Tagged “exploit-available”
CVEs tagged exploit-available, newest first.
3702 CVEsRSS
CVE-2025-53547High· 8.5PoChelm.sh/helm/v3: Helm Chart Code Execution (CVE-2025-53547)
A command injection vulnerability has been identified in Helm, a package manager for Kubernetes. An attacker can craft a malicious Chart.yaml file with specially linked dependencies in a Chart.lock file. If the Chart.lock file is a symboli…
CVE-2025-49706Medium· 6.5CISA KEVPoCImproper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-34088High· 8.8PoCAn authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier
An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrary OS commands via the select_ips parameter when performin…
CVE-2025-4334Critical· 9.8PoCThe Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3
The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. Thi…
CVE-2025-34037NonePoCAn OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080
An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the …
CVE-2025-44203High· 7.5PoCIn HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking
In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a…
CVE-2025-6019High· 7.0PoCA Local Privilege Escalation (LPE) vulnerability was found in libblockdev
A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev in…
CVE-2025-5777High· 7.5CISA KEVPoCInsufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CVE-2025-4404Critical· 9.1PoCA privilege escalation from host to domain vulnerability was found in the FreeIPA project
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services…
CVE-2025-6021High· 7.5PoCA flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafte…
CVE-2025-5915Medium· 6.6PoCA vulnerability has been identified in the libarchive library
A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may…
CVE-2025-5914High· 7.8PoCA vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a…
CVE-2025-49619High· 8.5PoCSkyvern has a Jinja runtime leak
Skyvern has a Jinja runtime leak
CVE-2025-4517Critical· 9.4PoCAllows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() o…
Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() o…
CVE-2025-4138High· 7.5PoCAllows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract …
Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract …
CVE-2025-5222High· 7.0PoCA stack buffer overflow was found in Internationl components for unicode (ICU )
A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary…
CVE-2025-34027NonePoCThe Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged fo…
CVE-2025-47273HighPoCsetuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
CVE-2025-4476Medium· 4.3PoCA denial-of-service vulnerability has been identified in the libsoup HTTP client library
A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter wit…
CVE-2025-32873Medium· 5.3PoCDjango has a denial-of-service possibility in strip_tags()
Django has a denial-of-service possibility in strip_tags()
CVE-2025-32432Critical· 10.0CISA KEVPoCCraft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to r…
CVE-2025-31324Critical· 10.0CISA KEVPoCSAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could signifi…
CVE-2025-32434CriticalPoCPyTorch: `torch.load` with `weights_only=True` leads to remote code execution
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
CVE-2025-3248Critical· 9.8CISA KEVPoCLangflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
CVE-2025-27520Critical· 9.8PoCBentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
CVE-2025-31489HighPoCMinIO performs incomplete signature validation for unsigned-trailer uploads
MinIO performs incomplete signature validation for unsigned-trailer uploads
CVE-2025-22457Critical· 9.0CISA KEV0dayPoCA stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code…
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code…
CVE-2025-3047Medium· 6.5PoCAWS SAM CLI Path Traversal allows file copy to build container
AWS SAM CLI Path Traversal allows file copy to build container
CVE-2025-1097High· 8.8PoCngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
CVE-2025-2610High· 7.6PoCImproper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting
Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protec…