VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3558 CVEsRSS

CVE-2025-70148High· 7.5PoC
7mo ago

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated…

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated…

▾ Midnightcodeastro · membership_management_systemEPSS 0.43%via NVD
CVE-2026-2670High· 7.2PoC
7mo ago

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

▾ MidnightEPSS 3.6%via NVD
CVE-2026-26731High· 8.8PoC
7mo ago

TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.

TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.

▾ Midnighttotolink · a3002ru_firmwareEPSS 1.3%via NVD
CVE-2026-24126Medium· 6.6PoC
7mo ago

Weblate has an argument injection in management console

Weblate has an argument injection in management console

▾ Twilightweblate · weblateEPSS 0.47%via OSV
CVE-2026-2441High· 8.8CISA KEVPoC
7mo ago

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

▾ AbyssalGoogle · ChromeEPSS 55%via CVEORG
CVE-2026-23111High· 7.8PoC
7mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-…

▾ Midnightlinux · linux_kernelEPSS 0.49%via NVD
CVE-2026-2005High· 8.8PoC
7mo ago

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

▾ Midnightpostgresql · postgresqlEPSS 1.3%via NVD
CVE-2026-26190Critical· 9.8PoC
7mo ago

Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise

Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise

▾ Abyssalmilvus-io · github.com/milvus-io/milvusEPSS 4.0%via OSV
CVE-2026-26157High· 7.0PoC
7mo ago

A flaw was found in BusyBox

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended dire…

▾ MidnightEPSS 0.60%via NVD
CVE-2025-69873Low· 2.9PoC
7mo ago

ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled

ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which i…

▾ Twilightajv.js · ajvEPSS 0.50%via NVD
CVE-2026-25890High· 8.1PoC
7mo ago

File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL

File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL

▾ Midnightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.55%via OSV
CVE-2026-0651High· 7.8PoC
7mo ago

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and fa…

▾ Midnighttp-link · tapo_c260_firmwareEPSS 0.32%via NVD
CVE-2026-1529High· 8.1PoC
7mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verifica…

▾ MidnightEPSS 0.46%via NVD
CVE-2026-2015Medium· 6.3PoC
7mo ago

A weakness has been identified in Portabilis i-Educar up to 2.10

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead …

▾ Twilightportabilis · i-educarEPSS 0.31%via NVD
CVE-2026-1337Medium· 5.4PoC
7mo ago

Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML

Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j prod…

▾ Twilightneo4j · neo4jEPSS 0.23%via NVD
CVE-2026-24514Medium· 6.5PoC
7mo ago

ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling

ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling

▾ Twilightingress-nginx · k8s.io/ingress-nginxEPSS 0.49%via OSV
CVE-2025-69848Medium· 5.4PoC
7mo ago

NetBox is an open-source infrastructure resource modeling and IP address management platform

NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object…

▾ Twilightnetbox · netboxEPSS 0.31%via NVD
CVE-2026-1312Medium· 5.4PoC
7mo ago

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, w…

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, w…

▾ Twilightdjangoproject · djangoEPSS 0.85%via NVD
CVE-2026-1207Medium· 5.4PoC
7mo ago

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupport…

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupport…

▾ Twilightdjangoproject · djangoEPSS 13%via NVD
CVE-2026-22778Critical· 9.8PoC
7mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a hea…

▾ Abyssalvllm · vllmEPSS 10%via NVD
CVE-2026-25211Low· 3.2PoC
8mo ago

Llama Stack exposes secret in initialization log

Llama Stack exposes secret in initialization log

▾ Twilightllama-stack · llama-stackEPSS 0.24%via OSV
CVE-2025-24293High· 8.1PoC
8mo ago

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…

▾ MidnightEPSS 5.5%via NVD
CVE-2020-36939High· 7.5PoC
8mo ago

Cassandra Web - Remote File Read

Cassandra Web - Remote File Read

▾ Midnightcassandra-web · cassandra-webEPSS 2.9%via GHSA
CVE-2025-15467High· 8.8PoC
8mo ago

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, …

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, …

▾ Midnightopenssl · opensslEPSS 52%via NVD
CVE-2026-21721High· 8.1PoC
8mo ago

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on ot…

▾ Midnightgrafana · grafanaEPSS 0.73%via NVD
CVE-2026-24486High· 8.6PoC
8mo ago

Python-Multipart is a streaming multipart parser for Python

Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write …

▾ Midnightfastapiexpert · python-multipartEPSS 2.2%via NVD
CVE-2026-24688MediumPoC
8mo ago

pypdf has possible Infinite Loop when processing outlines/bookmarks

pypdf has possible Infinite Loop when processing outlines/bookmarks

▾ Twilightpypdf · pypdfEPSS 0.45%via OSV
CVE-2026-21509High· 7.8CISA KEV0dayPoC
8mo ago

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

▾ Abyssalmicrosoft · 365_appsEPSS 71%via NVD
CVE-2026-23010High· 7.8PoC
8mo ago

ipv6: Fix use-after-free in inet6_addr_del().

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix use-after-free in inet6_addr_del(). syzbot reported use-after-free of inet6_ifaddr in inet6_addr_del(). [0] The cited commit accidentally moved ipv6_del_add…

▾ MidnightLinux · LinuxEPSS 0.20%via CVEORG
CVE-2026-23005NonePoC
8mo ago

x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state whenever XFD[i]=1

In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state whenever XFD[i]=1 When loading guest XSAVE state via KVM_SET_XSAVE, and when updating XFD in response to a guest WRMSR…

▾ TwilightLinux · LinuxEPSS 0.22%via CVEORG
CVEs tagged “exploit-available” — page 92 · VulnSea