VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3813 CVEsRSS

CVE-2024-11392High· 7.50dayPoC
1y ago

Deserialization of Untrusted Data in Hugging Face Transformers

Deserialization of Untrusted Data in Hugging Face Transformers

▾ Abyssaltransformers · transformersEPSS 7.3%via OSV
CVE-2024-11394High· 8.80dayPoC
1y ago

Deserialization of Untrusted Data in Hugging Face Transformers

Deserialization of Untrusted Data in Hugging Face Transformers

▾ Abyssaltransformers · transformersEPSS 2.6%via OSV
CVE-2024-10220High· 8.1PoC
1y ago

Kubernetes kubelet arbitrary command execution

Kubernetes kubelet arbitrary command execution

▾ Midnightkubernetes · k8s.io/kubernetesEPSS 3.0%via OSV
CVE-2024-9474High· 7.2CISA KEV0dayPoC
1y ago

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…

▾ Abyssalpaloaltonetworks · pan-osEPSS 95%via NVD
CVE-2024-0012Critical· 9.8CISA KEV0dayPoC
1y ago

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…

▾ Hadalpaloaltonetworks · pan-osEPSS 100%via NVD
CVE-2024-49039High· 8.8CISA KEV0dayPoC
1y ago

Windows Task Scheduler Elevation of Privilege Vulnerability

Windows Task Scheduler Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 14%via NVD
CVE-2024-9902Medium· 6.3PoC
1y ago

ansible-core Incorrect Authorization vulnerability

ansible-core Incorrect Authorization vulnerability

▾ Twilightansible-core · ansible-coreEPSS 0.26%via OSV
CVE-2024-48061Critical· 9.8PoC
1y ago

Langflow vulnerable to remote code execution

Langflow vulnerable to remote code execution

▾ Abyssallangflow · langflowEPSS 1.5%via OSV
CVE-2024-51483Medium· 6.5PoC
1y ago

changedetection.io Path Traversal

changedetection.io Path Traversal

▾ Twilightchangedetection-io · changedetection-ioEPSS 2.3%via OSV
CVE-2024-51378Critical· 10.0CISA KEV0dayPoC
1y ago

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…

▾ Hadalcyberpanel · cyberpanelEPSS 95%via NVD
CVE-2024-51567Critical· 10.0CISA KEV0dayPoC
1y ago

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…

▾ Hadalcyberpanel · cyberpanelEPSS 87%via NVD
CVE-2024-8309Medium· 4.9PoC
1y ago

Langchain SQL Injection vulnerability

Langchain SQL Injection vulnerability

▾ Twilightlangchain-community · langchain-communityEPSS 14%via OSV
CVE-2024-50492High· 8.3PoC
1y ago

Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.

Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.

▾ Midnightwpplugin · scottcartEPSS 1.4%via NVD
CVE-2024-50623Critical· 9.8CISA KEVPoC
1y ago

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

▾ Hadalcleo · harmonyEPSS 99%via NVD
CVE-2024-41713Critical· 9.1CISA KEVPoC
1y ago

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A succes…

▾ Hadalmitel · micollabEPSS 98%via NVD
CVE-2024-32651Critical· 10.0PoC
1y ago

changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution

changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution

▾ Abyssalchangedetection-io · changedetection-ioEPSS 84%via OSV
CVE-2024-21262Medium· 6.5PoC
1y ago

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC)

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access vi…

▾ Twilightnetapp · oncommand_insightEPSS 0.57%via NVD
CVE-2024-9680Critical· 9.8CISA KEV0dayPoC
1y ago

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.…

▾ Hadalmozilla · firefoxEPSS 23%via NVD
CVE-2024-6592Critical· 9.1PoC
2y ago

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker w…

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker w…

▾ Abyssalwatchguard · authentication_gatewayEPSS 1.2%via NVD
CVE-2024-9014High· 8.6PoC
2y ago

OAuth2 client ID and secret exposed through the web browser

OAuth2 client ID and secret exposed through the web browser

▾ Midnightpgadmin4 · pgadmin4EPSS 9.7%via OSV
CVE-2024-8698High· 7.7PoC
2y ago

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position o…

▾ MidnightEPSS 2.0%via NVD
CVE-2024-8883Medium· 6.1PoC
2y ago

A misconfiguration flaw was found in Keycloak

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as author…

▾ Twilightredhat · build_of_keycloakEPSS 2.1%via NVD
CVE-2024-6587High· 7.5PoC
2y ago

LiteLLM Server-Side Request Forgery (SSRF) vulnerability

LiteLLM Server-Side Request Forgery (SSRF) vulnerability

▾ Midnightlitellm · litellmEPSS 35%via OSV
CVE-2021-21401High· 7.1PoC
2y ago

nanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC

nanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC

▾ Midnightnanopb · nanopbEPSS 1.8%via OSV
CVE-2024-40766Critical· 9.8CISA KEVPoC
2y ago

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects So…

▾ Hadalsonicwall · sonicosEPSS 18%via NVD
CVE-2024-45163Critical· 9.1PoC
2y ago

The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server

The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, an attacker can send a recognized usern…

▾ AbyssalEPSS 0.77%via NVD
CVE-2024-6886Critical· 10.0PoC
2y ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

▾ AbyssalGitea · Gitea Open Source Git ServerEPSS 33%via NVD
CVE-2024-7340High· 8.8PoC
2y ago

Weave server API vulnerable to arbitrary file leak

Weave server API vulnerable to arbitrary file leak

▾ Midnightweave · weaveEPSS 5.0%via OSV
CVE-2024-41955Medium· 5.2PoC
2y ago

MobSF vulnerable to Open Redirect in Login Redirect

MobSF vulnerable to Open Redirect in Login Redirect

▾ Twilightmobsf · mobsfEPSS 1.0%via OSV
CVE-2024-39123Medium· 5.4PoC
2y ago

Calibre-Web Cross Site Scripting (XSS)

Calibre-Web Cross Site Scripting (XSS)

▾ Twilightcalibreweb · calibrewebEPSS 23%via OSV
CVEs tagged “exploit-available” — page 110 · VulnSea