VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3833 CVEsRSS

CVE-2020-15129Medium· 6.1PoC
4y ago

Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header

Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header

▾ Twilighttraefik · github.com/traefik/traefikEPSS 8.0%via OSV
CVE-2022-24682Medium· 6.1CISA KEV0dayPoC
4y ago

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript insi…

▾ Midnightsynacor · zimbra_collaboration_suiteEPSS 31%via NVD
CVE-2022-21728High· 8.1PoC
4y ago

Out of bounds read in Tensorflow

Out of bounds read in Tensorflow

▾ Midnighttensorflow · tensorflowEPSS 1.1%via OSV
CVE-2021-46354High· 7.5PoC
4y ago

Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site

Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can allow the vulnerable…

▾ Midnightcybelesoft · thinfinity_virtualuiEPSS 13%via NVD
CVE-2022-24348High· 7.7PoC
4y ago

Path traversal and dereference of symlinks in Argo CD

Path traversal and dereference of symlinks in Argo CD

▾ Midnightargoproj · github.com/argoproj/argo-cd/v2EPSS 2.7%via OSV
CVE-2021-44255High· 7.2PoC
4y ago

Unrestricted Upload of File with Dangerous Type in motionEye

Unrestricted Upload of File with Dangerous Type in motionEye

▾ Midnightmotioneye · motioneyeEPSS 3.1%via OSV
CVE-2021-45416Medium· 6.1PoC
4y ago

Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php script.

Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php script.

▾ Twilightrosariosis · rosariosisEPSS 2.3%via NVD
CVE-2021-4034High· 7.8CISA KEVPoC
4y ago

A local privilege escalation vulnerability was found on polkit's pkexec utility

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current …

▾ Abyssalpolkit_project · polkitEPSS 94%via NVD
CVE-2021-43831High· 8.3PoC
4y ago

Files on the host computer can be accessed from the Gradio interface

Files on the host computer can be accessed from the Gradio interface

▾ Midnightgradio · gradioEPSS 3.8%via OSV
CVE-2021-44217MediumPoC
4y ago

Cross-site Scripting in Ericsson CodeChecker

Cross-site Scripting in Ericsson CodeChecker

▾ Twilightcodechecker · codecheckerEPSS 1.6%via OSV
CVE-2022-23303Critical· 9.8PoC
4y ago

The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns

The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.

▾ Abyssalw1.fi · hostapdEPSS 3.1%via NVD
CVE-2021-45422Medium· 6.1PoC
4y ago

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process "count" parameter via GET

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process "count" parameter via GET. No authentication is required.

▾ Twilightreprisesoftware · reprise_license_managerEPSS 3.2%via NVD
CVE-2022-21882High· 7.0CISA KEV0dayPoC
4y ago

Win32k Elevation of Privilege Vulnerability

Win32k Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1809EPSS 59%via NVD
CVE-2021-43857Critical· 9.8PoC
4y ago

Gerapy may cause remote code execution

Gerapy may cause remote code execution

▾ Abyssalgerapy · gerapyEPSS 55%via OSV
CVE-2021-32849High· 8.8PoC
4y ago

An authenticated user can execute arbitrary command in Gerapy

An authenticated user can execute arbitrary command in Gerapy

▾ Midnightgerapy · gerapyEPSS 7.6%via OSV
CVE-2021-45485High· 7.5PoC
4y ago

In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically ch…

In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically ch…

▾ Midnightnetapp · e-series_santricity_os_controllerEPSS 3.6%via NVD
CVE-2021-44733High· 7.0PoC
4y ago

A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11

A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.

▾ Midnightlinux · linux_kernelEPSS 0.71%via NVD
CVE-2021-45105Medium· 5.90dayPoC
4y ago

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial …

▾ Midnightapache · log4jEPSS 100%via NVD
CVE-2021-43226High· 7.8CISA KEVPoC
4y ago

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Windows Common Log File System Driver Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 3.1%via NVD
CVE-2021-36450Medium· 6.1PoC
4y ago

Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.

Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.

▾ Twilightverint · workforce_optimizationEPSS 64%via NVD
CVE-2021-43811High· 7.8PoC
4y ago

Code injection via unsafe YAML loading

Code injection via unsafe YAML loading

▾ Midnightsockeye · sockeyeEPSS 2.4%via OSV
CVE-2021-44529Critical· 9.8CISA KEVPoC
4y ago

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

▾ Hadalivanti · endpoint_manager_cloud_services_applianceEPSS 99%via NVD
CVE-2021-23758High· 8.1CISA KEVPoC
4y ago

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

▾ Abyssalajaxpro.2_project · ajaxpro.2EPSS 83%via NVD
CVE-2021-41278Medium· 5.4PoC
4y ago

Broken encryption in EdgeX Foundry

Broken encryption in EdgeX Foundry

▾ Twilightedgexfoundry · github.com/edgexfoundry/app-functions-sdk-go/v2EPSS 0.32%via OSV
CVE-2021-41653Critical· 9.8⚠ ExploitedPoC
4y ago

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.

▾ Abyssaltp-link · tl-wr840n_firmwareEPSS 76%via NVD
CVE-2002-20001High· 7.5PoC
4y ago

The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)a…

The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)a…

▾ Midnightbalasys · dheaterEPSS 25%via NVD
CVE-2021-3572Medium· 5.7PoC
4y ago

A flaw was found in python-pip in the way it handled Unicode separators in git references

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to …

▾ Twilightpypa · pipEPSS 1.8%via NVD
CVE-2021-42321High· 8.8CISA KEVPoC
4y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · exchange_serverEPSS 92%via NVD
CVE-2021-42292High· 7.8CISA KEVPoC
4y ago

Microsoft Excel Security Feature Bypass Vulnerability

Microsoft Excel Security Feature Bypass Vulnerability

▾ Abyssalmicrosoft · 365_appsEPSS 43%via NVD
CVE-2021-42287High· 7.5CISA KEVPoC
4y ago

Active Directory Domain Services Elevation of Privilege Vulnerability

Active Directory Domain Services Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_server_2008EPSS 77%via NVD
CVEs tagged “exploit-available” — page 120 · VulnSea