VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3592 CVEsRSS

CVE-2026-20805Medium· 5.5CISA KEV0dayPoC
8mo ago

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 7.2%via NVD
CVE-2025-66177High· 8.8PoC
8mo ago

There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models

There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending spec…

▾ MidnightEPSS 0.35%via NVD
CVE-2025-66698High· 8.6PoC
8mo ago

An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.

An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.

▾ Midnightsemantic-machines · vedaEPSS 0.49%via NVD
CVE-2025-63314Critical· 10.0PoC
8mo ago

A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

▾ Abyssalddsn · cm3_acora_cmsEPSS 0.29%via NVD
CVE-2025-15514High· 7.5PoC
8mo ago

Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality

Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data via the /api/chat endpoint, the applicat…

▾ Midnightollama · ollamaEPSS 0.78%via NVD
CVE-2025-68493High· 8.1PoC
8mo ago

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes th…

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes th…

▾ Midnightapache · strutsEPSS 46%via NVD
CVE-2025-59057High· 7.6PoC
8mo ago

React Router is a router for React

React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating s…

▾ Midnightshopify · react-routerEPSS 0.51%via NVD
CVE-2025-61686Critical· 9.1PoC
8mo ago

React Router is a router for React

React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/…

▾ Abyssalshopify · react-router/nodeEPSS 18%via NVD
CVE-2025-15224Low· 3.1PoC
8mo ago

When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.

When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.

▾ Twilighthaxx · curlEPSS 0.49%via NVD
CVE-2025-15079Medium· 5.3PoC
8mo ago

When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *glob…

When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *glob…

▾ Twilighthaxx · curlEPSS 0.54%via NVD
CVE-2025-65518High· 7.5PoC
8mo ago

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected…

▾ Midnightwebpros · plesk_obsidianEPSS 0.62%via NVD
CVE-2026-0650NonePoC
8mo ago

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and…

▾ TwilightEPSS 1.5%via NVD
CVE-2025-69264High· 8.8PoC
8mo ago

pnpm is a package manager

pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". Wh…

▾ Midnightpnpm · pnpmEPSS 1.0%via NVD
CVE-2025-69263High· 7.5PoC
8mo ago

pnpm is a package manager

pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when…

▾ MidnightRed Hat · pnpmEPSS 0.48%via NVD
CVE-2025-12543Critical· 9.6PoC
8mo ago

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containi…

▾ Abyssalredhat · build_of_apache_camelEPSS 1.4%via NVD
CVE-2025-68428High· 7.5PoC
8mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsani…

▾ Midnightparall · jspdfEPSS 2.2%via NVD
CVE-2025-34171Medium· 5.3PoC
8mo ago

CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration files and system debug information

CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration files and system debug information. The /v1/users/image endpoint can be abused with a us…

▾ Twilighticewhale · casaosEPSS 0.64%via NVD
CVE-2026-21445HighPoC
8mo ago

Langflow Missing Authentication on Critical API Endpoints

Langflow Missing Authentication on Critical API Endpoints

▾ Midnightlangflow-base · langflow-baseEPSS 34%via OSV
CVE-2025-69286Critical· 9.8PoC
9mo ago

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows thes…

▾ Abyssalinfiniflow · ragflowEPSS 0.79%via NVD
CVE-2025-68664Critical· 9.3PoC
9mo ago

langchain-core: LangChain: Arbitrary code execution via serialization injection (CVE-2025-68664)

A flaw was found in LangChain, a framework for building agents and LLM-powered applications. A remote attacker can exploit a serialization injection vulnerability in LangChain's `dumps()` and `dumpd()` functions. This occurs because the fu…

▾ AbyssalRed Hat · Red Hat Ansible Automation Platform 2.5EPSS 43%via CSAF
CVE-2025-65857High· 7.5PoC
9mo ago

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.

▾ Midnightxiongmaitech · xm530v200_x6-weq_8m_firmwareEPSS 0.43%via NVD
CVE-2025-65856Critical· 9.8PoC
9mo ago

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF i…

▾ Abyssalxiongmaitech · xm530v200_x6-weq_8m_firmwareEPSS 0.74%via NVD
CVE-2025-14855High· 7.2PoC
9mo ago

The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping

The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible …

▾ MidnightEPSS 0.37%via NVD
CVE-2025-14733Critical· 9.8CISA KEV0dayPoC
9mo ago

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office V…

▾ Hadalwatchguard · firewareEPSS 27%via NVD
CVE-2025-43529High· 8.8CISA KEV0dayPoC
9mo ago

A use-after-free issue was addressed with improved memory management

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing malici…

▾ AbyssalApple · SafariEPSS 8.8%via CVEORG
CVE-2025-65427Medium· 6.5PoC
9mo ago

An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to /api/login allowing attackers to brute force password enumerations.

An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to /api/login allowing attackers to brute force password enumerations.

▾ Twilightdbitnet · dbit_n300_t1_pro_firmwareEPSS 0.27%via NVD
CVE-2025-65318Critical· 9.1PoC
9mo ago

When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS…

When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS…

▾ Abyssalcanarymail · canary_mailEPSS 0.56%via NVD
CVE-2025-67906Medium· 5.4PoC
9mo ago

In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.

In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.

▾ Twilightmisp-project · mispEPSS 0.33%via NVD
CVE-2025-43520Medium· 5.5CISA KEVPoC
9mo ago

A memory corruption issue was addressed with improved memory handling

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, …

▾ MidnightApple · iOS and iPadOSEPSS 0.43%via CVEORG
CVE-2025-14174High· 8.8CISA KEV0dayPoC
9mo ago

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

▾ AbyssalGoogle · ChromeEPSS 22%via CVEORG
CVEs tagged “exploit-available” — page 95 · VulnSea