VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3679 CVEsRSS

CVE-2025-10951High· 7.3PoC
1y ago

ml-logger has path traversal in the file argument

ml-logger has path traversal in the file argument

▾ Midnightml-logger · ml-loggerEPSS 0.61%via OSV
CVE-2025-48868High· 7.2PoC
1y ago

Horilla is a free and open source Human Resource Management System (HRMS)

Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to the unsafe use of Python’s eval() function on a user-controlled query pa…

▾ Midnighthorilla · horillaEPSS 2.5%via NVD
CVE-2025-23339Low· 3.3PoC
1y ago

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerabilit…

▾ Twilightnvidia · cuda_toolkitEPSS 0.36%via NVD
CVE-2025-20352High· 7.7CISA KEVPoC
1y ago

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of serv…

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of serv…

▾ Abyssalcisco · ios_xe_sd-wanEPSS 39%via NVD
CVE-2025-10585Critical· 9.8CISA KEV0dayPoC
1y ago

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

▾ Hadalgoogle · chromeEPSS 5.4%via NVD
CVE-2025-55887Medium· 6.1PoC
1y ago

Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD

Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD. The vulnerability exists in the transactionID GET parameter on the transaction confirmation page. Due to improper input validation and output en…

▾ Twilightard · gec_en_ligneEPSS 0.35%via NVD
CVE-2025-55888High· 7.3PoC
1y ago

Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD

Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can intercept the Ajax response and inject malicious JavaScript into the accountName field. This input is not properly s…

▾ Midnightard · gec_en_ligneEPSS 0.44%via NVD
CVE-2025-55885Medium· 6.3PoC
1y ago

SQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote attacker to escalate privileges via the GET parameters in index.php

SQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote attacker to escalate privileges via the GET parameters in index.php

▾ Twilightard · gec_en_ligneEPSS 0.36%via NVD
CVE-2025-39866High· 7.8PoC
1y ago

fs: writeback: fix use-after-free in __mark_inode_dirty()

In the Linux kernel, the following vulnerability has been resolved: fs: writeback: fix use-after-free in __mark_inode_dirty() An use-after-free issue occurred when __mark_inode_dirty() get the bdi_writeback that was in the progress of …

▾ MidnightLinux · LinuxEPSS 0.31%via CVEORG
CVE-2025-10035Critical· 10.0CISA KEVPoC
1y ago

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

▾ Hadalfortra · goanywhere_managed_file_transferEPSS 100%via NVD
CVE-2025-9216High· 8.8PoC
1y ago

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import() function in all ve…

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import() function in all ve…

▾ MidnightEPSS 0.88%via NVD
CVE-2025-59341HighPoC
1y ago

esm.sh has File Inclusion issue

esm.sh has File Inclusion issue

▾ Midnightesm-dev · github.com/esm-dev/esm.shEPSS 1.6%via OSV
CVE-2025-9242Critical· 9.8CISA KEVPoC
1y ago

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office V…

▾ Hadalwatchguard · firewareEPSS 91%via NVD
CVE-2025-59376Medium· 5.3PoC
1y ago

mcp-kubernetes-server has a Command Injection vulnerability

mcp-kubernetes-server has a Command Injection vulnerability

▾ Twilightmcp-kubernetes-server · mcp-kubernetes-serverEPSS 0.30%via OSV
CVE-2025-57174Critical· 9.8PoC
1y ago

An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions

An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions. The rfpiped service listening on TCP port 555 which uses static AES encryption keys …

▾ AbyssalEPSS 2.2%via NVD
CVE-2025-10211Medium· 6.3PoC
1y ago

A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0

A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/collect/getArticle. The manipulation of the argument taskUrl leads to server-side request f…

▾ Twilightchancms · chancmsEPSS 0.70%via NVD
CVE-2025-10210Medium· 6.3PoC
1y ago

A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0

A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argument key can lead to sql injection. The attack can be launc…

▾ Twilightchancms · chancmsEPSS 1.3%via NVD
CVE-2025-10200High· 8.8PoC
1y ago

Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page

Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.57%via NVD
CVE-2025-8889Low· 3.8PoC
1y ago

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in mu…

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in mu…

▾ Twilighteliehanna · compress_&_uploadEPSS 0.29%via NVD
CVE-2025-58180High· 8.8PoC
1y ago

OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload

OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload

▾ Midnightoctoprint · octoprintEPSS 21%via OSV
CVE-2025-57833High· 7.1PoC
1y ago

Django is subject to SQL injection through its column aliases

Django is subject to SQL injection through its column aliases

▾ Midnightdjango · djangoEPSS 17%via OSV
CVE-2025-10072Medium· 6.3PoC
1y ago

A vulnerability was found in Portabilis i-Educar up to 2.10

A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/. Performing a manipulation results in improper access controls. It is possible to initi…

▾ Twilightportabilis · i-educarEPSS 0.33%via NVD
CVE-2025-9961NonePoC
1y ago

An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500.  The exploit can only be conducted via a Man-In-The-Middle (MITM) attack.  This issue affects AX10 V1/V1.2/V2/V2.6/V3/V3.…

An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500.  The exploit can only be conducted via a Man-In-The-Middle (MITM) attack.  This issue affects AX10 V1/V1.2/V2/V2.6/V3/V3.…

▾ TwilightEPSS 10.0%via NVD
CVE-2025-39682Critical· 9.8CISA KEVPoC⚖ disputed
1y ago

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…

▾ Hadallinux · linux_kernelEPSS 2.9%via NVD
CVE-2025-10012Medium· 6.3PoC
1y ago

A security vulnerability has been detected in Portabilis i-Educar up to 2.10

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file educar_historico_escolar_lst.php. Such manipulation of the argument ref_cod_aluno leads to sql injectio…

▾ Twilightportabilis · i-educarEPSS 0.38%via NVD
CVE-2025-55190High· 8.8PoC
1y ago

github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials (CVE-2025-55190)

An information leak was discovered in how Argo CD handles API tokens. The project details API endpoint could provide unintentional access to sensitive repository credentials.

▾ MidnightRed Hat · Red Hat OpenShift GitOps 1.17EPSS 5.5%via CSAF
CVE-2025-57808High· 8.1PoC
1y ago

ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

▾ Midnightesphome · esphomeEPSS 1.6%via OSV
CVE-2025-9784High· 7.5PoC
1y ago

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive serv…

▾ Midnightredhat · build_of_apache_camel_for_spring_bootEPSS 2.3%via NVD
CVE-2005-10004High· 8.8PoC
1y ago

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled durin…

▾ Midnightcacti · cactiEPSS 2.0%via NVD
CVE-2025-9606Medium· 6.3PoC
1y ago

A vulnerability was detected in Portabilis i-Educar up to 2.10

A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/agenda_preferencias.php. Performing a manipulation of the argument cod_agenda results in sql…

▾ Twilightportabilis · i-educarEPSS 0.34%via NVD
CVEs tagged “exploit-available” — page 101 · VulnSea