VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3115 CVEsRSS

CVE-2026-93742Critical· 9.9PoC
5d ago

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be init…

AbyssalTotolink · A3002MUEPSS 1.9%via NVD
CVE-2026-93741Critical· 10.0PoC
5d ago

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It…

AbyssalTotolink · A3002MUEPSS 0.64%via NVD
CVE-2026-89274Critical· 9.1PoC
5d ago

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()…

Abyssalbrechtvds · WP Recipe MakerEPSS 0.38%via NVD
CVE-2026-92229Critical· 9.1PoC
5d ago

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to e…

Abyssalwpmudev · Forminator Forms – Contact Form, Payment Form & Custom Form BuilderEPSS 0.40%via NVD
CVE-2026-84434Critical· 9.8PoC
5d ago

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persis…

AbyssalGravity Forms · Gravity FormsEPSS 2.8%via NVD
CVE-2026-93922High· 8.8PoC
5d ago

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that exec…

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.54%via NVD
CVE-2026-93923High· 8.8PoC
5d ago

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject maliciou…

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.41%via NVD
CVE-2026-93921Medium· 4.3PoC
5d ago

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read bl…

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.23%via NVD
CVE-2026-93740Critical· 10.0PoC
6d ago

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initi…

AbyssalTotolink · A3002MUEPSS 0.61%via NVD
CVE-2026-93739Critical· 9.9PoC
6d ago

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be per…

AbyssalTotolink · A3002MUEPSS 0.49%via NVD
CVE-2026-93738Critical· 9.9PoC
6d ago

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possibl…

AbyssalTotolink · A3002MUEPSS 0.50%via NVD
CVE-2026-93562Medium· 6.5PoC
6d ago

A flaw was found in Netty's HTTP/1 decoder

A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker can inject arbit…

TwilightRed Hat · netty-codec-httpEPSS 0.34%via NVD
CVE-2026-85272Medium· 4.3PoC
6d ago

Open edX Platform enables the authoring and delivery of online learning at any scale

Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawood.1, openedx/core/lib/extract_archive.py uses _is_bad_path to validate safe_extractall targets by comparing resolved…

Twilightopenedx · openedx-platformEPSS 0.33%via NVD
CVE-2026-68928High· 8.6PoC
6d ago

Acode is a powerful text and code editor for Android

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and s…

MidnightAcode-Foundation · AcodeEPSS 0.13%via NVD
CVE-2026-93873Medium· 4.3PoC
6d ago

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-submit contact forms from attacker-controlled pages to send forged messages attri…

TwilightCotonti · CotontiEPSS 0.16%via NVD
CVE-2026-93871Medium· 5.4PoC
6d ago

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attackers can craft pa…

TwilightCotonti · CotontiEPSS 0.17%via NVD
CVE-2026-93870Medium· 4.3PoC
6d ago

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users. Attackers can craft malicious pages that auto-submit POST requests to modi…

TwilightCotonti · CotontiEPSS 0.14%via NVD
CVE-2026-93869Medium· 6.1PoC
6d ago

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers can bypass the redirect guard by sup…

TwilightCotonti · CotontiEPSS 0.22%via NVD
CVE-2026-93868High· 8.1PoC
6d ago

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the s…

MidnightCotonti · CotontiEPSS 0.61%via NVD
CVE-2026-76900Medium· 6.8PoC
6d ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In version 1.7.3, ApprovalResourceService.sendWebHook reads WebHookConfig.webHookUrl from stored approval-node configuration…

Twilight1Panel-dev · CordysCRMEPSS 0.38%via NVD
CVE-2026-63647Critical· 9.3PoC
6d ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFi…

Abyssal1Panel-dev · CordysCRMEPSS 0.47%via NVD
CVE-2026-63646Medium· 6.9PoC
6d ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, GET /mcp/form/config/{formKey} calls McpController.getMcpField without authentication because ShiroFilter.ad…

Twilight1Panel-dev · CordysCRMEPSS 0.49%via NVD
CVE-2017-20284High· 7.5PoC
6d ago

Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the…

Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the…

MidnightCaucho Technology, Inc. · ResinEPSS 0.96%via NVD
CVE-2026-93838Medium· 5.9PoC
6d ago

SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments

SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access …

Twilightsgl-project · sglangEPSS 0.46%via NVD
CVE-2026-93839Critical· 9.8PoC
6d ago

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. At…

AbyssalModelTC · LightLLMEPSS 0.60%via NVD
CVE-2026-91203Medium· 6.0PoC
6d ago

A flaw was found in cockpit-files

A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating…

TwilightRed Hat · cockpit-filesEPSS 0.07%via NVD
CVE-2023-54399Critical· 9.8PoC
6d ago

Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped

Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. An unauthentica…

AbyssalHongjing · e-HREPSS 0.42%via NVD
CVE-2019-25776High· 7.5PoC
6d ago

Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by submitting malicious input through the userIdentifiers GET parameter in the mobile plugin endpoint

Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by submitting malicious input through the userIdentifiers GET parameter in the mobile plugin endpoint. …

MidnightWeaver Network Co., Ltd. · E-cologyEPSS 0.36%via NVD
CVE-2026-93650Low· 3.7PoC
6d ago

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of…

TwilightEPSS 0.55%via NVD
CVE-2026-93753High· 7.5PoC
6d ago

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to…

MidnightTehShrike · deepmergeEPSS 0.36%via NVD
CVEs tagged “exploit-available” — page 9 · VulnSea