VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3811 CVEsRSS

CVE-2024-21762Critical· 9.8CISA KEV0dayPoC
2y ago

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…

▾ Hadalfortinet · fortiproxyEPSS 83%via NVD
CVE-2024-24590High· 8.8PoC
2y ago

Allegro AI ClearML vulnerable to deserialization of untrusted data

Allegro AI ClearML vulnerable to deserialization of untrusted data

▾ Midnightclearml · clearmlEPSS 2.5%via OSV
CVE-2024-21485Medium· 6.5PoC
2y ago

Dash apps vulnerable to Cross-site Scripting

Dash apps vulnerable to Cross-site Scripting

▾ Twilightdash-core-components · dash-core-componentsEPSS 1.5%via OSV
CVE-2021-43798High· 7.5CISA KEVPoC
2y ago

Grafana path traversal

Grafana path traversal

▾ Abyssalgrafana · github.com/grafana/grafanaEPSS 89%via OSV
CVE-2024-23652Critical· 10.0PoC
2y ago

BuildKit vulnerable to possible host system access from mount stub cleaner

BuildKit vulnerable to possible host system access from mount stub cleaner

▾ Abyssalmoby · github.com/moby/buildkitEPSS 2.5%via OSV
CVE-2024-1086High· 7.8CISA KEVPoC
2y ago

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …

▾ Abyssalnetapp · h300s_firmwareEPSS 28%via NVD
CVE-2024-21893High· 8.2CISA KEV0dayPoC
2y ago

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…

▾ Abyssalivanti · connect_secureEPSS 100%via NVD
CVE-2021-41091Medium· 5.9PoC
2y ago

Moby (Docker Engine) Insufficiently restricted permissions on data directory

Moby (Docker Engine) Insufficiently restricted permissions on data directory

▾ Twilightmoby · github.com/moby/mobyEPSS 2.8%via OSV
CVE-2024-21626High· 8.6PoC
2y ago

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc…

▾ Midnightlinuxfoundation · runcEPSS 19%via NVD
CVE-2024-23334Medium· 5.9PoC
2y ago

aiohttp is vulnerable to directory traversal

aiohttp is vulnerable to directory traversal

▾ Twilightaiohttp · aiohttpEPSS 77%via OSV
CVE-2023-52251High· 8.8PoC
2y ago

An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages

An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages. No fixed release is available; the project has had no com…

▾ Midnightprovectus · uiEPSS 87%via NVD
CVE-2023-47115High· 7.1PoC
2y ago

Cross-site Scripting Vulnerability on Avatar Upload

Cross-site Scripting Vulnerability on Avatar Upload

▾ Midnightlabel-studio · label-studioEPSS 1.4%via OSV
CVE-2023-27168Critical· 9.8PoC
2y ago

An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

▾ Abyssalxpand-it · write-back_managerEPSS 1.3%via NVD
CVE-2024-22416Critical· 9.6PoC
2y ago

Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation

Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation

▾ Abyssalpyload-ng · pyload-ngEPSS 0.95%via OSV
CVE-2024-21887Critical· 9.1CISA KEV0dayPoC
2y ago

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…

▾ Hadalivanti · connect_secureEPSS 100%via NVD
CVE-2023-46805High· 8.2CISA KEV0dayPoC
2y ago

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

▾ Abyssalivanti · connect_secureEPSS 100%via NVD
CVE-2022-2586Medium· 5.3CISA KEV0dayPoC
2y ago

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

▾ Midnightlinux · linux_kernelEPSS 10%via NVD
CVE-2024-21644High· 7.5PoC
2y ago

pyload Unauthenticated Flask Configuration Leakage vulnerability

pyload Unauthenticated Flask Configuration Leakage vulnerability

▾ Midnightpyload-ng · pyload-ngEPSS 42%via OSV
CVE-2024-21645Medium· 5.3PoC
2y ago

pyload Log Injection vulnerability

pyload Log Injection vulnerability

▾ Twilightpyload-ng · pyload-ngEPSS 25%via OSV
CVE-2024-21907High· 7.5PoC
2y ago

Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability

Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial…

▾ Midnightnewtonsoft · json.netEPSS 33%via NVD
CVE-2023-51449High· 8.6PoC
2y ago

Gradio makes the `/file` secure against file traversal and server-side request forgery attacks

Gradio makes the `/file` secure against file traversal and server-side request forgery attacks

▾ Midnightgradio · gradioEPSS 28%via OSV
CVE-2023-6546High· 7.00dayPoC
2y ago

A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel

A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a u…

▾ Abyssallinux · linux_kernelEPSS 0.73%via NVD
CVE-2023-6977High· 7.5PoC
2y ago

MLflow Local File Disclosure Vulnerability

MLflow Local File Disclosure Vulnerability

▾ Midnightmlflow · mlflowEPSS 3.9%via OSV
CVE-2023-6931High· 7.8PoC
2y ago

A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increme…

A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increme…

▾ Midnightlinux · linux_kernelEPSS 0.71%via NVD
CVE-2023-48795Medium· 5.9PoC
2y ago

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

▾ Twilightrussh · russhEPSS 94%via OSV
CVE-2023-6572Critical· 9.6PoC
2y ago

Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability

▾ Abyssalgradio · gradioEPSS 1.7%via OSV
CVE-2023-6710Medium· 5.4PoC
2y ago

A flaw was found in the mod_proxy_cluster in the Apache server

A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script …

▾ Twilightmodcluster · mod_proxy_clusterEPSS 2.2%via NVD
CVE-2023-43472High· 7.5PoC
2y ago

Information exposure in MLflow

Information exposure in MLflow

▾ Midnightmlflow · mlflowEPSS 37%via OSV
CVE-2023-48022Critical· 9.8PoC
2y ago

Ray has arbitrary code execution via jobs submission API

Ray has arbitrary code execution via jobs submission API

▾ Abyssalray · rayEPSS 84%via OSV
CVE-2023-49105Critical· 9.8CISA KEVPoC
2y ago

An issue was discovered in ownCloud owncloud/core before 10.13.1

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs b…

▾ Hadalowncloud · owncloud_serverEPSS 43%via NVD
CVEs tagged “exploit-available” — page 113 · VulnSea