VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3598 CVEsRSS

CVE-2025-54381Critical· 9.9PoC
1y ago

BentoML SSRF Vulnerability in File Upload Processing

BentoML SSRF Vulnerability in File Upload Processing

▾ Abyssalbentoml · bentomlEPSS 15%via OSV
CVE-2025-7404MediumPoC
1y ago

Calibre Web and Autocaliweb have OS Command Injection vulnerability

Calibre Web and Autocaliweb have OS Command Injection vulnerability

▾ Twilightcalibreweb · calibrewebEPSS 2.8%via OSV
CVE-2025-6998HighPoC
1y ago

Calibre Web and Autocaliweb have a ReDoS vulnerability

Calibre Web and Autocaliweb have a ReDoS vulnerability

▾ Midnightcalibreweb · calibrewebEPSS 0.84%via OSV
CVE-2016-15044NonePoC
1y ago

A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module

A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module. An unauthenticated remote attacker can exploit this issue by send…

▾ TwilightEPSS 2.1%via NVD
CVE-2025-6018High· 7.8PoC
1y ago

A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM)

A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw allows an unprivileged local attacker (for example, a user logged in via SSH) to obtain the…

▾ Midnightsuse · pam-configEPSS 1.1%via NVD
CVE-2025-38352High· 7.8CISA KEVPoC
1y ago

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls ha…

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls ha…

▾ Abyssallinux · linux_kernelEPSS 1.3%via NVD
CVE-2025-53770Critical· 9.8CISA KEV0dayPoC
1y ago

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing…

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing…

▾ Hadalmicrosoft · sharepoint_serverEPSS 100%via NVD
CVE-2015-10138Critical· 9.8PoC
1y ago

The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2

The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it p…

▾ Abyssallyntonreed · work_the_flow_file_uploadEPSS 3.6%via NVD
CVE-2025-3415Medium· 4.3PoC
1y ago

Grafana's insecure DingDing Alert integration exposes sensitive information

Grafana's insecure DingDing Alert integration exposes sensitive information

▾ Twilightgrafana · github.com/grafana/grafanaEPSS 0.98%via OSV
CVE-2025-34126NonePoC
1y ago

A path traversal vulnerability exists in RIPS Scanner version 0.54

A path traversal vulnerability exists in RIPS Scanner version 0.54. The vulnerability allows remote attackers to read arbitrary files on the system with the privileges of the web server by sending crafted HTTP GET requests to the 'window…

▾ TwilightEPSS 2.1%via NVD
CVE-2025-6558High· 8.8CISA KEVPoC
1y ago

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 9.6%via NVD
CVE-2025-34115High· 8.7PoC
1y ago

An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint

An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' featur…

▾ MidnightITRS Group · OP5 MonitorEPSS 3.6%via NVD
CVE-2025-6965High· 7.7PoC
1y ago

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

▾ Midnightsqlite · sqliteEPSS 73%via NVD
CVE-2025-53640MediumPoC
1y ago

Indico vulnerability allows attackers to bulk dump user details

Indico vulnerability allows attackers to bulk dump user details

▾ Twilightindico · indicoEPSS 0.60%via OSV
CVE-2025-51591Low· 3.7PoC
1y ago

A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe

A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. Note: Some users have stated that Pandoc by default can retrieve and par…

▾ TwilightEPSS 0.66%via NVD
CVE-2025-7425High· 7.8PoC
1y ago

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the pro…

▾ MidnightGNOME · libxml2EPSS 0.42%via NVD
CVE-2025-48384High· 8.0CISA KEVPoC
1y ago

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return a…

▾ Abyssalgit-scm · gitEPSS 4.1%via NVD
CVE-2025-53547High· 8.5PoC
1y ago

helm.sh/helm/v3: Helm Chart Code Execution (CVE-2025-53547)

A command injection vulnerability has been identified in Helm, a package manager for Kubernetes. An attacker can craft a malicious Chart.yaml file with specially linked dependencies in a Chart.lock file. If the Chart.lock file is a symboli…

▾ MidnightRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9EPSS 0.41%via CSAF
CVE-2025-49706Medium· 6.5CISA KEVPoC
1y ago

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

▾ Midnightmicrosoft · sharepoint_enterprise_serverEPSS 99%via NVD
CVE-2025-34088High· 8.8PoC
1y ago

An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier

An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrary OS commands via the select_ips parameter when performin…

▾ Midnightpandorafms · pandora_fmsEPSS 7.3%via NVD
CVE-2025-4334Critical· 9.8PoC
1y ago

The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3

The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. Thi…

▾ Abyssalnajeebmedia · memberheroEPSS 2.6%via NVD
CVE-2025-34037NonePoC
1y ago

An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080

An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the …

▾ TwilightEPSS 93%via NVD
CVE-2025-44203High· 7.5PoC
1y ago

In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking

In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a…

▾ Midnightdigitaldruid · hoteldruidEPSS 0.57%via NVD
CVE-2025-6019High· 7.0PoC
1y ago

A Local Privilege Escalation (LPE) vulnerability was found in libblockdev

A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev in…

▾ MidnightEPSS 0.47%via NVD
CVE-2025-5777High· 7.5CISA KEVPoC
1y ago

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

▾ Abyssalcitrix · netscaler_application_delivery_controllerEPSS 100%via NVD
CVE-2025-4404Critical· 9.1PoC
1y ago

A privilege escalation from host to domain vulnerability was found in the FreeIPA project

A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services…

▾ AbyssalEPSS 2.0%via NVD
CVE-2025-6021High· 7.5PoC
1y ago

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafte…

▾ Midnightxmlsoft · libxml2EPSS 1.4%via NVD
CVE-2025-5915Medium· 6.6PoC
1y ago

A vulnerability has been identified in the libarchive library

A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may…

▾ Twilightlibarchive · libarchiveEPSS 0.19%via NVD
CVE-2025-5914High· 7.8PoC
1y ago

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a…

▾ Midnightlibarchive · libarchiveEPSS 0.44%via NVD
CVE-2025-49619High· 8.5PoC
1y ago

Skyvern has a Jinja runtime leak

Skyvern has a Jinja runtime leak

▾ Midnightskyvern · skyvernEPSS 20%via OSV
CVEs tagged “exploit-available” — page 100 · VulnSea