VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3598 CVEsRSS

CVE-2025-56218Critical· 9.8PoC
11mo ago

An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

▾ Abyssalascertia · signinghubEPSS 0.63%via NVD
CVE-2025-9967Critical· 9.8PoC
11mo ago

The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7

The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7. This is due to the plugin not properly validating a user's identity prior to upda…

▾ AbyssalEPSS 0.43%via NVD
CVE-2025-39964High· 7.8CISA KEVPoC
11mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…

▾ Abyssallinux · linux_kernelEPSS 1.00%via NVD
CVE-2025-61884High· 7.5CISA KEVPoC
11mo ago

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI)

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network …

▾ Abyssaloracle · configuratorEPSS 96%via NVD
CVE-2025-11579Medium· 5.3PoC
11mo ago

github.com/nwaples/rardecode: RarDecode Out Of Memory Crash (CVE-2025-11579)

A memory exhaustion flaw has been discovered in the golang Rar Decode library (github.com/nwaples/rardecode). Affected versions did not limit the size of an archive and so an attacker could provide a crafted archive to a tool or service bu…

▾ TwilightRed Hat · Red Hat Advanced Cluster Security 4EPSS 0.37%via CSAF
CVE-2025-11371High· 7.5CISA KEVPoC
11mo ago

Gladinet CentreStack and TrioFox Local File Inclusion Flaw

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been obser…

▾ AbyssalGladinet · CentreStack and TrioFoxEPSS 92%via CVEORG
CVE-2025-61765Medium· 6.4PoC
11mo ago

python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server depl…

python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server deployments

▾ Twilightpython-socketio · python-socketioEPSS 0.48%via OSV
CVE-2025-61984Low· 3.6PoC
11mo ago

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %…

▾ TwilightOpenBSD · OpenSSHEPSS 0.29%via CVEORG
CVE-2025-61882Critical· 9.8CISA KEV0dayPoC
11mo ago

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration)

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated…

▾ Hadaloracle · concurrent_processingEPSS 100%via NVD
CVE-2025-10952Medium· 5.3PoC
1y ago

ml-logger file handler allows reading arbitrary files

ml-logger file handler allows reading arbitrary files

▾ Twilightml-logger · ml-loggerEPSS 0.45%via OSV
CVE-2025-10951High· 7.3PoC
1y ago

ml-logger has path traversal in the file argument

ml-logger has path traversal in the file argument

▾ Midnightml-logger · ml-loggerEPSS 0.61%via OSV
CVE-2025-48868High· 7.2PoC
1y ago

Horilla is a free and open source Human Resource Management System (HRMS)

Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to the unsafe use of Python’s eval() function on a user-controlled query pa…

▾ Midnighthorilla · horillaEPSS 2.5%via NVD
CVE-2025-23339Low· 3.3PoC
1y ago

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerabilit…

▾ Twilightnvidia · cuda_toolkitEPSS 0.36%via NVD
CVE-2025-20352High· 7.7CISA KEVPoC
1y ago

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of serv…

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of serv…

▾ Abyssalcisco · ios_xe_sd-wanEPSS 39%via NVD
CVE-2025-10585Critical· 9.8CISA KEV0dayPoC
1y ago

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

▾ Hadalgoogle · chromeEPSS 5.4%via NVD
CVE-2025-55887Medium· 6.1PoC
1y ago

Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD

Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD. The vulnerability exists in the transactionID GET parameter on the transaction confirmation page. Due to improper input validation and output en…

▾ Twilightard · gec_en_ligneEPSS 0.35%via NVD
CVE-2025-55888High· 7.3PoC
1y ago

Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD

Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can intercept the Ajax response and inject malicious JavaScript into the accountName field. This input is not properly s…

▾ Midnightard · gec_en_ligneEPSS 0.44%via NVD
CVE-2025-55885Medium· 6.3PoC
1y ago

SQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote attacker to escalate privileges via the GET parameters in index.php

SQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote attacker to escalate privileges via the GET parameters in index.php

▾ Twilightard · gec_en_ligneEPSS 0.36%via NVD
CVE-2025-39866High· 7.8PoC
1y ago

fs: writeback: fix use-after-free in __mark_inode_dirty()

In the Linux kernel, the following vulnerability has been resolved: fs: writeback: fix use-after-free in __mark_inode_dirty() An use-after-free issue occurred when __mark_inode_dirty() get the bdi_writeback that was in the progress of …

▾ MidnightLinux · LinuxEPSS 0.31%via CVEORG
CVE-2025-10035Critical· 10.0CISA KEVPoC
1y ago

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

▾ Hadalfortra · goanywhere_managed_file_transferEPSS 100%via NVD
CVE-2025-9216High· 8.8PoC
1y ago

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import() function in all ve…

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import() function in all ve…

▾ MidnightEPSS 0.88%via NVD
CVE-2025-59341HighPoC
1y ago

esm.sh has File Inclusion issue

esm.sh has File Inclusion issue

▾ Midnightesm-dev · github.com/esm-dev/esm.shEPSS 1.6%via OSV
CVE-2025-9242Critical· 9.8CISA KEVPoC
1y ago

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office V…

▾ Hadalwatchguard · firewareEPSS 91%via NVD
CVE-2025-59376Medium· 5.3PoC
1y ago

mcp-kubernetes-server has a Command Injection vulnerability

mcp-kubernetes-server has a Command Injection vulnerability

▾ Twilightmcp-kubernetes-server · mcp-kubernetes-serverEPSS 0.30%via OSV
CVE-2025-57174Critical· 9.8PoC
1y ago

An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions

An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions. The rfpiped service listening on TCP port 555 which uses static AES encryption keys …

▾ AbyssalEPSS 2.2%via NVD
CVE-2025-10211Medium· 6.3PoC
1y ago

A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0

A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/collect/getArticle. The manipulation of the argument taskUrl leads to server-side request f…

▾ Twilightchancms · chancmsEPSS 0.70%via NVD
CVE-2025-10210Medium· 6.3PoC
1y ago

A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0

A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argument key can lead to sql injection. The attack can be launc…

▾ Twilightchancms · chancmsEPSS 1.3%via NVD
CVE-2025-10200High· 8.8PoC
1y ago

Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page

Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.57%via NVD
CVE-2025-8889Low· 3.8PoC
1y ago

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in mu…

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in mu…

▾ Twilighteliehanna · compress_&_uploadEPSS 0.29%via NVD
CVE-2025-58180High· 8.8PoC
1y ago

OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload

OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload

▾ Midnightoctoprint · octoprintEPSS 21%via OSV
CVEs tagged “exploit-available” — page 98 · VulnSea