VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3834 CVEsRSS

CVE-2021-1675High· 7.8CISA KEVPoC
5y ago

Windows Print Spooler Remote Code Execution Vulnerability

Windows Print Spooler Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 85%via NVD
CVE-2021-21985Critical· 9.8CISA KEVPoC
5y ago

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to por…

▾ Hadalvmware · vcenter_serverEPSS 100%via NVD
CVE-2020-15257Medium· 5.2PoC
5y ago

containerd-shim API Exposed to Host Network Containers

containerd-shim API Exposed to Host Network Containers

▾ Twilightcontainerd · github.com/containerd/containerdEPSS 3.2%via OSV
CVE-2020-26160High· 7.5PoC
5y ago

Authorization bypass in github.com/dgrijalva/jwt-go

Authorization bypass in github.com/dgrijalva/jwt-go

▾ Midnightdgrijalva · github.com/dgrijalva/jwt-goEPSS 2.2%via OSV
CVE-2021-33034High· 7.8PoC
5y ago

In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409

In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.

▾ Midnightlinux · linux_kernelEPSS 0.82%via NVD
CVE-2021-22893Critical· 10.0CISA KEVPoC
5y ago

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticat…

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticat…

▾ Hadalivanti · connect_secureEPSS 47%via NVD
CVE-2021-22205Critical· 10.0CISA KEVPoC
5y ago

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

▾ Hadalgitlab · gitlabEPSS 100%via NVD
CVE-2021-25680Medium· 6.1PoC
5y ago

The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues

The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not …

▾ Twilightadtran · personal_phone_managerEPSS 2.5%via NVD
CVE-2021-25679Medium· 5.4PoC
5y ago

The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues

The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have…

▾ Twilightadtran · personal_phone_managerEPSS 2.7%via NVD
CVE-2021-25681High· 7.5PoC
5y ago

AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS

AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. This could allow for exposed AdTran Personal Phone Manager web servers to be used as DNS redirectors to tunnel arbitra…

▾ Midnightadtran · personal_phone_managerEPSS 11%via NVD
CVE-2021-29425Medium· 4.8PoC
5y ago

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent di…

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent di…

▾ Twilightapache · commons_ioEPSS 9.9%via NVD
CVE-2020-24285High· 7.5PoC
5y ago

INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgiServer.exx.

INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgiServer.exx.

▾ Midnightintelbras · tip200_firmwareEPSS 4.4%via NVD
CVE-2021-20021Critical· 9.8CISA KEVPoC
5y ago

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

▾ Hadalsonicwall · email_securityEPSS 89%via NVD
CVE-2021-21423Medium· 6.8PoC
5y ago

Rebuild-bot workflow may allow unauthorised repository modifications

Rebuild-bot workflow may allow unauthorised repository modifications

▾ Twilightprojen · projenEPSS 1.4%via OSV
CVE-2021-30109Medium· 6.1PoC
5y ago

Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS)

Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent Cross-site scripting (XSS) vulnerability within the hyperlink creation module.

▾ Twilightfroala · froala_editorEPSS 1.2%via NVD
CVE-2021-21983Medium· 6.5PoC
5y ago

Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locati…

Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locati…

▾ Twilightvmware · cloud_foundationEPSS 69%via NVD
CVE-2021-21975High· 7.5CISA KEVPoC
5y ago

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal…

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal…

▾ Abyssalvmware · cloud_foundationEPSS 78%via NVD
CVE-2021-28937High· 7.5PoC
5y ago

The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext

The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext. The page can be intercepted on HTTP.

▾ Midnightacexy · wireless-n_wifi_repeater_firmwareEPSS 4.2%via NVD
CVE-2021-27695Medium· 6.1PoC
5y ago

Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Par…

Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Par…

▾ Twilightopenmaint · openmaintEPSS 3.0%via NVD
CVE-2021-26411High· 8.8CISA KEV0dayPoC
5y ago

Internet Explorer Memory Corruption Vulnerability

Internet Explorer Memory Corruption Vulnerability

▾ Abyssalmicrosoft · edgeEPSS 81%via NVD
CVE-2020-29238High· 7.5PoC
5y ago

An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request.

An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request.

▾ Midnightexpressvpn · expressvpnEPSS 16%via NVD
CVE-2021-21337Medium· 5.7PoC
5y ago

URL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService

URL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService

▾ Twilightproducts-pluggableauthservice · products-pluggableauthserviceEPSS 8.4%via OSV
CVE-2021-27365High· 7.8PoC
5y ago

An issue was discovered in the Linux kernel through 5.11.3

An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is a…

▾ Midnightnetapp · cloud_backupEPSS 2.1%via NVD
CVE-2020-24912Medium· 6.1PoC
5y ago

A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.

A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.

▾ Twilightqcubed · qcubedEPSS 6.3%via NVD
CVE-2020-24913Critical· 9.8PoC
5y ago

A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.

A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.

▾ Abyssalqcubed · qcubedEPSS 41%via NVD
CVE-2021-27065High· 7.8CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · exchange_serverEPSS 100%via NVD
CVE-2021-26857High· 7.8CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · exchange_serverEPSS 96%via NVD
CVE-2021-26855Critical· 9.1CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Hadalmicrosoft · exchange_serverEPSS 100%via NVD
CVE-2021-27132Critical· 9.8PoC
5y ago

SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.

SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.

▾ Abyssalsercomm · agcombo_vd625_firmwareEPSS 16%via NVD
CVE-2021-1732High· 7.8CISA KEV0dayPoC
5y ago

Windows Win32k Elevation of Privilege Vulnerability

Windows Win32k Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1803EPSS 78%via NVD
CVEs tagged “exploit-available” — page 122 · VulnSea