Tagged “exploit-available”
CVEs tagged exploit-available, newest first.
3811 CVEsRSS
CVE-2023-6019Critical· 9.8PoCRay OS Command Injection vulnerability
Ray OS Command Injection vulnerability
CVE-2023-6020Critical· 9.3PoCRay Missing Authorization vulnerability
Ray Missing Authorization vulnerability
CVE-2023-6021Critical· 9.3PoCRay Path Traversal vulnerability
Ray Path Traversal vulnerability
CVE-2023-47117High· 7.5PoCLabel Studio Object Relational Mapper Leak Vulnerability in Filtering Task
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
CVE-2023-47246Critical· 9.8CISA KEV0dayPoCIn SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
CVE-2023-47248Critical· 9.8PoCPyArrow: Arbitrary code execution when loading a malicious data file
PyArrow: Arbitrary code execution when loading a malicious data file
CVE-2023-27170High· 7.5PoCXpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.
Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.
CVE-2023-46136Medium· 5.7PoCWerkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
CVE-2023-5043High· 7.6PoCIngress nginx annotation injection causes arbitrary command execution
Ingress nginx annotation injection causes arbitrary command execution
CVE-2023-39325High· 7.5PoCHTTP/2 rapid reset can cause excessive work in net/http
HTTP/2 rapid reset can cause excessive work in net/http
CVE-2023-4966Critical· 9.4CISA KEVPoCSensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
CVE-2023-43261High· 7.5PoCAn information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
CVE-2023-43804Medium· 5.9PoC`Cookie` HTTP header isn't stripped on cross-origin redirects
`Cookie` HTTP header isn't stripped on cross-origin redirects
CVE-2023-43654Critical· 9.8PoCTorchServe Server-Side Request Forgery vulnerability
TorchServe Server-Side Request Forgery vulnerability
CVE-2023-43364Critical· 9.8PoCSearchor CLI's Search vulnerable to Arbitrary Code using Eval
Searchor CLI's Search vulnerable to Arbitrary Code using Eval
CVE-2023-4863High· 8.8CISA KEV0dayPoClibwebp: OOB write in BuildHuffmanTable
libwebp: OOB write in BuildHuffmanTable
CVE-2023-4622High· 7.8PoCA use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without lock…
A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without lock…
CVE-2023-39265Medium· 6.5PoCApache Superset Improper Input Validation vulnerability
Apache Superset Improper Input Validation vulnerability
CVE-2023-37941Medium· 6.6PoCApache Superset Deserialization of Untrusted Data vulnerability
Apache Superset Deserialization of Untrusted Data vulnerability
CVE-2023-28434High· 8.8CISA KEVPoCPrivilege Escalation on Linux/MacOS
Privilege Escalation on Linux/MacOS
CVE-2023-41266High· 8.2CISA KEVPoCA path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an un…
A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an un…
CVE-2023-41265Critical· 9.6CISA KEVPoCAn HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier all…
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier all…
CVE-2023-4548Medium· 6.3PoCA vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3
A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET Parameter Handler. Such manipulation of the argument filter[brandid] leads to sql inje…
CVE-2023-4547Low· 3.5PoCA flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3
A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected element is an unknown function of the file /search. This manipulation of the argument filter[brandid]/filter[price] causes cross site scripting. The attack is possible…
CVE-2023-38831High· 7.8CISA KEV0dayPoCRARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and al…
CVE-2023-38950High· 7.5CISA KEVPoCA path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
CVE-2023-35078Critical· 9.8CISA KEV0dayPoCAn authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
CVE-2023-3640High· 7.0PoCA possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data
A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-…
CVE-2023-3609High· 7.8PoCA use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing…
A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing…
CVE-2023-37276Medium· 5.3PoCaiohttp is an asynchronous HTTP client/server framework for asyncio and Python
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled with llhttp v6.0.6. Vulnerable code is used by aiohttp for its HTTP request parser when available which is the default…