via MultiPartParser through crafted multipart uploads

Django has potential DoS via MultiPartParser through crafted multipart uploads

▾ Twilightdjango · djangoEPSS 0.88%via OSV
CVE-2026-39364High· 7.5PoC
5mo ago

Vite is a frontend tooling framework for JavaScript

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query par…

▾ Midnightvitejs · viteEPSS 1.5%via NVD
CVE-2026-39363High· 7.5PoC
5mo ago

Vite is a frontend tooling framework for JavaScript

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custo…

▾ Midnightvitejs · viteEPSS 2.6%via NVD
CVE-2026-33439Critical· 9.8PoC
5mo ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP…

▾ Abyssalopenidentityplatform · openamEPSS 8.4%via NVD
CVE-2025-69515Critical· 9.1PoC
5mo ago

An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.

An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.

▾ AbyssalEPSS 0.46%via NVD
CVE-2025-14857NonePoC
5mo ago

An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory write command accessible via the physical SPI interface fails to enforce write protection on the pro…

An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory write command accessible via the physical SPI interface fails to enforce write protection on the pro…

▾ TwilightEPSS 0.24%via NVD
CVE-2026-29181High· 7.5PoC
5mo ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to ampli…

▾ Midnightopentelemetry · opentelemetryEPSS 0.87%via NVD
CVE-2026-34444Critical· 10.0PoC
5mo ago

Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr

Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr

▾ Abyssallupa · lupaEPSS 0.80%via OSV
CVE-2026-34197High· 8.8CISA KEVPoC
5mo ago

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web conso…

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web conso…

▾ Abyssalapache · activemqEPSS 15%via NVD
CVE-2026-4631Critical· 9.8PoC
5mo ago

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP r…

▾ AbyssalEPSS 9.2%via NVD
CVE-2026-35030Critical· 9.1PoC
5mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers prod…

▾ Abyssallitellm · litellmEPSS 0.88%via NVD
CVE-2026-5682Low· 3.7PoC
5mo ago

A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android

A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of the file /api/endpoint of the component com.meesho.supply. Such manipulation leads to risky cryptographic algorithm. T…

▾ TwilightEPSS 0.28%via NVD
CVE-2026-35492Medium· 6.5PoC
5mo ago

kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write

kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write

▾ Twilightkedro-datasets · kedro-datasetsEPSS 0.45%via OSV
CVE-2026-35172High· 7.5PoC
5mo ago

Distribution is a toolkit to pack, ship, store, and deliver container content

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: t…

▾ Midnightdistribution · distributionEPSS 0.67%via NVD
CVE-2026-5530Medium· 6.3PoC
5mo ago

A flaw has been found in Ollama up to 0.18.1

A flaw has been found in Ollama up to 0.18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be …

▾ TwilightEPSS 0.35%via NVD
CVE-2026-40072High· 7.2PoC
5mo ago

web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling

web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling

▾ Midnightweb3 · web3EPSS 0.31%via OSV
CVE-2026-32662Medium· 5.3PoC
5mo ago

Development and test API endpoints are present that mirror production functionality.

Development and test API endpoints are present that mirror production functionality.

▾ Twilightmygardyn · cloud_apiEPSS 0.44%via NVD
CVE-2026-32646High· 7.5PoC
5mo ago

A specific administrative endpoint is accessible without proper authentication, exposing device management functions.

A specific administrative endpoint is accessible without proper authentication, exposing device management functions.

▾ Midnightmygardyn · cloud_apiEPSS 0.68%via NVD
CVE-2026-28767Medium· 5.3PoC
5mo ago

A specific administrative endpoint notifications is accessible without proper authentication.

A specific administrative endpoint notifications is accessible without proper authentication.

▾ Twilightmygardyn · cloud_apiEPSS 0.53%via NVD
CVE-2026-28766Critical· 9.3PoC
5mo ago

A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

▾ Abyssalmygardyn · cloud_apiEPSS 0.60%via NVD
CVE-2026-25197Critical· 9.1PoC
5mo ago

A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

▾ Abyssalmygardyn · cloud_apiEPSS 0.29%via NVD
CVE-2025-10681High· 8.6PoC
5mo ago

Storage credentials are hardcoded in the mobile app and device firmware

Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not expire within a reasonable amount of time. This vulnerability may grant unauthorized acces…

▾ MidnightEPSS 0.34%via NVD
CVEs tagged “exploit-available” — page 87 · VulnSea