VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3554 CVEsRSS

CVE-2026-0545Critical· 9.8PoC
5mo ago

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job e…

▾ Abyssallfprojects · mlflowEPSS 4.4%via NVD
CVE-2026-4350High· 8.1PoC
5mo ago

The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1

The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter…

▾ MidnightEPSS 0.53%via NVD
CVE-2026-33752High· 8.6PoC
5mo ago

curl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)

curl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)

▾ Midnightcurl-cffi · curl-cffiEPSS 0.45%via OSV
CVE-2026-34753Medium· 5.4PoC
5mo ago

vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `

vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `

▾ Twilightvllm · vllmEPSS 0.30%via OSV
CVE-2026-35029HighPoC
5mo ago

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

▾ Midnightlitellm · litellmEPSS 4.0%via OSV
CVE-2026-31402Critical· 9.8PoC
5mo ago

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_REPLAY_ISIZE]) to store encoded operat…

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_REPLAY_ISIZE]) to store encoded operat…

▾ Abyssallinux · linux_kernelEPSS 0.58%via NVD
CVE-2026-34976Critical· 10.0PoC
5mo ago

Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization

Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization

▾ Abyssaldgraph-io · github.com/dgraph-io/dgraph/v25EPSS 1.7%via OSV
CVE-2026-5281High· 8.8CISA KEV0dayPoC
6mo ago

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 0.70%via NVD
CVE-2026-34040High· 8.4PoC
6mo ago

Moby: Moby: Authorization bypass vulnerability (CVE-2026-34040)

A flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container enviro…

▾ MidnightRed Hat · Multicluster Global Hub 1.4.9EPSS 0.16%via CSAF
CVE-2026-34453High· 7.5PoC
6mo ago

SiYuan is a personal knowledge management system

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks from password-protected documents to unauthenticated visitors. In publish/read-only mode, /api/bookmark/getBookmark f…

▾ Midnightb3log · siyuanEPSS 1.5%via NVD
CVE-2026-34156Critical· 9.9PoC
6mo ago

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js vm sandbox with …

▾ Abyssalnocobase · nocobaseEPSS 6.8%via NVD
CVE-2026-34200High· 7.5PoC
6mo ago

Nhost is an open source Firebase alternative with GraphQL

Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nhost CLI MCP server, when explicitly configured to listen on a network port, applies no inbound authentication and does not enforce strict CORS. Thi…

▾ Midnightnhost · cliEPSS 0.60%via NVD
CVE-2026-33579Critical· 9.9PoC
6mo ago

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can…

▾ Abyssalopenclaw · openclawEPSS 0.51%via NVD
CVE-2026-5203Medium· 4.7PoC
6mo ago

A vulnerability was found in CMS Made Simple up to 2.2.22

A vulnerability was found in CMS Made Simple up to 2.2.22. This impacts the function _copyFilesToFolder in the library modules/UserGuide/lib/class.UserGuideImporterExporter.php of the component UserGuide Module XML Import. The manipulati…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-34243Critical· 9.8PoC
6mo ago

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title)

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell com…

▾ Abyssalnjzjz · wenxianEPSS 2.8%via NVD
CVE-2026-34227High· 8.8PoC
6mo ago

Sliver is a command and control framework that uses a custom Wireguard netstack

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beaco…

▾ Midnightbishopfox · sliverEPSS 0.47%via NVD
CVE-2026-34220Critical· 9.8PoC
6mo ago

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpreted as raw SQL q…

▾ Abyssalmikro-orm · mikroormEPSS 0.47%via NVD
CVE-2026-0596High· 7.8PoC
6mo ago

A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`

A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into a shell command executed via `bash -c` without proper sanitization. If the `model_uri` …

▾ Midnightlfprojects · mlflowEPSS 1.3%via NVD
CVE-2026-32794Medium· 4.8PoC
6mo ago

Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange

Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange

▾ Twilightapache-airflow · apache-airflowEPSS 0.43%via OSV
CVE-2026-34070High· 7.5PoC
6mo ago

LangChain is a framework for building agents and LLM-powered applications

LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating again…

▾ Midnightlangchain · langchain_coreEPSS 1.2%via NVD
CVE-2026-4800High· 8.1PoC
6mo ago

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the s…

▾ Midnightlodash · lodashEPSS 2.6%via NVD
CVE-2026-21710High· 7.5PoC
6mo ago

A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `O…

A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `O…

▾ Midnightnodejs · node.jsEPSS 25%via NVD
CVE-2026-21717Medium· 5.9PoC
6mo ago

A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable

A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, …

▾ Twilightnodejs · node.jsEPSS 0.27%via NVD
CVE-2026-33641High· 7.8PoC
6mo ago

Glances Vulnerable to Command Injection via Dynamic Configuration Values

Glances Vulnerable to Command Injection via Dynamic Configuration Values

▾ Midnightglances · glancesEPSS 0.78%via OSV
CVE-2026-0560High· 7.5PoC
6mo ago

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/exp…

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails …

▾ Midnightlollms · lollmsEPSS 1.8%via OSV
CVE-2026-0558Critical· 9.8PoC
6mo ago

A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through t…

A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other f…

▾ Abyssallollms · lollmsEPSS 2.0%via OSV
CVE-2026-5027High· 8.8PoC
6mo ago

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

▾ Midnightlangflow · langflowEPSS 4.8%via NVD
CVE-2026-33701Critical· 9.8PoC
6mo ago

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data with…

▾ Abyssallinuxfoundation · opentelemetry_instrumentation_for_javaEPSS 1.1%via NVD
CVE-2026-33980High· 8.3PoC
6mo ago

Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries

Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries

▾ Midnightadx-mcp-server · adx-mcp-serverEPSS 0.43%via OSV
CVE-2026-33936Medium· 5.3PoC
6mo ago

python-ecdsa: Denial of Service via improper DER length validation in crafted private keys

python-ecdsa: Denial of Service via improper DER length validation in crafted private keys

▾ Twilightecdsa · ecdsaEPSS 0.52%via OSV
CVEs tagged “exploit-available” — page 88 · VulnSea