Tagged “exploit-available”
CVEs tagged exploit-available, newest first.
3702 CVEsRSS
CVE-2025-34157Critical· 9.0PoCCoolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name con…
CVE-2025-9236Medium· 6.3PoCA vulnerability has been found in Portabilis i-Educar up to 2.10
A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usuàrio Page. Such manipulation of the argument nm_tipo/descri…
CVE-2010-20103Critical· 9.8PoCA malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010
A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute a…
CVE-2025-51529Medium· 5.3PoCIncorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial of service (database server resource exhaustion) via unl…
Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial of service (database server resource exhaustion) via unl…
CVE-2025-8875High· 7.8CISA KEV0dayPoCDeserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
CVE-2025-25256Critical· 9.8PoCAn improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, F…
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, F…
CVE-2025-8088High· 8.8CISA KEVPoCA path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepano…
CVE-2025-8539Low· 2.4PoCA weakness has been identified in Portabilis i-Educar 2.10
A weakness has been identified in Portabilis i-Educar 2.10. This affects an unknown function of the file /intranet/public_distrito_cad.php. This manipulation of the argument nome causes cross site scripting. The attack is possible to be …
CVE-2025-8538Low· 2.4PoCA security flaw has been discovered in Portabilis i-Educar 2.10
A security flaw has been discovered in Portabilis i-Educar 2.10. The impacted element is an unknown function of the file /usuarios/tipos/novo. The manipulation of the argument name/description results in cross site scripting. The attack …
CVE-2025-20701High· 8.8PoCIn the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not nee…
CVE-2025-50460Critical· 9.8PoCMS SWIFT Remote Code Execution via unsafe PyYAML deserialization
MS SWIFT Remote Code Execution via unsafe PyYAML deserialization
CVE-2025-54589Medium· 6.3PoCcopyparty Reflected XSS via Filter Parameter
copyparty Reflected XSS via Filter Parameter
CVE-2025-31277High· 8.8CISA KEVPoCThe issue was addressed with improved memory handling
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory…
CVE-2025-54381Critical· 9.9PoCBentoML SSRF Vulnerability in File Upload Processing
BentoML SSRF Vulnerability in File Upload Processing
CVE-2025-7404MediumPoCCalibre Web and Autocaliweb have OS Command Injection vulnerability
Calibre Web and Autocaliweb have OS Command Injection vulnerability
CVE-2025-6998HighPoCCalibre Web and Autocaliweb have a ReDoS vulnerability
Calibre Web and Autocaliweb have a ReDoS vulnerability
CVE-2016-15044NonePoCA remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module
A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module. An unauthenticated remote attacker can exploit this issue by send…
CVE-2025-6018High· 7.8PoCA Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM)
A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw allows an unprivileged local attacker (for example, a user logged in via SSH) to obtain the…
CVE-2025-38352High· 7.8CISA KEVPoCIn the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls ha…
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls ha…
CVE-2025-53770Critical· 9.8CISA KEV0dayPoCDeserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing…
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing…
CVE-2015-10138Critical· 9.8PoCThe Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2
The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it p…
CVE-2025-3415Medium· 4.3PoCGrafana's insecure DingDing Alert integration exposes sensitive information
Grafana's insecure DingDing Alert integration exposes sensitive information
CVE-2025-34126NonePoCA path traversal vulnerability exists in RIPS Scanner version 0.54
A path traversal vulnerability exists in RIPS Scanner version 0.54. The vulnerability allows remote attackers to read arbitrary files on the system with the privileges of the web server by sending crafted HTTP GET requests to the 'window…
CVE-2025-6558High· 8.8CISA KEVPoCInsufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2025-34115High· 8.7PoCAn authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint
An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' featur…
CVE-2025-6965High· 7.7PoCThere exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
CVE-2025-53640MediumPoCIndico vulnerability allows attackers to bulk dump user details
Indico vulnerability allows attackers to bulk dump user details
CVE-2025-51591Low· 3.7PoCA Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe
A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. Note: Some users have stated that Pandoc by default can retrieve and par…
CVE-2025-7425High· 7.8PoCA flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the pro…
CVE-2025-48384High· 8.0CISA KEVPoCGit is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return a…