VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3702 CVEsRSS

CVE-2024-53995LowPoC
1y ago

GHSL-2024-288: SickChill open redirect in login

GHSL-2024-288: SickChill open redirect in login

▾ Twilightsickchill · sickchillEPSS 0.97%via OSV
CVE-2024-38819High· 7.5PoC
1y ago

Spring Framework Path Traversal vulnerability

Spring Framework Path Traversal vulnerability

▾ Midnightspringframework · org.springframework:spring-webfluxEPSS 56%via GHSA
CVE-2024-55956Critical· 9.8CISA KEVPoC
1y ago

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…

▾ Hadalcleo · harmonyEPSS 94%via NVD
CVE-2024-55890MediumPoC
1y ago

D-Tale allows Remote Code Execution through the Custom Filter Input

D-Tale allows Remote Code Execution through the Custom Filter Input

▾ Twilightdtale · dtaleEPSS 2.4%via OSV
CVE-2024-55587High· 8.8PoC
1y ago

python-libarchive directory traversal

python-libarchive directory traversal

▾ Midnightpython-libarchive · python-libarchiveEPSS 2.1%via OSV
CVE-2024-45337NonePoC
1y ago

Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto

Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto

▾ Twilightx · golang.org/x/cryptoEPSS 3.2%via OSV
CVE-2024-55550Low· 2.7CISA KEVPoC
1y ago

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to…

▾ Twilightmitel · micollabEPSS 38%via NVD
CVE-2024-52270High· 8.2PoC
1y ago

PDF Document Spoofing in DropBox Sign(HelloSign)

User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrom…

▾ MidnightDropBox(HelloSign) · DropBox SignEPSS 0.19%via CVEORG
CVE-2024-53920High· 7.8PoC
1y ago

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrar…

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrar…

▾ Midnightgnu · emacsEPSS 0.60%via NVD
CVE-2024-11680Critical· 9.8CISA KEVPoC
1y ago

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of …

▾ Hadalprojectsend · projectsendEPSS 92%via NVD
CVE-2024-11393High· 8.80dayPoC
1y ago

Deserialization of Untrusted Data in Hugging Face Transformers

Deserialization of Untrusted Data in Hugging Face Transformers

▾ Abyssaltransformers · transformersEPSS 3.1%via OSV
CVE-2024-11392High· 7.50dayPoC
1y ago

Deserialization of Untrusted Data in Hugging Face Transformers

Deserialization of Untrusted Data in Hugging Face Transformers

▾ Abyssaltransformers · transformersEPSS 7.3%via OSV
CVE-2024-11394High· 8.80dayPoC
1y ago

Deserialization of Untrusted Data in Hugging Face Transformers

Deserialization of Untrusted Data in Hugging Face Transformers

▾ Abyssaltransformers · transformersEPSS 2.6%via OSV
CVE-2024-10220High· 8.1PoC
1y ago

Kubernetes kubelet arbitrary command execution

Kubernetes kubelet arbitrary command execution

▾ Midnightkubernetes · k8s.io/kubernetesEPSS 3.0%via OSV
CVE-2024-9474High· 7.2CISA KEV0dayPoC
1y ago

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…

▾ Abyssalpaloaltonetworks · pan-osEPSS 95%via NVD
CVE-2024-0012Critical· 9.8CISA KEV0dayPoC
1y ago

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…

▾ Hadalpaloaltonetworks · pan-osEPSS 100%via NVD
CVE-2024-49039High· 8.8CISA KEV0dayPoC
1y ago

Windows Task Scheduler Elevation of Privilege Vulnerability

Windows Task Scheduler Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 14%via NVD
CVE-2024-9902Medium· 6.3PoC
1y ago

ansible-core Incorrect Authorization vulnerability

ansible-core Incorrect Authorization vulnerability

▾ Twilightansible-core · ansible-coreEPSS 0.26%via OSV
CVE-2024-48061Critical· 9.8PoC
1y ago

Langflow vulnerable to remote code execution

Langflow vulnerable to remote code execution

▾ Abyssallangflow · langflowEPSS 1.5%via OSV
CVE-2024-51483Medium· 6.5PoC
1y ago

changedetection.io Path Traversal

changedetection.io Path Traversal

▾ Twilightchangedetection-io · changedetection-ioEPSS 2.3%via OSV
CVE-2024-51378Critical· 10.0CISA KEV0dayPoC
1y ago

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…

▾ Hadalcyberpanel · cyberpanelEPSS 95%via NVD
CVE-2024-51567Critical· 10.0CISA KEV0dayPoC
1y ago

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…

▾ Hadalcyberpanel · cyberpanelEPSS 87%via NVD
CVE-2024-8309Medium· 4.9PoC
1y ago

Langchain SQL Injection vulnerability

Langchain SQL Injection vulnerability

▾ Twilightlangchain-community · langchain-communityEPSS 14%via OSV
CVE-2024-50492High· 8.3PoC
1y ago

Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.

Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.

▾ Midnightwpplugin · scottcartEPSS 1.4%via NVD
CVE-2024-50623Critical· 9.8CISA KEVPoC
1y ago

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

▾ Hadalcleo · harmonyEPSS 99%via NVD
CVE-2024-41713Critical· 9.1CISA KEVPoC
1y ago

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A succes…

▾ Hadalmitel · micollabEPSS 98%via NVD
CVE-2024-32651Critical· 10.0PoC
1y ago

changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution

changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution

▾ Abyssalchangedetection-io · changedetection-ioEPSS 84%via OSV
CVE-2024-21262Medium· 6.5PoC
1y ago

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC)

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access vi…

▾ Twilightnetapp · oncommand_insightEPSS 0.57%via NVD
CVE-2024-9680Critical· 9.8CISA KEV0dayPoC
1y ago

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.…

▾ Hadalmozilla · firefoxEPSS 23%via NVD
CVE-2024-6592Critical· 9.1PoC
2y ago

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker w…

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker w…

▾ Abyssalwatchguard · authentication_gatewayEPSS 1.2%via NVD
CVEs tagged “exploit-available” — page 106 · VulnSea