Tagged “exploit-available”
CVEs tagged exploit-available, newest first.
3833 CVEsRSS
CVE-2021-42278High· 7.5CISA KEVPoCActive Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42237Critical· 9.8CISA KEV0dayPoCSitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is requir…
CVE-2021-41184Medium· 6.5PoCjQuery-UI is the official jQuery user interface library
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0.…
CVE-2021-41182Medium· 6.5PoCjQuery-UI is the official jQuery user interface library
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.…
CVE-2021-41078High· 8.6PoCNameko Arbitrary code execution due to YAML deserialization
Nameko Arbitrary code execution due to YAML deserialization
CVE-2021-29006Medium· 6.5PoCrConfig 3.9.6 is affected by a Local File Disclosure vulnerability
rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.
CVE-2021-40323Critical· 9.8PoCCobbler before 3.3.0 allows log poisoning
Cobbler before 3.3.0 allows log poisoning
CVE-2021-39226High· 7.3CISA KEVPoCAuthentication bypass for viewing and deletions of snapshots
Authentication bypass for viewing and deletions of snapshots
CVE-2021-41318Medium· 6.1PoCIn Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input
In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.
CVE-2021-41617High· 7.0PoCsshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and Authoriz…
CVE-2021-40438Critical· 9.0CISA KEVPoCA crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVE-2021-40444High· 8.8CISA KEV0dayPoCMicrosoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft …
CVE-2021-38648High· 7.8CISA KEVPoCOpen Management Infrastructure Elevation of Privilege Vulnerability
Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38647Critical· 9.8CISA KEVPoCOpen Management Infrastructure (OMI) Remote Code Execution Vulnerability
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CVE-2021-36955High· 7.8CISA KEVPoCWindows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-24040High· 8.4PoCDeserialization of Untrusted Data in parlai
Deserialization of Untrusted Data in parlai
CVE-2021-39156High· 8.1PoCIstio Fragments in Path May Lead to Authorization Policy Bypass
Istio Fragments in Path May Lead to Authorization Policy Bypass
CVE-2021-37678Critical· 9.3PoCArbitrary code execution due to YAML deserialization
Arbitrary code execution due to YAML deserialization
CVE-2021-36942High· 7.5CISA KEVPoCWindows LSA Spoofing Vulnerability
Windows LSA Spoofing Vulnerability
CVE-2021-34486High· 7.8CISA KEVPoCWindows Event Tracing Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-36934High· 7.8CISA KEVPoCAn elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnera…
CVE-2021-34523Critical· 9.0CISA KEV0dayPoCMicrosoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2021-34473Critical· 9.1CISA KEV0dayPoCMicrosoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-34470High· 8.0PoCMicrosoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2021-33766High· 7.3CISA KEV0dayPoCMicrosoft Exchange Server Information Disclosure Vulnerability
Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2021-30116Critical· 10.0CISA KEVPoCKaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page …
CVE-2021-34110High· 7.8PoCWinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a malicious file that will be executed with "LocalSystem" privileges.
WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a malicious file that will be executed with "LocalSystem" privileges.
CVE-2021-34527High· 8.8CISA KEVPoCA remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges…
CVE-2020-13258Medium· 6.1PoCCross-site scripting in Contentful
Cross-site scripting in Contentful
CVE-2021-1675High· 7.8CISA KEVPoCWindows Print Spooler Remote Code Execution Vulnerability
Windows Print Spooler Remote Code Execution Vulnerability