VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3811 CVEsRSS

CVE-2023-6019Critical· 9.8PoC
2y ago

Ray OS Command Injection vulnerability

Ray OS Command Injection vulnerability

▾ Abyssalray · rayEPSS 75%via OSV
CVE-2023-6020Critical· 9.3PoC
2y ago

Ray Missing Authorization vulnerability

Ray Missing Authorization vulnerability

▾ Abyssalray · rayEPSS 15%via OSV
CVE-2023-6021Critical· 9.3PoC
2y ago

Ray Path Traversal vulnerability

Ray Path Traversal vulnerability

▾ Abyssalray · rayEPSS 37%via OSV
CVE-2023-47117High· 7.5PoC
2y ago

Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task

Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task

▾ Midnightlabel-studio · label-studioEPSS 4.1%via OSV
CVE-2023-47246Critical· 9.8CISA KEV0dayPoC
2y ago

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

▾ Hadalsysaid · sysaidEPSS 99%via NVD
CVE-2023-47248Critical· 9.8PoC
2y ago

PyArrow: Arbitrary code execution when loading a malicious data file

PyArrow: Arbitrary code execution when loading a malicious data file

▾ Abyssalpyarrow · pyarrowEPSS 15%via OSV
CVE-2023-27170High· 7.5PoC
2y ago

Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.

Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.

▾ Midnightxpand-it · write-back_managerEPSS 0.87%via NVD
CVE-2023-46136Medium· 5.7PoC
2y ago

Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning

Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning

▾ Twilightwerkzeug · werkzeugEPSS 1.1%via OSV
CVE-2023-5043High· 7.6PoC
2y ago

Ingress nginx annotation injection causes arbitrary command execution

Ingress nginx annotation injection causes arbitrary command execution

▾ Midnightingress-nginx · k8s.io/ingress-nginxEPSS 2.2%via OSV
CVE-2023-39325High· 7.5PoC
2y ago

HTTP/2 rapid reset can cause excessive work in net/http

HTTP/2 rapid reset can cause excessive work in net/http

▾ Midnightstdlib · stdlibEPSS 3.8%via OSV
CVE-2023-4966Critical· 9.4CISA KEVPoC
2y ago

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

▾ Hadalcitrix · netscaler_application_delivery_controllerEPSS 100%via NVD
CVE-2023-43261High· 7.5PoC
2y ago

An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

▾ Midnightmilesight · ur5x_firmwareEPSS 60%via NVD
CVE-2023-43804Medium· 5.9PoC
2y ago

`Cookie` HTTP header isn't stripped on cross-origin redirects

`Cookie` HTTP header isn't stripped on cross-origin redirects

▾ Twilighturllib3 · urllib3EPSS 1.2%via OSV
CVE-2023-43654Critical· 9.8PoC
2y ago

TorchServe Server-Side Request Forgery vulnerability

TorchServe Server-Side Request Forgery vulnerability

▾ Abyssaltorchserve · torchserveEPSS 40%via OSV
CVE-2023-43364Critical· 9.8PoC
3y ago

Searchor CLI's Search vulnerable to Arbitrary Code using Eval

Searchor CLI's Search vulnerable to Arbitrary Code using Eval

▾ Abyssalsearchor · searchorEPSS 2.9%via OSV
CVE-2023-4863High· 8.8CISA KEV0dayPoC
3y ago

libwebp: OOB write in BuildHuffmanTable

libwebp: OOB write in BuildHuffmanTable

▾ Abyssallibwebp-sys2 · libwebp-sys2EPSS 100%via OSV
CVE-2023-4622High· 7.8PoC
3y ago

A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without lock…

A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without lock…

▾ Midnightlinux · linux_kernelEPSS 0.61%via NVD
CVE-2023-39265Medium· 6.5PoC
3y ago

Apache Superset Improper Input Validation vulnerability

Apache Superset Improper Input Validation vulnerability

▾ Twilightapache-superset · apache-supersetEPSS 86%via OSV
CVE-2023-37941Medium· 6.6PoC
3y ago

Apache Superset Deserialization of Untrusted Data vulnerability

Apache Superset Deserialization of Untrusted Data vulnerability

▾ Twilightapache-superset · apache-supersetEPSS 35%via OSV
CVE-2023-28434High· 8.8CISA KEVPoC
3y ago

Privilege Escalation on Linux/MacOS

Privilege Escalation on Linux/MacOS

▾ Abyssalminio · github.com/minio/minioEPSS 7.9%via OSV
CVE-2023-41266High· 8.2CISA KEVPoC
3y ago

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an un…

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an un…

▾ Abyssalqlik · qlik_senseEPSS 85%via NVD
CVE-2023-41265Critical· 9.6CISA KEVPoC
3y ago

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier all…

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier all…

▾ Hadalqlik · qlik_senseEPSS 88%via NVD
CVE-2023-4548Medium· 6.3PoC
3y ago

A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3

A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET Parameter Handler. Such manipulation of the argument filter[brandid] leads to sql inje…

▾ Twilightspa-cart · ecommerce_cmsEPSS 32%via NVD
CVE-2023-4547Low· 3.5PoC
3y ago

A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3

A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected element is an unknown function of the file /search. This manipulation of the argument filter[brandid]/filter[price] causes cross site scripting. The attack is possible…

▾ Twilightspa-cart · ecommerce_cmsEPSS 60%via NVD
CVE-2023-38831High· 7.8CISA KEV0dayPoC
3y ago

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and al…

▾ Abyssalrarlab · winrarEPSS 100%via NVD
CVE-2023-38950High· 7.5CISA KEVPoC
3y ago

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.

▾ Abyssalzkteco · biotimeEPSS 92%via NVD
CVE-2023-35078Critical· 9.8CISA KEV0dayPoC
3y ago

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

▾ Hadalivanti · endpoint_manager_mobileEPSS 100%via NVD
CVE-2023-3640High· 7.0PoC
3y ago

A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data

A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-…

▾ Midnightlinux · linux_kernelEPSS 0.76%via NVD
CVE-2023-3609High· 7.8PoC
3y ago

A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing…

A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing…

▾ Midnightlinux · linux_kernelEPSS 0.45%via NVD
CVE-2023-37276Medium· 5.3PoC
3y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled with llhttp v6.0.6. Vulnerable code is used by aiohttp for its HTTP request parser when available which is the default…

▾ Twilightaiohttp · aiohttpEPSS 1.3%via NVD
CVEs tagged “exploit-available” — page 114 · VulnSea