Tagged “exploit-available”
CVEs tagged exploit-available, newest first.
3811 CVEsRSS
CVE-2024-21762Critical· 9.8CISA KEV0dayPoCA out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…
CVE-2024-24590High· 8.8PoCAllegro AI ClearML vulnerable to deserialization of untrusted data
Allegro AI ClearML vulnerable to deserialization of untrusted data
CVE-2024-21485Medium· 6.5PoCDash apps vulnerable to Cross-site Scripting
Dash apps vulnerable to Cross-site Scripting
CVE-2021-43798High· 7.5CISA KEVPoCGrafana path traversal
Grafana path traversal
CVE-2024-23652Critical· 10.0PoCBuildKit vulnerable to possible host system access from mount stub cleaner
BuildKit vulnerable to possible host system access from mount stub cleaner
CVE-2024-1086High· 7.8CISA KEVPoCA use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …
CVE-2024-21893High· 8.2CISA KEV0dayPoCA server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…
CVE-2021-41091Medium· 5.9PoCMoby (Docker Engine) Insufficiently restricted permissions on data directory
Moby (Docker Engine) Insufficiently restricted permissions on data directory
CVE-2024-21626High· 8.6PoCrunc is a CLI tool for spawning and running containers on Linux according to the OCI specification
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc…
CVE-2024-23334Medium· 5.9PoCaiohttp is vulnerable to directory traversal
aiohttp is vulnerable to directory traversal
CVE-2023-52251High· 8.8PoCAn issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages
An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages. No fixed release is available; the project has had no com…
CVE-2023-47115High· 7.1PoCCross-site Scripting Vulnerability on Avatar Upload
Cross-site Scripting Vulnerability on Avatar Upload
CVE-2023-27168Critical· 9.8PoCAn arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.
An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.
CVE-2024-22416Critical· 9.6PoCCross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation
Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation
CVE-2024-21887Critical· 9.1CISA KEV0dayPoCA command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…
CVE-2023-46805High· 8.2CISA KEV0dayPoCAn authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
CVE-2022-2586Medium· 5.3CISA KEV0dayPoCIt was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
CVE-2024-21644High· 7.5PoCpyload Unauthenticated Flask Configuration Leakage vulnerability
pyload Unauthenticated Flask Configuration Leakage vulnerability
CVE-2024-21645Medium· 5.3PoCpyload Log Injection vulnerability
pyload Log Injection vulnerability
CVE-2024-21907High· 7.5PoCNewtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability
Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial…
CVE-2023-51449High· 8.6PoCGradio makes the `/file` secure against file traversal and server-side request forgery attacks
Gradio makes the `/file` secure against file traversal and server-side request forgery attacks
CVE-2023-6546High· 7.00dayPoCA race condition was found in the GSM 0710 tty multiplexor in the Linux kernel
A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a u…
CVE-2023-6977High· 7.5PoCMLflow Local File Disclosure Vulnerability
MLflow Local File Disclosure Vulnerability
CVE-2023-6931High· 7.8PoCA heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increme…
A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increme…
CVE-2023-48795Medium· 5.9PoCPrefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
CVE-2023-6572Critical· 9.6PoCGradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-6710Medium· 5.4PoCA flaw was found in the mod_proxy_cluster in the Apache server
A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script …
CVE-2023-43472High· 7.5PoCInformation exposure in MLflow
Information exposure in MLflow
CVE-2023-48022Critical· 9.8PoCRay has arbitrary code execution via jobs submission API
Ray has arbitrary code execution via jobs submission API
CVE-2023-49105Critical· 9.8CISA KEVPoCAn issue was discovered in ownCloud owncloud/core before 10.13.1
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs b…