VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3810 CVEsRSS

CVE-2023-37474High· 7.5PoC
3y ago

copyparty vulnerable to path traversal attack

copyparty vulnerable to path traversal attack

▾ Midnightcopyparty · copypartyEPSS 45%via OSV
CVE-2023-3390High· 7.8PoC
3y ago

A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction caus…

A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction caus…

▾ Midnightlinux · linux_kernelEPSS 0.91%via NVD
CVE-2023-36664High· 7.8PoC
3y ago

Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

▾ Midnightartifex · ghostscriptEPSS 4.0%via NVD
CVE-2023-3128Critical· 9.4PoC
3y ago

Grafana vulnerable to Authentication Bypass by Spoofing

Grafana vulnerable to Authentication Bypass by Spoofing

▾ Abyssalgrafana · github.com/grafana/grafanaEPSS 4.0%via OSV
CVE-2023-35788High· 7.8PoC
3y ago

An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7

An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial…

▾ MidnightEPSS 0.53%via CVEORG
CVE-2023-27997Critical· 9.8CISA KEV0dayPoC
3y ago

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, versio…

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, versio…

▾ Hadalfortinet · fortiproxyEPSS 86%via NVD
CVE-2023-33977High· 8.1PoC
3y ago

kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload

kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload

▾ Midnightkiwitcms · kiwitcmsEPSS 0.87%via OSV
CVE-2023-33733High· 7.8PoC
3y ago

Reportlab vulnerable to remote code execution

Reportlab vulnerable to remote code execution

▾ Midnightreportlab · reportlabEPSS 2.1%via OSV
CVE-2023-32681Medium· 6.1PoC
3y ago

Unintended leak of Proxy-Authorization header in requests

Unintended leak of Proxy-Authorization header in requests

▾ Twilightrequests · requestsEPSS 3.0%via OSV
CVE-2023-32309High· 7.5PoC
3y ago

Any file can be included with the pymdown-snippets extension

Any file can be included with the pymdown-snippets extension

▾ Midnightpymdown-extensions · pymdown-extensionsEPSS 1.7%via OSV
CVE-2023-30861High· 7.5PoC
3y ago

Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header

Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header

▾ Midnightflask · flaskEPSS 1.3%via OSV
CVE-2023-2375High· 7.2PoC
3y ago

A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. Impacted is an unknown function of the component Web Management Interface. Executing a manipulation of the argument src can lead to command injection. It is po…

▾ Midnightui · er-x_firmwareEPSS 9.3%via NVD
CVE-2023-27524High· 8.9CISA KEVPoC
3y ago

Apache superset missing check for default SECRET_KEY

Apache superset missing check for default SECRET_KEY

▾ Abyssalapache-superset · apache-supersetEPSS 97%via OSV
CVE-2023-2008High· 8.20dayPoC
3y ago

A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler

A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This issue occurs due to the lack of proper validation of user-supplied data, which can result in memory access past the end of an array. This may allo…

▾ Abyssallinux · linux_kernelEPSS 1.0%via NVD
CVE-2023-1829High· 7.8PoC
3y ago

A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect…

A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect…

▾ Midnightlinux · linux_kernelEPSS 1.1%via NVD
CVE-2023-1281High· 7.8PoC
3y ago

Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imperfect hash area can be updated while packets are traversing, which will cause a use-after-free when 'tcf_exts_exec()…

Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imperfect hash area can be updated while packets are traversing, which will cause a use-after-free when 'tcf_exts_exec()…

▾ Midnightlinux · linux_kernelEPSS 0.30%via NVD
CVE-2023-27534Low· 3.7PoC⚖ disputed
3y ago

curl: SFTP path ~ resolving discrepancy (CVE-2023-27534)

A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicat…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 2.2%via CSAF
CVE-2023-22432Medium· 6.1PoC
3y ago

Open redirect in web2py

Open redirect in web2py

▾ Twilightweb2py · web2pyEPSS 2.4%via OSV
CVE-2023-0943Medium· 4.7PoC
3y ago

A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0

A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. This issue affects the function save_settings of the file index.php?page=site_settings of the component Image Handler.…

▾ Twilightmayurik · best_pos_management_systemEPSS 2.3%via NVD
CVE-2023-0860High· 7.5PoC
3y ago

Improper Restriction of Excessive Authentication Attempts in modoboa

Improper Restriction of Excessive Authentication Attempts in modoboa

▾ Midnightmodoboa · modoboaEPSS 0.66%via OSV
CVE-2023-0669High· 7.2CISA KEVPoC
3y ago

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in versi…

▾ Abyssalfortra · goanywhere_managed_file_transferEPSS 100%via NVD
CVE-2022-4510High· 7.8PoC
3y ago

Path traversal in binwalk

Path traversal in binwalk

▾ Midnightbinwalk · binwalkEPSS 22%via OSV
CVE-2022-47966Critical· 9.8CISA KEVPoC
3y ago

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in t…

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in t…

▾ Hadalzohocorp · manageengine_access_manager_plusEPSS 100%via NVD
CVE-2022-26485High· 8.8CISA KEV0dayPoC
3y ago

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for A…

▾ Abyssalmozilla · firefoxEPSS 14%via NVD
CVE-2022-4223High· 8.8PoC
3y ago

pgadmin4 vulnerable to Code Injection

pgadmin4 vulnerable to Code Injection

▾ Midnightpgadmin4 · pgadmin4EPSS 80%via OSV
CVE-2022-42118Medium· 6.1PoC
3y ago

A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject…

A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject…

▾ Twilightliferay · liferay_portalEPSS 0.97%via NVD
CVE-2022-40684Critical· 9.8CISA KEV0dayPoC
3y ago

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 …

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 …

▾ Hadalfortinet · fortiproxyEPSS 100%via NVD
CVE-2022-35155Medium· 6.1PoC
4y ago

Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.

Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.

▾ Twilightphpgurukul · bus_pass_management_systemEPSS 2.5%via NVD
CVE-2022-41352Critical· 9.8CISA KEVPoC
4y ago

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to …

▾ Hadalsynacor · zimbra_collaboration_suiteEPSS 95%via NVD
CVE-2021-36782Critical· 9.9PoC
4y ago

Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials

Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials

▾ Abyssalrancher · github.com/rancher/rancherEPSS 4.2%via OSV
CVEs tagged “exploit-available” — page 115 · VulnSea