Tagged “exploit-available”
CVEs tagged exploit-available, newest first.
3809 CVEsRSS
CVE-2022-29004Medium· 6.1PoCDiary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.
Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.
CVE-2022-28944High· 8.8PoCCertain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check
Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote …
CVE-2014-3840MediumPoCMayan EDMS multiple cross-site scripting (XSS) vulnerabilities
Mayan EDMS multiple cross-site scripting (XSS) vulnerabilities
CVE-2016-4807Medium· 4.8PoCWeb2py Reflected XSS vulnerability
Web2py Reflected XSS vulnerability
CVE-2016-4808Medium· 4.5PoCWeb2py Cross-Site Request Forgery vulnerability
Web2py Cross-Site Request Forgery vulnerability
CVE-2011-3587HighPoCZope Command Execution Vulnerability
Zope Command Execution Vulnerability
CVE-2022-24611Medium· 6.5PoCDenial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but abs…
Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but abs…
CVE-2014-3225MediumPoCCobbler Path Traversal vulnerability
Cobbler Path Traversal vulnerability
CVE-2015-3221MediumPoCOpenStack Neutron Improper Input Validation vulnerability
OpenStack Neutron Improper Input Validation vulnerability
CVE-2022-28078Medium· 6.1PoCHome Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.
CVE-2022-28077Medium· 6.1PoCHome Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.
CVE-2022-28986High· 7.5PoCLMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone n…
LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone n…
CVE-2022-30333High· 7.5CISA KEVPoCRARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
CVE-2022-1592High· 8.2PoCServer-Side Request Forgery in scout-browser
Server-Side Request Forgery in scout-browser
CVE-2021-45783Medium· 4.6PoCBookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information.
Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information.
CVE-2021-43164High· 8.8PoCA Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.
CVE-2022-28118Critical· 9.8PoCSiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
CVE-2009-0260MediumPoCMoinMoin Multiple cross-site scripting (XSS) vulnerabilities
MoinMoin Multiple cross-site scripting (XSS) vulnerabilities
CVE-2021-31674Medium· 6.1PoCCyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.
Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.
CVE-2021-31673Medium· 6.1PoCA Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.
A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.
CVE-2006-1711MediumPoCPlone allows remote users to modify arbitrary portraits
Plone allows remote users to modify arbitrary portraits
CVE-2008-0782MediumPoCMoinMoin Directory traversal vulnerability
MoinMoin Directory traversal vulnerability
CVE-2022-1227High· 8.8PoCPodman publishes a malicious image to public registries
Podman publishes a malicious image to public registries
CVE-2004-1444MediumPoCRoundup Directory traversal vulnerability
Roundup Directory traversal vulnerability
CVE-2003-0038MediumPoCMailman Cross-site scripting (XSS) vulnerability
Mailman Cross-site scripting (XSS) vulnerability
CVE-2021-44596Critical· 9.8PoCWondershare LTD Dr
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the service is running unde…
CVE-2021-44595High· 8.8PoCWondershare Dr
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to the ElevationService.exe and execute arbitrary code without any validation with SYSTEM pri…
CVE-2022-27985Critical· 9.8PoCCuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
CVE-2022-27984Critical· 9.8PoCCuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
CVE-2021-36460High· 7.8PoCVeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords
VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allow…