VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3559 CVEsRSS

CVE-2026-23005NonePoC
8mo ago

x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state whenever XFD[i]=1

In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state whenever XFD[i]=1 When loading guest XSAVE state via KVM_SET_XSAVE, and when updating XFD in response to a guest WRMSR…

▾ TwilightLinux · LinuxEPSS 0.22%via CVEORG
CVE-2026-23003High· 7.5PoC
8mo ago

ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv()

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() Blamed commit did not take care of VLAN encapsulations as spotted by syzbot [1]. Use skb_vlan_inet_prepare(…

▾ MidnightLinux · LinuxEPSS 0.52%via CVEORG
CVE-2026-0766NonePoC
8mo ago

Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design,…

Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design,…

▾ TwilightEPSS 26%via NVD
CVE-2026-24423Critical· 9.8CISA KEVPoC
8mo ago

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the …

▾ Hadalsmartertools · smartermailEPSS 88%via NVD
CVE-2026-0770HighCISA KEV0dayPoC
8mo ago

Langflow affected by Remote Code Execution via validate_code() exec()

Langflow affected by Remote Code Execution via validate_code() exec()

▾ Abyssallangflow · langflowEPSS 64%via OSV
CVE-2026-0994High· 7.5PoC
8mo ago

A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth ac…

A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth ac…

▾ Midnightgoogle · protobufEPSS 0.72%via NVD
CVE-2026-0603High· 8.3PoC
8mo ago

A flaw was found in Hibernate

A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrCl…

▾ MidnightRed Hat · Red Hat JBoss EAP 7.4 ELS for RHEL 8EPSS 0.87%via NVD
CVE-2026-24332Medium· 4.3PoC
8mo ago

Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": …

Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": …

▾ TwilightDiscord · WebSocket API serviceEPSS 0.29%via CVEORG
CVE-2025-67221HighPoC
8mo ago

orjson does not limit recursion for deeply nested JSON documents

orjson does not limit recursion for deeply nested JSON documents

▾ Midnightorjson · orjsonEPSS 0.64%via OSV
CVE-2026-23760Critical· 9.8CISA KEVPoC
8mo ago

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a r…

▾ Hadalsmartertools · smartermailEPSS 97%via NVD
CVE-2026-24009High· 8.1PoC
8mo ago

docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage

docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage

▾ Midnightdocling-core · docling-coreEPSS 1.6%via OSV
CVE-2026-24049High· 7.1PoC
8mo ago

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after e…

▾ Midnightwheel_project · wheelEPSS 0.36%via NVD
CVE-2026-22807High· 8.8PoC
8mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_…

▾ Midnightvllm · vllmEPSS 0.83%via NVD
CVE-2025-13465Medium· 5.3PoC
8mo ago

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion …

▾ Twilightlodash · lodashEPSS 1.8%via NVD
CVE-2026-21962Critical· 10.0CISA KEVPoC
8mo ago

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versio…

▾ Hadaloracle · http_serverEPSS 71%via NVD
CVE-2026-23842High· 7.5PoC
8mo ago

ChatterBot Vulnerable to Denial of Service via Database Connection Pool Exhaustion

ChatterBot Vulnerable to Denial of Service via Database Connection Pool Exhaustion

▾ Midnightchatterbot · chatterbotEPSS 0.55%via OSV
CVE-2025-55130Critical· 9.1PoC
8mo ago

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the curren…

▾ Abyssalnodejs · node.jsEPSS 1.7%via NVD
CVE-2025-56005Critical· 9.8PoC⚖ disputed
8mo ago

An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function

An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized with `pick…

▾ Abyssaldabeaz · plyEPSS 19%via NVD
CVE-2025-68616High· 7.5PoC
8mo ago

WeasyPrint helps web developers to create PDF documents

WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in WeasyPrint's `default_url_fetcher`. The vulnerability allows attackers to access internal ne…

▾ Midnightkozea · weasyprintEPSS 0.71%via NVD
CVE-2026-23745Medium· 6.1PoC
8mo ago

node-tar is a Tar for Node.js

node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass…

▾ Twilightisaacs · tarEPSS 0.38%via NVD
CVE-2026-23490High· 7.5PoC
8mo ago

pyasn1 is a generic ASN.1 library for Python

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

▾ Midnightpyasn1 · pyasn1EPSS 0.77%via NVD
CVE-2026-0897High· 7.5PoC
8mo ago

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a c…

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a c…

▾ Midnightkeras · kerasEPSS 0.34%via NVD
CVE-2025-12548Critical· 9.0PoC
8mo ago

A flaw was found in Eclipse Che che-machine-exec

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unau…

▾ AbyssalRed Hat · devspaces/code-rhel9EPSS 1.3%via NVD
CVE-2026-0716Medium· 4.8PoC
8mo ago

A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages

A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. T…

▾ TwilightRed Hat · libsoup3EPSS 0.39%via NVD
CVE-2025-25249High· 8.1CISA KEVPoC
8mo ago

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…

▾ Abyssalfortinet · fortiswitchmanagerEPSS 3.9%via NVD
CVE-2026-20820High· 7.8PoC
8mo ago

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 2.6%via NVD
CVE-2026-20817High· 7.8PoC
8mo ago

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

▾ Midnightmicrosoft · windows_10_21h2EPSS 5.5%via NVD
CVE-2026-20805Medium· 5.5CISA KEV0dayPoC
8mo ago

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 7.2%via NVD
CVE-2025-66177High· 8.8PoC
8mo ago

There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models

There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending spec…

▾ MidnightEPSS 0.35%via NVD
CVE-2025-66698High· 8.6PoC
8mo ago

An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.

An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.

▾ Midnightsemantic-machines · vedaEPSS 0.49%via NVD
CVEs tagged “exploit-available” — page 93 · VulnSea