VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3811 CVEsRSS

CVE-2024-39887Medium· 4.3PoC
2y ago

Apache Superset vulnerable to improper SQL authorization

Apache Superset vulnerable to improper SQL authorization

▾ Twilightapache-superset · apache-supersetEPSS 4.4%via OSV
CVE-2024-39903High· 8.6PoC
2y ago

Local File Inclusion in Solara

Local File Inclusion in Solara

▾ Midnightsolara · solaraEPSS 2.9%via OSV
CVE-2024-39614High· 7.5PoC
2y ago

Django vulnerable to Denial of Service

Django vulnerable to Denial of Service

▾ Midnightdjango · djangoEPSS 29%via OSV
CVE-2024-39689LowPoC
2y ago

Certifi removes GLOBALTRUST root certificate

Certifi removes GLOBALTRUST root certificate

▾ Twilightcertifi · certifiEPSS 1.0%via OSV
CVE-2024-31223Medium· 5.3PoC
2y ago

Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL

Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL

▾ Twilightethyca-fides · ethyca-fidesEPSS 1.1%via OSV
CVE-2024-38537None· 0.0PoC
2y ago

Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js

Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js

▾ Twilightethyca-fides · ethyca-fidesEPSS 1.4%via OSV
CVE-2024-6387High· 8.1PoC
2y ago

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd)

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by f…

▾ Midnightopenbsd · opensshEPSS 100%via NVD
CVE-2024-5751Critical· 9.8PoC
2y ago

BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution

BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_deployment` function, which decodes and decrypts environment variables from base64 and ass…

▾ Abyssallitellm · litellmEPSS 0.88%via NVD
CVE-2024-6127Critical· 9.8PoC
2y ago

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all crypt…

▾ AbyssalEPSS 10%via NVD
CVE-2024-21520Medium· 6.1PoC
2y ago

Cross-site Scripting in djangorestframework

Cross-site Scripting in djangorestframework

▾ Twilightdjangorestframework · djangorestframeworkEPSS 1.1%via OSV
CVE-2024-38526High· 7.2PoC
2y ago

pdoc embeds link to malicious CDN if math mode is enabled

pdoc embeds link to malicious CDN if math mode is enabled

▾ Midnightpdoc · pdocEPSS 3.8%via OSV
CVE-2024-3121Medium· 6.8PoC
2y ago

Remote Code Execution in create_conda_env function in lollms

Remote Code Execution in create_conda_env function in lollms

▾ Twilightlollms · lollmsEPSS 0.45%via OSV
CVE-2024-4940Medium· 5.4PoC
2y ago

Open redirect in gradio

Open redirect in gradio

▾ Twilightgradio · gradioEPSS 1.0%via OSV
CVE-2024-34693Medium· 6.8PoC
2y ago

Apache Superset server arbitrary file read

Apache Superset server arbitrary file read

▾ Twilightapache-superset · apache-supersetEPSS 1.6%via OSV
CVE-2024-28397High· 8.8PoC
2y ago

js2py allows remote code execution

js2py allows remote code execution

▾ Midnightjs2py · js2pyEPSS 4.5%via OSV
CVE-2024-38355Medium· 7.3PoC
2y ago

socket.io has an unhandled 'error' event

socket.io has an unhandled 'error' event

▾ Twilightsocket.io · socket.ioEPSS 0.81%via GHSA
CVE-2024-35250High· 7.8CISA KEVPoC
2y ago

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 25%via NVD
CVE-2024-30090High· 7.0PoC
2y ago

Microsoft Streaming Service Elevation of Privilege Vulnerability

Microsoft Streaming Service Elevation of Privilege Vulnerability

▾ Midnightmicrosoft · windows_10_1507EPSS 2.0%via NVD
CVE-2024-30088High· 7.0CISA KEVPoC
2y ago

Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 68%via NVD
CVE-2024-30085High· 7.8PoC
2y ago

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

▾ Midnightmicrosoft · windows_10_1809EPSS 14%via NVD
CVE-2024-30052Medium· 4.7PoC
2y ago

Visual Studio Remote Code Execution Vulnerability

Visual Studio Remote Code Execution Vulnerability

▾ Twilightmicrosoft · visual_studio_2019EPSS 1.4%via NVD
CVE-2024-37152Medium· 5.3PoC
2y ago

Unauthenticated Access to sensitive settings in Argo CD

Unauthenticated Access to sensitive settings in Argo CD

▾ Twilightargoproj · github.com/argoproj/argo-cd/v2/serverEPSS 2.3%via OSV
CVE-2024-5452Critical· 9.8PoC
2y ago

Remote code execution in pytorch lightning

Remote code execution in pytorch lightning

▾ Abyssallightning · lightningEPSS 27%via OSV
CVE-2024-4325High· 8.6PoC
2y ago

Server-Side Request Forgery in gradio

Server-Side Request Forgery in gradio

▾ Midnightgradio · gradioEPSS 37%via OSV
CVE-2024-4890Medium· 4.9PoC
2y ago

SQL injection in litellm

SQL injection in litellm

▾ Twilightlitellm · litellmEPSS 0.56%via OSV
CVE-2024-4253Critical· 9.1PoC
2y ago

A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The…

A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing…

▾ Abyssalgradio · gradioEPSS 1.7%via OSV
CVE-2024-37054High· 8.8PoC
2y ago

MLFlow unsafe deserialization

MLFlow unsafe deserialization

▾ Midnightmlflow · mlflowEPSS 0.70%via OSV
CVE-2024-23692Critical· 9.8CISA KEVPoC
2y ago

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending…

▾ Hadalrejetto · http_file_serverEPSS 99%via NVD
CVE-2024-24919High· 8.6CISA KEVPoC
2y ago

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerab…

▾ Abyssalcheckpoint · cloudguard_network_securityEPSS 100%via NVD
CVE-2024-36039Critical· 9.8PoC
2y ago

PyMySQL SQL Injection vulnerability

PyMySQL SQL Injection vulnerability

▾ Abyssalpymysql · pymysqlEPSS 0.69%via OSV
CVEs tagged “exploit-available” — page 111 · VulnSea