Tagged “exploit-available”
CVEs tagged exploit-available, newest first.
3811 CVEsRSS
CVE-2024-39887Medium· 4.3PoCApache Superset vulnerable to improper SQL authorization
Apache Superset vulnerable to improper SQL authorization
CVE-2024-39903High· 8.6PoCLocal File Inclusion in Solara
Local File Inclusion in Solara
CVE-2024-39614High· 7.5PoCDjango vulnerable to Denial of Service
Django vulnerable to Denial of Service
CVE-2024-39689LowPoCCertifi removes GLOBALTRUST root certificate
Certifi removes GLOBALTRUST root certificate
CVE-2024-31223Medium· 5.3PoCInformation Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
CVE-2024-38537None· 0.0PoCInclusion of Untrusted polyfill.io Code Vulnerability in fides.js
Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js
CVE-2024-6387High· 8.1PoCA security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd)
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by f…
CVE-2024-5751Critical· 9.8PoCBerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution
BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_deployment` function, which decodes and decrypts environment variables from base64 and ass…
CVE-2024-6127Critical· 9.8PoCBC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution
BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all crypt…
CVE-2024-21520Medium· 6.1PoCCross-site Scripting in djangorestframework
Cross-site Scripting in djangorestframework
CVE-2024-38526High· 7.2PoCpdoc embeds link to malicious CDN if math mode is enabled
pdoc embeds link to malicious CDN if math mode is enabled
CVE-2024-3121Medium· 6.8PoCRemote Code Execution in create_conda_env function in lollms
Remote Code Execution in create_conda_env function in lollms
CVE-2024-4940Medium· 5.4PoCOpen redirect in gradio
Open redirect in gradio
CVE-2024-34693Medium· 6.8PoCApache Superset server arbitrary file read
Apache Superset server arbitrary file read
CVE-2024-28397High· 8.8PoCjs2py allows remote code execution
js2py allows remote code execution
CVE-2024-38355Medium· 7.3PoCsocket.io has an unhandled 'error' event
socket.io has an unhandled 'error' event
CVE-2024-35250High· 7.8CISA KEVPoCWindows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2024-30090High· 7.0PoCMicrosoft Streaming Service Elevation of Privilege Vulnerability
Microsoft Streaming Service Elevation of Privilege Vulnerability
CVE-2024-30088High· 7.0CISA KEVPoCWindows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-30085High· 7.8PoCWindows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2024-30052Medium· 4.7PoCVisual Studio Remote Code Execution Vulnerability
Visual Studio Remote Code Execution Vulnerability
CVE-2024-37152Medium· 5.3PoCUnauthenticated Access to sensitive settings in Argo CD
Unauthenticated Access to sensitive settings in Argo CD
CVE-2024-5452Critical· 9.8PoCRemote code execution in pytorch lightning
Remote code execution in pytorch lightning
CVE-2024-4325High· 8.6PoCServer-Side Request Forgery in gradio
Server-Side Request Forgery in gradio
CVE-2024-4890Medium· 4.9PoCSQL injection in litellm
SQL injection in litellm
CVE-2024-4253Critical· 9.1PoCA command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The…
A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing…
CVE-2024-37054High· 8.8PoCMLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-23692Critical· 9.8CISA KEVPoCRejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending…
CVE-2024-24919High· 8.6CISA KEVPoCPotentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerab…
CVE-2024-36039Critical· 9.8PoCPyMySQL SQL Injection vulnerability
PyMySQL SQL Injection vulnerability