VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3593 CVEsRSS

CVE-2025-14174High· 8.8CISA KEV0dayPoC
9mo ago

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

▾ AbyssalGoogle · ChromeEPSS 22%via CVEORG
CVE-2025-67780Medium· 4.2PoC
9mo ago

SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via unauthenticated LAN gRPC requests, aka MARMALADE 2

SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via unauthenticated LAN gRPC requests, aka MARMALADE 2. The cross-origin policy can be bypassed by omitting a Referer heade…

▾ TwilightEPSS 0.17%via NVD
CVE-2025-66628High· 7.5PoC
9mo ago

ImageMagick is a software suite to create, edit, compose, or convert bitmap images

ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim…

▾ Midnightimagemagick · imagemagickEPSS 0.51%via NVD
CVE-2025-66472Medium· 6.1PoC
9mo ago

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1 of both XWiki Platform Flamingo Skin Resources and XWiki Pl…

▾ Twilightxwiki · xwikiEPSS 0.51%via NVD
CVE-2025-65950High· 8.8PoC
9mo ago

WBCE CMS is a content management system

WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged authenticated user with permissions to modify users to execute arbitrary SQL queries. This can be escalated to a ful…

▾ Midnightwbce · wbce_cmsEPSS 0.54%via NVD
CVE-2025-13339High· 7.5PoC
9mo ago

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the…

▾ MidnightEPSS 2.2%via NVD
CVE-2025-67644High· 7.3PoC
9mo ago

LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method

LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method

▾ Midnightlanggraph-checkpoint-sqlite · langgraph-checkpoint-sqliteEPSS 2.3%via OSV
CVE-2025-66039Critical· 9.8PoC
9mo ago

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an…

▾ Abyssalsangoma · freepbxEPSS 3.3%via NVD
CVE-2025-62221High· 7.8CISA KEV0dayPoC
9mo ago

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

▾ Abyssalmicrosoft · windows_10_1809EPSS 2.5%via NVD
CVE-2025-66470Medium· 6.1PoC
9mo ago

NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content

NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content

▾ Twilightnicegui · niceguiEPSS 0.25%via OSV
CVE-2025-58098High· 8.3PoC
9mo ago

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. User…

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. User…

▾ Midnightapache · http_serverEPSS 1.4%via NVD
CVE-2025-12163Medium· 6.4PoC
9mo ago

The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping

The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authe…

▾ TwilightEPSS 0.36%via NVD
CVE-2025-34291High· 8.8CISA KEVPoC
9mo ago

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a …

▾ Abyssallangflow · langflowEPSS 93%via NVD
CVE-2025-65637HighPoC
9mo ago

Logrus is vulnerable to DoS when using Entry.Writer()

Logrus is vulnerable to DoS when using Entry.Writer()

▾ Midnightsirupsen · github.com/sirupsen/logrusEPSS 0.63%via OSV
CVE-2025-1910NonePoC
9mo ago

The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM on the Windows machine where the VPN Client is installed.

The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM on the Windows machine where the VPN Client is installed.

▾ TwilightEPSS 0.26%via NVD
CVE-2025-65945High· 7.5PoC
9mo ago

auth0/node-jws is a JSON Web Signature implementation for Node.js

auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditi…

▾ Midnightauth0 · node-jwsEPSS 0.21%via NVD
CVE-2025-65027High· 7.6PoC
9mo ago

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. RomM contains multiple unrestricted file upload vulnerabilities that allow authenticated users to upload malic…

▾ Midnightromm.app · rommEPSS 0.33%via NVD
CVE-2025-20384Medium· 5.3PoC
9mo ago

In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject American National Standards Institute (…

In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject American National Standards Institute (…

▾ Twilightsplunk · splunkEPSS 0.39%via NVD
CVE-2025-55182Critical· 10.0CISA KEVPoC
9mo ago

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-serve…

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-serve…

▾ Hadalfacebook · reactEPSS 100%via NVD
CVE-2025-57199High· 8.8PoC
9mo ago

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetFailDetectD binary

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetFailDetectD binary. This vulnerability allows attackers to execute arbitrary commands vi…

▾ Midnightavtech · dgm1104_firmwareEPSS 3.3%via NVD
CVE-2025-13947High· 7.4PoC
9mo ago

A flaw was found in WebKitGTK

A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify tha…

▾ MidnightEPSS 0.33%via NVD
CVE-2025-65858LowPoC
10mo ago

Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation

Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation

▾ Twilightcalibreweb · calibrewebEPSS 0.21%via OSV
CVE-2025-66301Critical· 9.6PoC
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the …

▾ Abyssalgetgrav · gravEPSS 1.3%via NVD
CVE-2025-66294High· 8.8PoC
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, …

▾ Midnightgetgrav · gravEPSS 2.8%via NVD
CVE-2025-55749High· 7.5PoC
10mo ago

XWiki is an open-source wiki software platform

XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJetty), a context is exposed to statically access any file located in the webapp/ folder.…

▾ Midnightxwiki · xwikiEPSS 1.5%via NVD
CVE-2025-3500Critical· 9.0PoC
10mo ago

Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.

Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.

▾ Abyssalavast · antivirusEPSS 0.46%via NVD
CVE-2025-13796Medium· 6.3PoC
10mo ago

A security vulnerability has been detected in deco-cx apps up to 0.120.1

A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this vulnerability is the function AnalyticsScript of the file website/loaders/analyticsScript.ts of the component Parameter Handler. Such manipulation…

▾ TwilightEPSS 0.32%via NVD
CVE-2025-66034Medium· 6.3PoC
10mo ago

fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

▾ Twilightfonttools · fonttoolsEPSS 0.55%via OSV
CVE-2025-12758High· 7.5PoC
10mo ago

Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E)…

Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E)…

▾ Midnightvalidator_project · validatorEPSS 0.52%via NVD
CVE-2025-62593CriticalCISA KEVPoC
10mo ago

Ray is an AI compute engine

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient gu…

▾ Hadalray · rayEPSS 62%via NVD
CVEs tagged “exploit-available” — page 96 · VulnSea