Tagged “exploit-available”
CVEs tagged exploit-available, newest first.
3813 CVEsRSS
CVE-2024-11392High· 7.50dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-11394High· 8.80dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-10220High· 8.1PoCKubernetes kubelet arbitrary command execution
Kubernetes kubelet arbitrary command execution
CVE-2024-9474High· 7.2CISA KEV0dayPoCA privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…
CVE-2024-0012Critical· 9.8CISA KEV0dayPoCAn authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…
CVE-2024-49039High· 8.8CISA KEV0dayPoCWindows Task Scheduler Elevation of Privilege Vulnerability
Windows Task Scheduler Elevation of Privilege Vulnerability
CVE-2024-9902Medium· 6.3PoCansible-core Incorrect Authorization vulnerability
ansible-core Incorrect Authorization vulnerability
CVE-2024-48061Critical· 9.8PoCLangflow vulnerable to remote code execution
Langflow vulnerable to remote code execution
CVE-2024-51483Medium· 6.5PoCchangedetection.io Path Traversal
changedetection.io Path Traversal
CVE-2024-51378Critical· 10.0CISA KEV0dayPoCgetresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…
CVE-2024-51567Critical· 10.0CISA KEV0dayPoCupgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…
CVE-2024-8309Medium· 4.9PoCLangchain SQL Injection vulnerability
Langchain SQL Injection vulnerability
CVE-2024-50492High· 8.3PoCImproper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.
Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.
CVE-2024-50623Critical· 9.8CISA KEVPoCIn Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
CVE-2024-41713Critical· 9.1CISA KEVPoCA vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A succes…
CVE-2024-32651Critical· 10.0PoCchangedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution
changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution
CVE-2024-21262Medium· 6.5PoCVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC)
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access vi…
CVE-2024-9680Critical· 9.8CISA KEV0dayPoCAn attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.…
CVE-2024-6592Critical· 9.1PoCAn incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker w…
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker w…
CVE-2024-9014High· 8.6PoCOAuth2 client ID and secret exposed through the web browser
OAuth2 client ID and secret exposed through the web browser
CVE-2024-8698High· 7.7PoCA flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class
A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position o…
CVE-2024-8883Medium· 6.1PoCA misconfiguration flaw was found in Keycloak
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as author…
CVE-2024-6587High· 7.5PoCLiteLLM Server-Side Request Forgery (SSRF) vulnerability
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
CVE-2021-21401High· 7.1PoCnanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC
nanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC
CVE-2024-40766Critical· 9.8CISA KEVPoCAn improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects So…
CVE-2024-45163Critical· 9.1PoCThe Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server
The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, an attacker can send a recognized usern…
CVE-2024-6886Critical· 10.0PoCImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.
CVE-2024-7340High· 8.8PoCWeave server API vulnerable to arbitrary file leak
Weave server API vulnerable to arbitrary file leak
CVE-2024-41955Medium· 5.2PoCMobSF vulnerable to Open Redirect in Login Redirect
MobSF vulnerable to Open Redirect in Login Redirect
CVE-2024-39123Medium· 5.4PoCCalibre-Web Cross Site Scripting (XSS)
Calibre-Web Cross Site Scripting (XSS)