VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3595 CVEsRSS

CVE-2025-12758High· 7.5PoC
10mo ago

Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E)…

Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E)…

▾ Midnightvalidator_project · validatorEPSS 0.52%via NVD
CVE-2025-62593CriticalCISA KEVPoC
10mo ago

Ray is an AI compute engine

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient gu…

▾ Hadalray · rayEPSS 62%via NVD
CVE-2025-50433Critical· 9.8PoC
10mo ago

An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.

An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.

▾ Abyssalmonnit · imonnitEPSS 0.43%via NVD
CVE-2025-48593High· 8.0PoC
10mo ago

In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free

In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed…

▾ Midnightgoogle · androidEPSS 0.89%via NVD
CVE-2025-56499Medium· 6.5PoC
10mo ago

Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file.

Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file.

▾ Twilightmetacubex · mihomoEPSS 0.31%via NVD
CVE-2025-63892Medium· 6.8PoC
10mo ago

A vulnerability was determined in SourceCodester Student Grades Management System 1.0

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_classroom of the file /classroom.php of the component My Classrooms Management Page. This manipulation of the argument…

▾ Twilightremyandrade · student_grades_management_systemEPSS 0.36%via NVD
CVE-2025-13223High· 8.8CISA KEVPoC
10mo ago

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 5.0%via NVD
CVE-2025-60689Medium· 5.4PoC
10mo ago

An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz)

An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl…

▾ Twilightlinksys · e1200_firmwareEPSS 18%via NVD
CVE-2025-40123High· 7.8PoC
10mo ago

bpf: Enforce expected_attach_type for tailcall compatibility

In the Linux kernel, the following vulnerability has been resolved: bpf: Enforce expected_attach_type for tailcall compatibility Yinhao et al. recently reported: Our fuzzer tool discovered an uninitialized pointer issue in the bpf…

▾ MidnightLinux · LinuxEPSS 0.15%via CVEORG
CVE-2025-9223High· 8.8PoC
10mo ago

Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.

Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.

▾ MidnightEPSS 4.2%via NVD
CVE-2025-12748Medium· 5.5PoC
10mo ago

A flaw was discovered in libvirt in the XML file processing

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a…

▾ TwilightEPSS 0.21%via NVD
CVE-2025-64432Medium· 4.7PoC
10mo ago

KubeVirt is a virtual machine management add-on for Kubernetes

KubeVirt is a virtual machine management add-on for Kubernetes. Versions 1.5.3 and below, and 1.6.0 contained a flawed implementation of the Kubernetes aggregation layer's authentication flow which could enable bypass of RBAC controls. I…

▾ Twilightkubevirt · kubevirtEPSS 0.14%via NVD
CVE-2025-64512High· 8.6PoC
10mo ago

Arbitrary Code Execution in pdfminer.six via Crafted PDF Input

Arbitrary Code Execution in pdfminer.six via Crafted PDF Input

▾ Midnightpdfminer-six · pdfminer-sixEPSS 0.31%via OSV
CVE-2025-64495High· 8.7PoC
10mo ago

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

▾ Midnightopen-webui · open-webuiEPSS 0.46%via OSV
CVE-2025-70559High· 7.8PoC
10mo ago

Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc

Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc

▾ Midnightpdfminer-six · pdfminer-sixEPSS 0.30%via OSV
CVE-2025-10230Critical· 10.0PoC
10mo ago

A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping

A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserte…

▾ AbyssalEPSS 40%via NVD
CVE-2023-43000High· 8.8CISA KEVPoC
10mo ago

A use-after-free issue was addressed with improved memory management

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to …

▾ Abyssalapple · safariEPSS 3.9%via NVD
CVE-2025-64458High· 7.5PoC
10mo ago

Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

▾ Midnightdjango · djangoEPSS 1.9%via OSV
CVE-2025-43426Medium· 5.5PoC
10mo ago

A logging issue was addressed with improved data redaction

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to access sensitive user data.

▾ Twilightapple · ipadosEPSS 0.26%via NVD
CVE-2025-60787High· 7.2PoC
10mo ago

motionEye vulnerable to RCE via unsanitized motion config parameter

motionEye vulnerable to RCE via unsanitized motion config parameter

▾ Midnightmotioneye · motioneyeEPSS 18%via OSV
CVE-2025-11201High· 8.10dayPoC
11mo ago

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability

▾ Abyssalmlflow · mlflowEPSS 27%via OSV
CVE-2025-62727High· 7.5PoC
11mo ago

Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``

Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``

▾ Midnightstarlette · starletteEPSS 0.64%via OSV
CVE-2025-11844Medium· 5.4PoC
11mo ago

Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function

Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function

▾ Twilightsmolagents · smolagentsEPSS 0.28%via OSV
CVE-2025-56224High· 8.1PoC
11mo ago

A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.

A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.

▾ Midnightascertia · signinghubEPSS 0.39%via NVD
CVE-2025-56223High· 7.5PoC
11mo ago

A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive number of files.

A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive number of files.

▾ Midnightascertia · signinghubEPSS 0.46%via NVD
CVE-2025-56219High· 7.1PoC
11mo ago

Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting

Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resource exhaustion and a Denial of Service (DoS) when an excessively large number of user acco…

▾ Midnightascertia · signinghubEPSS 0.32%via NVD
CVE-2025-34282Critical· 9.1PoC
11mo ago

ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature

ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload a malicious SVG file that references a remote URL. If the server processes th…

▾ Abyssalthingsboard · thingsboardEPSS 1.8%via NVD
CVE-2025-56218Critical· 9.8PoC
11mo ago

An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

▾ Abyssalascertia · signinghubEPSS 0.63%via NVD
CVE-2025-9967Critical· 9.8PoC
11mo ago

The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7

The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7. This is due to the plugin not properly validating a user's identity prior to upda…

▾ AbyssalEPSS 0.43%via NVD
CVE-2025-39964High· 7.8CISA KEVPoC
11mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…

▾ Abyssallinux · linux_kernelEPSS 1.00%via NVD
CVEs tagged “exploit-available” — page 97 · VulnSea