VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3848 CVEsRSS

CVE-2020-0618High· 8.8CISA KEVPoC
6y ago

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

▾ Abyssalmicrosoft · sql_serverEPSS 99%via NVD
CVE-2020-5236Medium· 5.7PoC
6y ago

Catastrophic backtracking in regex allows Denial of Service in Waitress

Catastrophic backtracking in regex allows Denial of Service in Waitress

▾ Twilightwaitress · waitressEPSS 2.4%via OSV
CVE-2019-16784High· 7.0PoC
6y ago

Local Privilege Escalation in PyInstaller

Local Privilege Escalation in PyInstaller

▾ Midnightpyinstaller · pyinstallerEPSS 0.69%via OSV
CVE-2014-5287High· 8.8PoC
6y ago

A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).

A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).

▾ Midnightprogress · loadmasterEPSS 8.0%via NVD
CVE-2019-19781Critical· 9.8CISA KEVPoC
6y ago

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

▾ Hadalcitrix · application_delivery_controller_firmwareEPSS 100%via NVD
CVE-2019-7481High· 7.5CISA KEVPoC
6y ago

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

▾ Abyssalsonicwall · sma_100_firmwareEPSS 100%via NVD
CVE-2019-19634Critical· 9.8PoC
6y ago

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.

▾ Abyssalverot_project · verotEPSS 4.2%via NVD
CVE-2019-1458High· 7.8CISA KEV0dayPoC
6y ago

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

▾ Abyssalmicrosoft · windows_10_1507EPSS 74%via NVD
CVE-2019-19576Critical· 9.8PoC
6y ago

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

▾ Abyssalverot_project · verotEPSS 26%via NVD
CVE-2019-6693Medium· 6.5CISA KEVPoC
6y ago

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementio…

▾ Midnightfortinet · fortiosEPSS 5.8%via NVD
CVE-2019-1405High· 7.8CISA KEVPoC
6y ago

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.

▾ Abyssalmicrosoft · windows_10_1507EPSS 30%via NVD
CVE-2019-10219Medium· 6.1PoC
6y ago

A vulnerability was found in Hibernate-Validator

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS a…

▾ Twilightredhat · hibernate_validatorEPSS 2.2%via NVD
CVE-2019-1978Medium· 5.8PoC
6y ago

A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to b…

A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to b…

▾ Twilightcisco · firepower_services_software_for_asaEPSS 9.4%via NVD
CVE-2017-18638High· 7.5PoC
6y ago

graphite.composer.views.send_email vulnerable to SSRF

graphite.composer.views.send_email vulnerable to SSRF

▾ Midnightgraphite-web · graphite-webEPSS 15%via OSV
CVE-2019-13529High· 8.8PoC
6y ago

An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior

An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses …

▾ Midnightsma · sunny_webbox_firmwareEPSS 3.1%via NVD
CVE-2019-15107Critical· 9.8CISA KEVPoC
7y ago

An issue was discovered in Webmin <=1.920

An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.

▾ Hadalwebmin · webminEPSS 100%via NVD
CVE-2019-14750Medium· 6.1PoC
7y ago

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The inse…

▾ Twilightenhancesoft · osticketEPSS 11%via NVD
CVE-2019-14749High· 8.8PoC
7y ago

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or unfiltered user inp…

▾ Midnightenhancesoft · osticketEPSS 9.6%via NVD
CVE-2019-14748Medium· 5.4PoC
7y ago

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implement…

▾ Twilightenhancesoft · osticketEPSS 2.7%via NVD
CVE-2019-1579High· 8.1CISA KEVPoC
7y ago

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute a…

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute a…

▾ Abyssalpaloaltonetworks · pan-osEPSS 46%via NVD
CVE-2019-1068High· 8.8CISA KEVPoC
7y ago

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

▾ Abyssalmicrosoft · sql_serverEPSS 58%via NVD
CVE-2019-1069High· 7.8CISA KEVPoC
7y ago

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploi…

▾ Abyssalmicrosoft · windows_10_1507EPSS 6.1%via NVD
CVE-2019-10869High· 8.1PoC
7y ago

Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated)

Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the…

▾ Midnightninjaforms · ninja_forms_file_uploadsEPSS 8.0%via NVD
CVE-2019-2725Critical· 9.8CISA KEVPoC
7y ago

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services)

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated a…

▾ Hadaloracle · agile_plmEPSS 100%via NVD
CVE-2019-11358Medium· 6.1⚠ ExploitedPoC
7y ago

XSS in jQuery as used in Drupal, Backdrop CMS, and other products

XSS in jQuery as used in Drupal, Backdrop CMS, and other products

▾ Twilightjquery · jqueryEPSS 87%via OSV
CVE-2019-11537Medium· 6.1PoC
7y ago

In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can a…

In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can a…

▾ Twilightenhancesoft · osticketEPSS 4.6%via NVD
CVE-2019-0752High· 7.5CISA KEV0dayPoC
7y ago

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-…

▾ Abyssalmicrosoft · internet_explorerEPSS 82%via NVD
CVE-2018-20250High· 7.8CISA KEVPoC
7y ago

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll)

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (ex…

▾ Abyssalrarlab · winrarEPSS 96%via NVD
CVE-2017-18362Critical· 9.8CISA KEVPoC
7y ago

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the …

▾ Hadalconnectwise · manageditsyncEPSS 87%via NVD
CVE-2018-13374Medium· 4.3CISA KEVPoC
7y ago

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connecti…

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connecti…

▾ Midnightfortinet · fortiadcEPSS 38%via NVD
CVEs tagged “exploit-available” — page 125 · VulnSea