VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3702 CVEsRSS

CVE-2025-2609High· 8.2PoC
1y ago

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/lo…

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/lo…

▾ Midnightmagnussolution · magnusbillingEPSS 1.1%via NVD
CVE-2024-12537High· 7.5PoC
1y ago

Open WebUI Uncontrolled Resource Consumption vulnerability

Open WebUI Uncontrolled Resource Consumption vulnerability

▾ Midnightopen-webui · open-webuiEPSS 0.89%via OSV
CVE-2024-8021Medium· 5.4PoC
1y ago

Gradio Vulnerable to Open Redirect

Gradio Vulnerable to Open Redirect

▾ Twilightgradio · gradioEPSS 0.74%via OSV
CVE-2024-10908Medium· 6.1PoC
1y ago

FastChat open redirect vulnerability

FastChat open redirect vulnerability

▾ Twilightfschat · fschatEPSS 0.78%via OSV
CVE-2024-10829High· 7.5PoC
1y ago

DB-GPT Uncontrolled Resource Consumption vulnerability

DB-GPT Uncontrolled Resource Consumption vulnerability

▾ Midnightdbgpt · dbgptEPSS 0.72%via OSV
CVE-2024-10821High· 7.5PoC
1y ago

InvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`

InvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`

▾ Midnightinvokeai · invokeaiEPSS 0.63%via OSV
CVE-2024-8859High· 7.5PoC
1y ago

MLflow has a Local File Read/Path Traversal in dbfs

MLflow has a Local File Read/Path Traversal in dbfs

▾ Midnightmlflow · mlflowEPSS 2.7%via OSV
CVE-2024-40635Medium· 4.6PoC
1y ago

containerd: containerd has an integer overflow in User ID handling (CVE-2024-40635)

A flaw was found in containerd package. Containers launched with a User set as a UID:GID larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This issue could ca…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.29%via CSAF
CVE-2025-30066High· 8.6CISA KEVPoC
1y ago

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at comm…

▾ Abyssaltj-actions · changed-filesEPSS 72%via NVD
CVE-2023-52927High· 7.8PoC
1y ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: allow exp not to be removed in nf_ct_find_expectation Currently nf_conntrack_in() calling nf_ct_find_expectation() will remove the exp from the hash table

In the Linux kernel, the following vulnerability has been resolved: netfilter: allow exp not to be removed in nf_ct_find_expectation Currently nf_conntrack_in() calling nf_ct_find_expectation() will remove the exp from the hash table. …

▾ Midnightlinux · linux_kernelEPSS 0.31%via NVD
CVE-2024-8176High· 7.5PoC
1y ago

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse ind…

▾ MidnightRed Hat · libexpatEPSS 1.3%via NVD
CVE-2025-1550HighPoC
1y ago

Arbitrary Code Execution via Crafted Keras Config for Model Loading

Arbitrary Code Execution via Crafted Keras Config for Model Loading

▾ Midnightkeras · kerasEPSS 2.6%via OSV
CVE-2025-26633High· 7.0CISA KEV0dayPoC
1y ago

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

▾ Abyssalmicrosoft · windows_10_1507EPSS 30%via NVD
CVE-2024-48248High· 8.6CISA KEVPoC
1y ago

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext creden…

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext creden…

▾ Abyssalnakivo · backup_&_replication_directorEPSS 94%via NVD
CVE-2025-1716Critical· 9.8PoC
1y ago

picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft …

picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle and include a malicious pickle file with a non-standard file exte…

▾ Abyssalpicklescan · picklescanEPSS 1.7%via OSV
CVE-2025-26466Medium· 5.9PoC
1y ago

A flaw was found in the OpenSSH package

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A …

▾ Twilightopenbsd · opensshEPSS 40%via NVD
CVE-2025-25279Critical· 9.9PoC
1y ago

Mattermost allows reading arbitrary files related to importing boards

Mattermost allows reading arbitrary files related to importing boards

▾ Abyssalmattermost · github.com/mattermost/mattermost/server/v8EPSS 24%via OSV
CVE-2025-0690Medium· 6.1PoC
1y ago

The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character

The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character. During this process, wit…

▾ TwilightEPSS 0.72%via NVD
CVE-2025-26465Medium· 6.8PoC
1y ago

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error …

▾ Twilightopenbsd · opensshEPSS 7.7%via NVD
CVE-2024-57049NonePoC
1y ago

Rejected reason: DO NOT USE THIS CVE RECORD

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

▾ TwilightEPSS 3.2%via NVD
CVE-2025-25296Medium· 6.1PoC
1y ago

Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint

Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint

▾ Twilightlabel-studio · label-studioEPSS 1.9%via OSV
CVE-2025-0108Critical· 9.1CISA KEVPoC
1y ago

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…

▾ Hadalpaloaltonetworks · pan-osEPSS 98%via NVD
CVE-2025-24472High· 8.1CISA KEVPoC
1y ago

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior k…

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior k…

▾ Abyssalfortinet · fortiproxyEPSS 7.2%via NVD
CVE-2024-50633None· 0.0PoC
1y ago

Indico Insecure Access

Indico Insecure Access

▾ Twilightindico · indicoEPSS 0.63%via OSV
CVE-2024-57727High· 7.5CISA KEVPoC
1y ago

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. Th…

▾ Abyssalsimple-help · simplehelpEPSS 97%via NVD
CVE-2024-12084Critical· 9.8PoC
1y ago

A heap-based buffer overflow flaw was found in the rsync daemon

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attac…

▾ Abyssalsamba · rsyncEPSS 72%via NVD
CVE-2024-55591Critical· 9.8CISA KEV0dayPoC
1y ago

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain supe…

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain supe…

▾ Hadalfortinet · fortiproxyEPSS 94%via NVD
CVE-2024-12085High· 7.5PoC
1y ago

A flaw was found in rsync which could be triggered when rsync compares file checksums

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak o…

▾ Midnightsamba · rsyncEPSS 8.8%via NVD
CVE-2024-53704Critical· 9.8CISA KEVPoC
1y ago

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

▾ Hadalsonicwall · sonicosEPSS 95%via NVD
CVE-2025-0282Critical· 9.0CISA KEV0dayPoC
1y ago

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve…

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve…

▾ Hadalivanti · connect_secureEPSS 100%via NVD
CVEs tagged “exploit-available” — page 105 · VulnSea