Tagged “exploit-available”
CVEs tagged exploit-available, newest first.
3702 CVEsRSS
CVE-2025-2609High· 8.2PoCImproper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/lo…
Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/lo…
CVE-2024-12537High· 7.5PoCOpen WebUI Uncontrolled Resource Consumption vulnerability
Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-8021Medium· 5.4PoCGradio Vulnerable to Open Redirect
Gradio Vulnerable to Open Redirect
CVE-2024-10908Medium· 6.1PoCFastChat open redirect vulnerability
FastChat open redirect vulnerability
CVE-2024-10829High· 7.5PoCDB-GPT Uncontrolled Resource Consumption vulnerability
DB-GPT Uncontrolled Resource Consumption vulnerability
CVE-2024-10821High· 7.5PoCInvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`
InvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`
CVE-2024-8859High· 7.5PoCMLflow has a Local File Read/Path Traversal in dbfs
MLflow has a Local File Read/Path Traversal in dbfs
CVE-2024-40635Medium· 4.6PoCcontainerd: containerd has an integer overflow in User ID handling (CVE-2024-40635)
A flaw was found in containerd package. Containers launched with a User set as a UID:GID larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This issue could ca…
CVE-2025-30066High· 8.6CISA KEVPoCtj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at comm…
CVE-2023-52927High· 7.8PoCIn the Linux kernel, the following vulnerability has been resolved: netfilter: allow exp not to be removed in nf_ct_find_expectation Currently nf_conntrack_in() calling nf_ct_find_expectation() will remove the exp from the hash table
In the Linux kernel, the following vulnerability has been resolved: netfilter: allow exp not to be removed in nf_ct_find_expectation Currently nf_conntrack_in() calling nf_ct_find_expectation() will remove the exp from the hash table. …
CVE-2024-8176High· 7.5PoCA stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse ind…
CVE-2025-1550HighPoCArbitrary Code Execution via Crafted Keras Config for Model Loading
Arbitrary Code Execution via Crafted Keras Config for Model Loading
CVE-2025-26633High· 7.0CISA KEV0dayPoCImproper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
CVE-2024-48248High· 8.6CISA KEVPoCNAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext creden…
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext creden…
CVE-2025-1716Critical· 9.8PoCpicklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft …
picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle and include a malicious pickle file with a non-standard file exte…
CVE-2025-26466Medium· 5.9PoCA flaw was found in the OpenSSH package
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A …
CVE-2025-25279Critical· 9.9PoCMattermost allows reading arbitrary files related to importing boards
Mattermost allows reading arbitrary files related to importing boards
CVE-2025-0690Medium· 6.1PoCThe read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character
The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character. During this process, wit…
CVE-2025-26465Medium· 6.8PoCA vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error …
CVE-2024-57049NonePoCRejected reason: DO NOT USE THIS CVE RECORD
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2025-25296Medium· 6.1PoCLabel Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
CVE-2025-0108Critical· 9.1CISA KEVPoCAn authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…
An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…
CVE-2025-24472High· 8.1CISA KEVPoCAn Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior k…
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior k…
CVE-2024-50633None· 0.0PoCIndico Insecure Access
Indico Insecure Access
CVE-2024-57727High· 7.5CISA KEVPoCSimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. Th…
CVE-2024-12084Critical· 9.8PoCA heap-based buffer overflow flaw was found in the rsync daemon
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attac…
CVE-2024-55591Critical· 9.8CISA KEV0dayPoCAn Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain supe…
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain supe…
CVE-2024-12085High· 7.5PoCA flaw was found in rsync which could be triggered when rsync compares file checksums
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak o…
CVE-2024-53704Critical· 9.8CISA KEVPoCAn Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
CVE-2025-0282Critical· 9.0CISA KEV0dayPoCA stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve…
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve…