Tagged “exploit-available”
CVEs tagged exploit-available, newest first.
3811 CVEsRSS
CVE-2024-3822Medium· 4.8PoCThe Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such a…
The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such a…
CVE-2024-34064Medium· 5.4PoCJinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
CVE-2024-34069High· 7.5PoCWerkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
CVE-2024-34061Medium· 4.3PoCchangedetection.io Cross-site Scripting vulnerability
changedetection.io Cross-site Scripting vulnerability
CVE-2024-33775High· 8.8PoCAn issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
CVE-2024-33668Critical· 9.1PoCAn issue was discovered in Zammad before 6.3.0
An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no …
CVE-2020-8559Medium· 6.8PoCPrivilege Escalation in Kubernetes
Privilege Escalation in Kubernetes
CVE-2024-1183Medium· 6.5PoCgradio Server-Side Request Forgery vulnerability
gradio Server-Side Request Forgery vulnerability
CVE-2024-1561High· 7.5PoCgradio vulnerable to Path Traversal
gradio vulnerable to Path Traversal
CVE-2024-1483High· 7.5PoCmlflow Path Traversal vulnerability
mlflow Path Traversal vulnerability
CVE-2024-3651Medium· 6.2PoCInternationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode
Internationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode
CVE-2024-3568Low· 3.4PoCTransformers Deserialization of Untrusted Data vulnerability
Transformers Deserialization of Untrusted Data vulnerability
CVE-2023-45288Medium· 5.3PoCnet/http, x/net/http2: close connections when receiving too many headers
net/http, x/net/http2: close connections when receiving too many headers
CVE-2024-3116High· 7.4PoCpgAdmin Remote Code Execution (RCE) vulnerability
pgAdmin Remote Code Execution (RCE) vulnerability
CVE-2024-1023Medium· 6.5PoCA vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures
A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. …
CVE-2024-1753High· 8.6PoCA flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers
A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the ro…
CVE-2024-22513LowPoCImproper Privilege Management in djangorestframework-simplejwt
Improper Privilege Management in djangorestframework-simplejwt
CVE-2024-27102Critical· 9.9PoCWings is the server control plane for Pterodactyl Panel
Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can potentially be used to access files and directories on the host system. The full sco…
CVE-2023-42789Critical· 9.8PoCA out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 throug…
A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 throug…
CVE-2024-27304High· 8.1PoCpgx: SQL Injection via Protocol Message Size Overflow (CVE-2024-27304)
pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be…
CVE-2024-22889Medium· 5.5PoCPhone information disclosure vulnerability
Phone information disclosure vulnerability
CVE-2024-27292High· 7.5PoCDocassemble unauthorized access through URL manipulation
Docassemble unauthorized access through URL manipulation
CVE-2024-25169MediumPoCMezzanine allows attackers to bypass access control mechanisms
Mezzanine allows attackers to bypass access control mechanisms
CVE-2024-25170MediumPoCMezzanine allows attackers to bypass access controls via manipulating the Host header
Mezzanine allows attackers to bypass access controls via manipulating the Host header
CVE-2024-25723Medium· 6.5PoCZenML Server Remote Privilege Escalation Vulnerability
ZenML Server Remote Privilege Escalation Vulnerability
CVE-2019-25162High· 7.8PoCIn the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are done using it. This patch just moves the put_device() down a bit to avoid the use after f…
In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are done using it. This patch just moves the put_device() down a bit to avoid the use after f…
CVE-2023-52440Critical· 9.8PoCIn the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If authblob->SessionKey.Length is bigger than session key size(CIFS_KEY_SIZE), slub overflow can happen in…
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If authblob->SessionKey.Length is bigger than session key size(CIFS_KEY_SIZE), slub overflow can happen in…
CVE-2024-1212Critical· 10.0CISA KEVPoCUnauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
CVE-2024-21338High· 7.8CISA KEV0dayPoCWindows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-21490High· 7.5PoCThis affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0
This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. Wit…