VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3809 CVEsRSS

CVE-2022-29004Medium· 6.1PoC
4y ago

Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.

Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.

▾ Twilightphpgurukul · e-diary_management_systemEPSS 2.9%via NVD
CVE-2022-28944High· 8.8PoC
4y ago

Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check

Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote …

▾ Midnightemcosoftware · msi_package_builderEPSS 1.5%via NVD
CVE-2014-3840MediumPoC
4y ago

Mayan EDMS multiple cross-site scripting (XSS) vulnerabilities

Mayan EDMS multiple cross-site scripting (XSS) vulnerabilities

▾ Twilightmayan-edms · mayan-edmsEPSS 3.5%via OSV
CVE-2016-4807Medium· 4.8PoC
4y ago

Web2py Reflected XSS vulnerability

Web2py Reflected XSS vulnerability

▾ Twilightweb2py · web2pyEPSS 2.3%via OSV
CVE-2016-4808Medium· 4.5PoC
4y ago

Web2py Cross-Site Request Forgery vulnerability

Web2py Cross-Site Request Forgery vulnerability

▾ Twilightweb2py · web2pyEPSS 1.8%via OSV
CVE-2011-3587HighPoC
4y ago

Zope Command Execution Vulnerability

Zope Command Execution Vulnerability

▾ Midnightzope2 · zope2EPSS 78%via OSV
CVE-2022-24611Medium· 6.5PoC
4y ago

Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but abs…

Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but abs…

▾ Twilightsilabs · zm5202_firmwareEPSS 0.69%via NVD
CVE-2014-3225MediumPoC
4y ago

Cobbler Path Traversal vulnerability

Cobbler Path Traversal vulnerability

▾ Twilightcobbler · cobblerEPSS 8.9%via OSV
CVE-2015-3221MediumPoC
4y ago

OpenStack Neutron Improper Input Validation vulnerability

OpenStack Neutron Improper Input Validation vulnerability

▾ Twilightneutron · neutronEPSS 11%via OSV
CVE-2022-28078Medium· 6.1PoC
4y ago

Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.

Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.

▾ Twilighthome_owners_collection_management_system_project · home_owners_collection_management_systemEPSS 1.1%via NVD
CVE-2022-28077Medium· 6.1PoC
4y ago

Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.

Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.

▾ Twilighthome_owners_collection_management_system_project · home_owners_collection_management_systemEPSS 0.81%via NVD
CVE-2022-28986High· 7.5PoC
4y ago

LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone n…

LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone n…

▾ Midnightlmsdoctor · 2_factor_authenticationEPSS 2.3%via NVD
CVE-2022-30333High· 7.5CISA KEVPoC
4y ago

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

▾ Abyssalrarlab · unrarEPSS 99%via NVD
CVE-2022-1592High· 8.2PoC
4y ago

Server-Side Request Forgery in scout-browser

Server-Side Request Forgery in scout-browser

▾ Midnightscout-browser · scout-browserEPSS 1.2%via OSV
CVE-2021-45783Medium· 4.6PoC
4y ago

Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information.

Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information.

▾ Twilightbookeen · notea_firmwareEPSS 1.9%via NVD
CVE-2021-43164High· 8.8PoC
4y ago

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.

▾ Midnightruijienetworks · reyeeosEPSS 35%via NVD
CVE-2022-28118Critical· 9.8PoC
4y ago

SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.

SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.

▾ Abyssalsscms · siteserver_cmsEPSS 2.8%via NVD
CVE-2009-0260MediumPoC
4y ago

MoinMoin Multiple cross-site scripting (XSS) vulnerabilities

MoinMoin Multiple cross-site scripting (XSS) vulnerabilities

▾ Twilightmoin · moinEPSS 5.5%via OSV
CVE-2021-31674Medium· 6.1PoC
4y ago

Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.

Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.

▾ Twilightcyclos · cyclosEPSS 3.9%via NVD
CVE-2021-31673Medium· 6.1PoC
4y ago

A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.

A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.

▾ Twilightcyclos · cyclosEPSS 2.6%via NVD
CVE-2006-1711MediumPoC
4y ago

Plone allows remote users to modify arbitrary portraits

Plone allows remote users to modify arbitrary portraits

▾ Twilightplone · ploneEPSS 4.0%via OSV
CVE-2008-0782MediumPoC
4y ago

MoinMoin Directory traversal vulnerability

MoinMoin Directory traversal vulnerability

▾ Twilightmoin · moinEPSS 15%via OSV
CVE-2022-1227High· 8.8PoC
4y ago

Podman publishes a malicious image to public registries

Podman publishes a malicious image to public registries

▾ Midnightcontainers · github.com/containers/podman/v3EPSS 4.2%via OSV
CVE-2004-1444MediumPoC
4y ago

Roundup Directory traversal vulnerability

Roundup Directory traversal vulnerability

▾ Twilightroundup · roundupEPSS 8.9%via OSV
CVE-2003-0038MediumPoC
4y ago

Mailman Cross-site scripting (XSS) vulnerability

Mailman Cross-site scripting (XSS) vulnerability

▾ Twilightmailman · mailmanEPSS 4.8%via OSV
CVE-2021-44596Critical· 9.8PoC
4y ago

Wondershare LTD Dr

Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the service is running unde…

▾ Abyssalwondershare · dr.foneEPSS 23%via NVD
CVE-2021-44595High· 8.8PoC
4y ago

Wondershare Dr

Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to the ElevationService.exe and execute arbitrary code without any validation with SYSTEM pri…

▾ Midnightwondershare · dr.foneEPSS 21%via NVD
CVE-2022-27985Critical· 9.8PoC
4y ago

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

▾ Abyssalcuppacms · cuppacmsEPSS 6.6%via NVD
CVE-2022-27984Critical· 9.8PoC
4y ago

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

▾ Abyssalcuppacms · cuppacmsEPSS 6.8%via NVD
CVE-2021-36460High· 7.8PoC
4y ago

VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords

VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allow…

▾ Midnightveryfitpro_project · veryfitproEPSS 0.36%via NVD
CVEs tagged “exploit-available” — page 117 · VulnSea