VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3833 CVEsRSS

CVE-2022-0995High· 7.8CISA KEVPoC
4y ago

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a …

▾ Abyssallinux · linux_kernelEPSS 8.8%via NVD
CVE-2018-25032High· 7.5PoC
4y ago

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

▾ Midnightnokogiri · nokogiriEPSS 52%via NVD
CVE-2021-40906Medium· 6.1PoC
4y ago

CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone

CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content an…

▾ Twilightcheckmk · checkmkEPSS 0.99%via NVD
CVE-2021-40904High· 8.8PoC
4y ago

The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code

The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Success…

▾ Midnightcheckmk · checkmkEPSS 3.7%via NVD
CVE-2022-26263Medium· 6.1PoC
4y ago

Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.

Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.

▾ Twilightyonyou · u8+EPSS 42%via NVD
CVE-2021-40905High· 8.8PoC
4y ago

The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible

The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible. Successful exploitation r…

▾ Midnightcheckmk · checkmkEPSS 3.0%via NVD
CVE-2022-27666High· 7.8PoC
4y ago

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privileg…

▾ Midnightredhat · virtualizationEPSS 5.5%via NVD
CVE-2022-23348Medium· 5.3PoC
4y ago

BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.

BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.

▾ Twilightbigantsoft · bigant_serverEPSS 3.3%via NVD
CVE-2022-23347High· 7.5PoC
4y ago

BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.

BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.

▾ Midnightbigantsoft · bigant_serverEPSS 13%via NVD
CVE-2022-1011High· 7.8PoC
4y ago

A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write()

A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.

▾ Midnightredhat · build_of_quarkusEPSS 1.2%via NVD
CVE-2022-0811High· 8.8PoC
4y ago

Code Injection in CRI-O

Code Injection in CRI-O

▾ Midnightcri-o · github.com/cri-o/cri-oEPSS 19%via OSV
CVE-2022-25090High· 8.1PoC
4y ago

Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition.

Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition.

▾ Midnightkofax · printixEPSS 11%via NVD
CVE-2022-24644High· 8.8PoC
4y ago

ZZ Inc

ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated update. To exploit this vulnerability, a user must trigger an update of an affected installation of KeyMouse.

▾ Midnightzzinc · keymouse_firmwareEPSS 1.9%via NVD
CVE-2022-0869Medium· 6.1PoC
4y ago

Open Redirect in django-spirit

Open Redirect in django-spirit

▾ Twilightdjango-spirit · django-spiritEPSS 2.6%via OSV
CVE-2021-3654Medium· 6.1PoC
4y ago

Open Redirect in CPython that affects users of OpenStack Nova

Open Redirect in CPython that affects users of OpenStack Nova

▾ Twilightnova · novaEPSS 27%via OSV
CVE-2020-18326High· 8.8PoC
4y ago

Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfull…

Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfull…

▾ Midnightintelliants · subrion_cmsEPSS 2.2%via NVD
CVE-2020-18325Medium· 6.1PoC
4y ago

Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.

Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.

▾ Twilightintelliants · subrion_cmsEPSS 1.6%via NVD
CVE-2020-18324Medium· 6.1PoC
4y ago

Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.

Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.

▾ Twilightintelliants · subrion_cmsEPSS 2.2%via NVD
CVE-2022-25089Critical· 9.8PoC
4y ago

Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.

Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.

▾ Abyssalkofax · printixEPSS 18%via NVD
CVE-2022-25020Medium· 5.4PoC
4y ago

A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.

A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.

▾ Twilightpluxml · pluxmlEPSS 1.2%via NVD
CVE-2022-25018High· 8.8PoC
4y ago

Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

▾ Midnightpluxml · pluxmlEPSS 2.7%via NVD
CVE-2022-25022Medium· 5.4PoC
4y ago

A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.

A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.

▾ Twilighthtmly · htmlyEPSS 1.1%via NVD
CVE-2022-25064Critical· 9.8PoC
4y ago

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

▾ Abyssaltp-link · tl-wr840n_firmwareEPSS 36%via NVD
CVE-2022-25062High· 7.5PoC
4y ago

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

▾ Midnighttp-link · tl-wr840n_firmwareEPSS 3.5%via NVD
CVE-2022-25061Critical· 9.8PoC
4y ago

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

▾ Abyssaltp-link · tl-wr840n_firmwareEPSS 59%via NVD
CVE-2022-25060Critical· 9.8⚠ ExploitedPoC
4y ago

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

▾ Abyssaltp-link · tl-wr840n_firmwareEPSS 40%via NVD
CVE-2022-22916Critical· 9.8PoC
4y ago

O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.

O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.

▾ Abyssalzoneland · o2oaEPSS 39%via NVD
CVE-2018-1002105Critical· 9.8PoC
4y ago

Privilege Escalation in Kubernetes

Privilege Escalation in Kubernetes

▾ Abyssalkubernetes · github.com/kubernetes/kubernetesEPSS 87%via OSV
CVE-2019-1002101Medium· 5.5PoC
4y ago

Symlink Attack in kubectl cp

Symlink Attack in kubectl cp

▾ Twilightkubernetes · k8s.io/kubernetesEPSS 13%via OSV
CVE-2021-45420Critical· 9.8PoC
4y ago

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system with…

▾ Abyssalemerson · dixell_xweb-500_firmwareEPSS 18%via NVD
CVEs tagged “exploit-available” — page 119 · VulnSea