VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3554 CVEsRSS

CVE-2026-33870High· 7.5PoC
6mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request s…

▾ Midnightnetty · nettyEPSS 0.70%via NVD
CVE-2026-33941High· 8.2PoC
6mo ago

Handlebars provides the power necessary to let users build semantic templates

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file…

▾ Midnighthandlebarsjs · handlebarsEPSS 0.22%via NVD
CVE-2026-33937Critical· 9.8PoC
6mo ago

Handlebars provides the power necessary to let users build semantic templates

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field of a `NumberLitera…

▾ Abyssalhandlebarsjs · handlebarsEPSS 1.7%via NVD
CVE-2026-33894High· 7.5PoC
6mo ago

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attack…

▾ Midnightdigitalbazaar · forgeEPSS 0.45%via NVD
CVE-2026-27876Critical· 9.1PoC
6mo ago

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE)

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future…

▾ AbyssalEPSS 1.4%via NVD
CVE-2026-23398NonePoC
6mo ago

icmp: fix NULL pointer dereference in icmp_tag_validation()

In the Linux kernel, the following vulnerability has been resolved: icmp: fix NULL pointer dereference in icmp_tag_validation() icmp_tag_validation() unconditionally dereferences the result of rcu_dereference(inet_protos[proto]) withou…

▾ TwilightLinux · LinuxEPSS 0.12%via CVEORG
CVE-2026-33487High· 7.5PoC
6mo ago

goxmlsig provides XML Digital Signatures implemented in Go

goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID.…

▾ Midnightgoxmldsig_project · goxmldsigEPSS 0.42%via NVD
CVE-2026-32285High· 7.5PoC
6mo ago

The Delete function fails to properly validate offsets when processing malformed JSON input

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

▾ Midnightjsonparser_project · jsonparserEPSS 0.97%via NVD
CVE-2026-32286High· 7.5PoC
6mo ago

The DataRow.Decode function fails to properly validate field lengths

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

▾ Midnightjackc · pgproto3EPSS 0.92%via NVD
CVE-2026-1961High· 8.0PoC
6mo ago

A flaw was found in Foreman

A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resou…

▾ MidnightEPSS 1.4%via NVD
CVE-2026-27889High· 7.5PoC
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic…

▾ Midnightlinuxfoundation · nats-serverEPSS 0.84%via NVD
CVE-2026-25645Medium· 4.4PoC
6mo ago

Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function

Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function

▾ Twilightrequests · requestsEPSS 0.18%via OSV
CVE-2026-33634CriticalCISA KEVPoC
6mo ago

Trivy ecosystem supply chain was briefly compromised

Trivy ecosystem supply chain was briefly compromised

▾ Hadalaquasecurity · github.com/aquasecurity/trivyEPSS 1.7%via OSV
CVE-2026-23921High· 8.8PoC
6mo ago

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned dire…

▾ Midnightzabbix · zabbixEPSS 3.5%via NVD
CVE-2026-22739High· 8.6PoC
6mo ago

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configu…

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configu…

▾ Midnightvmware · spring_cloud_configEPSS 1.2%via NVD
CVE-2026-4602High· 7.5PoC
6mo ago

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and brea…

▾ Midnightkjur · jsrsasignEPSS 0.88%via NVD
CVE-2026-4598High· 7.5PoC
6mo ago

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang th…

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang th…

▾ Midnightkjur · jsrsasignEPSS 0.96%via NVD
CVE-2026-4600High· 7.4PoC
6mo ago

Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/ds…

Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/ds…

▾ Midnightkjur · jsrsasignEPSS 0.32%via NVD
CVE-2026-33154High· 7.5PoC
6mo ago

dynaconf: jinja2: Dynaconf: Arbitrary code execution via Server-Side Template Injection (CVE-2026-33154)

A flaw was found in dynaconf, a Python configuration management tool. This Server-Side Template Injection (SSTI) vulnerability occurs due to unsafe template evaluation in the @Jinja resolver when the jinja2 package is installed. A remote a…

▾ MidnightRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.57%via CSAF
CVE-2026-33231High· 7.5PoC
6mo ago

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthentic…

▾ Midnightnltk · nltkEPSS 1.5%via NVD
CVE-2026-33186Critical· 9.1PoC
6mo ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logi…

▾ Abyssalgrpc · grpcEPSS 1.6%via NVD
CVE-2026-33320Medium· 6.2PoC
6mo ago

Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service

Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service

▾ Twilighttomwright · github.com/tomwright/dasel/v3EPSS 0.17%via OSV
CVE-2025-71259Medium· 4.3PoC
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from th…

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from th…

▾ Twilightbmc · footprintsEPSS 13%via NVD
CVE-2025-71258Medium· 4.3PoC
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound re…

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound re…

▾ Twilightbmc · footprintsEPSS 17%via NVD
CVE-2025-71257High· 7.3PoC
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated remote attackers can…

▾ Midnightbmc · footprintsEPSS 45%via NVD
CVE-2026-33310High· 8.8PoC
6mo ago

Intake has a Command Injection via shell() Expansion in Parameter Defaults

Intake has a Command Injection via shell() Expansion in Parameter Defaults

▾ Midnightintake · intakeEPSS 0.49%via OSV
CVE-2026-30922High· 7.5PoC
6mo ago

pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)

An unbounded recursion flaw has been discovered in the pypi pyasn1 library. This uncontrolled recursion occurs when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing nested SEQUENCE (0x3…

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.93%via CSAF
CVE-2026-32596HighPoC
6mo ago

Glances exposes the REST API without authentication

Glances exposes the REST API without authentication

▾ Midnightglances · glancesEPSS 1.7%via OSV
CVE-2026-32722Low· 3.6PoC
6mo ago

Stored XSS in Memray-generated HTML reports via unescaped command-line metadata

Stored XSS in Memray-generated HTML reports via unescaped command-line metadata

▾ Twilightmemray · memrayEPSS 0.35%via OSV
CVE-2025-50881High· 8.8PoC
6mo ago

The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution

The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution. When handling GET requests, the script takes user-supplied input from the `action` URL parameter, performs i…

▾ MidnightEPSS 0.61%via NVD
CVEs tagged “exploit-available” — page 89 · VulnSea