VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3558 CVEsRSS

CVE-2025-66024Critical· 9.0PoC
6mo ago

The XWiki blog application allows users of the XWiki platform to create and manage blog posts

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability…

▾ Abyssalxwiki · blog_applicationEPSS 0.36%via NVD
CVE-2026-20079Critical· 10.0CISA KEVPoC
6mo ago

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …

▾ Hadalcisco · secure_firewall_management_centerEPSS 88%via NVD
CVE-2026-0014Medium· 6.2PoC
7mo ago

In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation

In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interactio…

▾ Twilightgoogle · androidEPSS 0.11%via NVD
CVE-2026-0013High· 8.4PoC
7mo ago

In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy

In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User inter…

▾ Midnightgoogle · androidEPSS 0.16%via NVD
CVE-2026-0010High· 8.4PoC
7mo ago

In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check

In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…

▾ Midnightgoogle · androidEPSS 0.12%via NVD
CVE-2026-2256Medium· 6.5PoC
7mo ago

MS-Agent vulnerable to Command Injection

MS-Agent vulnerable to Command Injection

▾ Twilightms-agent · ms-agentEPSS 1.6%via OSV
CVE-2026-27941Critical· 9.9PoC
7mo ago

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repo…

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from fork…

▾ Abyssalopenlit · openlitEPSS 0.57%via OSV
CVE-2026-26986Medium· 5.5PoC
7mo ago

FreeRDP has heap-use-after-free in rail_window_free

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `rail_window_free` dereferences a freed `xfAppWindow` pointer during `HashTable_Free` cleanup because `xf_rail_window_common` calls `free(appWindow…

▾ TwilightFreeRDP · FreeRDPEPSS 0.79%via CVEORG
CVE-2026-27577Critical· 9.9PoC
7mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An authenticated user w…

▾ Abyssaln8n · n8nEPSS 1.0%via NVD
CVE-2026-26717Medium· 4.8PoC
7mo ago

OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function

OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function

▾ Twilightrichie · richieEPSS 0.51%via OSV
CVE-2026-27645Medium· 6.1PoC
7mo ago

changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.49%via OSV
CVE-2026-27727Critical· 9.8PoC
7mo ago

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked…

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked…

▾ Abyssalmchange · mchange_commons_javaEPSS 1.6%via NVD
CVE-2026-27606Critical· 9.8PoC
7mo ago

Rollup is a module bundler for JavaScript

Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure …

▾ Abyssalrollupjs · rollupEPSS 1.5%via NVD
CVE-2026-23980MediumPoC
7mo ago

Apache Superset allows privileged users to conduct error-based SQL Injection

Apache Superset allows privileged users to conduct error-based SQL Injection

▾ Twilightapache-superset · apache-supersetEPSS 0.65%via OSV
CVE-2026-27483High· 8.8PoC
7mo ago

MindsDB: Path Traversal in /api/files Leading to Remote Code Execution

MindsDB: Path Traversal in /api/files Leading to Remote Code Execution

▾ Midnightmindsdb · mindsdbEPSS 8.8%via OSV
CVE-2026-25747High· 8.8PoC
7mo ago

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without a…

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without a…

▾ Midnightapache · camelEPSS 0.89%via NVD
CVE-2026-26331High· 8.8PoC
7mo ago

yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

▾ Midnightyt-dlp · yt-dlpEPSS 2.0%via OSV
CVE-2026-25896Critical· 9.3PoC⚖ disputed
7mo ago

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard…

▾ Abyssalnaturalintelligence · fast-xml-parserEPSS 0.50%via NVD
CVE-2026-2472HighPoC
7mo ago

Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)

Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)

▾ Midnightgoogle-cloud-aiplatform · google-cloud-aiplatformEPSS 0.54%via OSV
CVE-2026-25527Medium· 5.3PoC
7mo ago

changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` ro…

changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This…

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.89%via OSV
CVE-2026-27199MediumPoC
7mo ago

Werkzeug safe_join() allows Windows special device names

Werkzeug safe_join() allows Windows special device names

▾ Twilightwerkzeug · werkzeugEPSS 0.54%via OSV
CVE-2026-25940High· 8.1PoC
7mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass u…

▾ Midnightparall · jspdfEPSS 0.63%via NVD
CVE-2026-25755High· 8.1PoC
7mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes the …

▾ Midnightparall · jspdfEPSS 0.80%via NVD
CVE-2025-70141Critical· 9.4PoC
7mo ago

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php bas…

▾ Abyssaloretnom23 · customer_support_systemEPSS 0.69%via NVD
CVE-2025-70147High· 7.5PoC
7mo ago

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET …

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET …

▾ Midnightprojectworlds · online_time_table_generatorEPSS 0.52%via NVD
CVE-2025-70146Critical· 9.1PoC
7mo ago

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting reco…

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting reco…

▾ Abyssalprojectworlds · online_time_table_generatorEPSS 0.57%via NVD
CVE-2025-70152Critical· 9.8PoC
7mo ago

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly c…

▾ Abyssalfabian · scholars_tracking_systemEPSS 0.45%via NVD
CVE-2025-70151High· 8.8PoC
7mo ago

code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload

code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-acce…

▾ Midnightfabian · scholars_tracking_systemEPSS 0.70%via NVD
CVE-2025-70150Critical· 9.8PoC
7mo ago

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.

▾ Abyssalcodeastro · membership_management_systemEPSS 0.66%via NVD
CVE-2025-70149Critical· 9.8PoC
7mo ago

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

▾ Abyssalcodeastro · membership_management_systemEPSS 0.39%via NVD
CVEs tagged “exploit-available” — page 91 · VulnSea