VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3833 CVEsRSS

CVE-2021-42278High· 7.5CISA KEVPoC
4y ago

Active Directory Domain Services Elevation of Privilege Vulnerability

Active Directory Domain Services Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_server_2004EPSS 73%via NVD
CVE-2021-42237Critical· 9.8CISA KEV0dayPoC
4y ago

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is requir…

▾ Hadalsitecore · experience_platformEPSS 98%via NVD
CVE-2021-41184Medium· 6.5PoC
4y ago

jQuery-UI is the official jQuery user interface library

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0.…

▾ Twilightjqueryui · jquery_uiEPSS 41%via NVD
CVE-2021-41182Medium· 6.5PoC
4y ago

jQuery-UI is the official jQuery user interface library

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.…

▾ Twilightjqueryui · jquery_uiEPSS 39%via NVD
CVE-2021-41078High· 8.6PoC
4y ago

Nameko Arbitrary code execution due to YAML deserialization

Nameko Arbitrary code execution due to YAML deserialization

▾ Midnightnameko · namekoEPSS 1.5%via OSV
CVE-2021-29006Medium· 6.5PoC
4y ago

rConfig 3.9.6 is affected by a Local File Disclosure vulnerability

rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.

▾ Twilightrconfig · rconfigEPSS 5.6%via NVD
CVE-2021-40323Critical· 9.8PoC
4y ago

Cobbler before 3.3.0 allows log poisoning

Cobbler before 3.3.0 allows log poisoning

▾ Abyssalcobbler · cobblerEPSS 87%via OSV
CVE-2021-39226High· 7.3CISA KEVPoC
4y ago

Authentication bypass for viewing and deletions of snapshots

Authentication bypass for viewing and deletions of snapshots

▾ Abyssalgrafana · github.com/grafana/grafanaEPSS 100%via OSV
CVE-2021-41318Medium· 6.1PoC
5y ago

In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input

In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.

▾ Twilightprogress · whatsup_goldEPSS 5.9%via NVD
CVE-2021-41617High· 7.0PoC
5y ago

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and Authoriz…

▾ Midnightopenbsd · opensshEPSS 2.5%via NVD
CVE-2021-40438Critical· 9.0CISA KEVPoC
5y ago

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

▾ Hadalredhat · jboss_core_servicesEPSS 100%via NVD
CVE-2021-40444High· 8.8CISA KEV0dayPoC
5y ago

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft …

▾ Abyssalmicrosoft · windows_10_1507EPSS 97%via NVD
CVE-2021-38648High· 7.8CISA KEVPoC
5y ago

Open Management Infrastructure Elevation of Privilege Vulnerability

Open Management Infrastructure Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · azure_automation_state_configurationEPSS 11%via NVD
CVE-2021-38647Critical· 9.8CISA KEVPoC
5y ago

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

▾ Hadalmicrosoft · azure_automation_state_configurationEPSS 100%via NVD
CVE-2021-36955High· 7.8CISA KEVPoC
5y ago

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Windows Common Log File System Driver Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 4.0%via NVD
CVE-2021-24040High· 8.4PoC
5y ago

Deserialization of Untrusted Data in parlai

Deserialization of Untrusted Data in parlai

▾ Midnightparlai · parlaiEPSS 17%via OSV
CVE-2021-39156High· 8.1PoC
5y ago

Istio Fragments in Path May Lead to Authorization Policy Bypass

Istio Fragments in Path May Lead to Authorization Policy Bypass

▾ Midnightistio · istio.io/istioEPSS 1.2%via OSV
CVE-2021-37678Critical· 9.3PoC
5y ago

Arbitrary code execution due to YAML deserialization

Arbitrary code execution due to YAML deserialization

▾ Abyssaltensorflow · tensorflowEPSS 0.45%via OSV
CVE-2021-36942High· 7.5CISA KEVPoC
5y ago

Windows LSA Spoofing Vulnerability

Windows LSA Spoofing Vulnerability

▾ Abyssalmicrosoft · windows_server_2004EPSS 66%via NVD
CVE-2021-34486High· 7.8CISA KEVPoC
5y ago

Windows Event Tracing Elevation of Privilege Vulnerability

Windows Event Tracing Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1809EPSS 9.3%via NVD
CVE-2021-36934High· 7.8CISA KEVPoC
5y ago

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnera…

▾ Abyssalmicrosoft · windows_10_1809EPSS 67%via NVD
CVE-2021-34523Critical· 9.0CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Microsoft Exchange Server Elevation of Privilege Vulnerability

▾ Hadalmicrosoft · exchange_serverEPSS 100%via NVD
CVE-2021-34473Critical· 9.1CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Hadalmicrosoft · exchange_serverEPSS 100%via NVD
CVE-2021-34470High· 8.0PoC
5y ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Microsoft Exchange Server Elevation of Privilege Vulnerability

▾ Midnightmicrosoft · exchange_serverEPSS 4.4%via NVD
CVE-2021-33766High· 7.3CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Information Disclosure Vulnerability

Microsoft Exchange Server Information Disclosure Vulnerability

▾ Abyssalmicrosoft · exchange_serverEPSS 98%via NVD
CVE-2021-30116Critical· 10.0CISA KEVPoC
5y ago

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page …

▾ Hadalkaseya · vsa_agentEPSS 86%via NVD
CVE-2021-34110High· 7.8PoC
5y ago

WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a malicious file that will be executed with "LocalSystem" privileges.

WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a malicious file that will be executed with "LocalSystem" privileges.

▾ Midnightnica · winwaste.netEPSS 1.2%via NVD
CVE-2021-34527High· 8.8CISA KEVPoC
5y ago

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges…

▾ Abyssalmicrosoft · windows_10_1507EPSS 100%via NVD
CVE-2020-13258Medium· 6.1PoC
5y ago

Cross-site scripting in Contentful

Cross-site scripting in Contentful

▾ Twilightcontentful · contentfulEPSS 2.1%via OSV
CVE-2021-1675High· 7.8CISA KEVPoC
5y ago

Windows Print Spooler Remote Code Execution Vulnerability

Windows Print Spooler Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 85%via NVD
CVEs tagged “exploit-available” — page 121 · VulnSea