VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3598 CVEsRSS

CVE-2025-57833High· 7.1PoC
1y ago

Django is subject to SQL injection through its column aliases

Django is subject to SQL injection through its column aliases

▾ Midnightdjango · djangoEPSS 17%via OSV
CVE-2025-10072Medium· 6.3PoC
1y ago

A vulnerability was found in Portabilis i-Educar up to 2.10

A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/. Performing a manipulation results in improper access controls. It is possible to initi…

▾ Twilightportabilis · i-educarEPSS 0.33%via NVD
CVE-2025-9961NonePoC
1y ago

An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500.  The exploit can only be conducted via a Man-In-The-Middle (MITM) attack.  This issue affects AX10 V1/V1.2/V2/V2.6/V3/V3.…

An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500.  The exploit can only be conducted via a Man-In-The-Middle (MITM) attack.  This issue affects AX10 V1/V1.2/V2/V2.6/V3/V3.…

▾ TwilightEPSS 10.0%via NVD
CVE-2025-39682Critical· 9.8CISA KEVPoC⚖ disputed
1y ago

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…

▾ Hadallinux · linux_kernelEPSS 2.9%via NVD
CVE-2025-10012Medium· 6.3PoC
1y ago

A security vulnerability has been detected in Portabilis i-Educar up to 2.10

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file educar_historico_escolar_lst.php. Such manipulation of the argument ref_cod_aluno leads to sql injectio…

▾ Twilightportabilis · i-educarEPSS 0.38%via NVD
CVE-2025-55190High· 8.8PoC
1y ago

github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials (CVE-2025-55190)

An information leak was discovered in how Argo CD handles API tokens. The project details API endpoint could provide unintentional access to sensitive repository credentials.

▾ MidnightRed Hat · Red Hat OpenShift GitOps 1.17EPSS 5.5%via CSAF
CVE-2025-57808High· 8.1PoC
1y ago

ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

▾ Midnightesphome · esphomeEPSS 1.6%via OSV
CVE-2025-9784High· 7.5PoC
1y ago

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive serv…

▾ Midnightredhat · build_of_apache_camel_for_spring_bootEPSS 2.3%via NVD
CVE-2005-10004High· 8.8PoC
1y ago

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled durin…

▾ Midnightcacti · cactiEPSS 2.0%via NVD
CVE-2025-9606Medium· 6.3PoC
1y ago

A vulnerability was detected in Portabilis i-Educar up to 2.10

A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/agenda_preferencias.php. Performing a manipulation of the argument cod_agenda results in sql…

▾ Twilightportabilis · i-educarEPSS 0.34%via NVD
CVE-2025-57819Critical· 9.8CISA KEV0dayPoC
1y ago

FreePBX is an open-source web-based graphical user interface

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrar…

▾ Hadalsangoma · freepbxEPSS 85%via NVD
CVE-2025-51643Low· 2.4PoC
1y ago

Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection

Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection. An attacker with physical access to the device can use a standard SPI programmer to extra…

▾ Twilightmeitrack · t366l-g_firmwareEPSS 0.26%via NVD
CVE-2025-8067High· 8.5PoC
1y ago

A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system

A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system. This is achieved via the loop device handler, which handles requests sent through the D-BUS interface. As two of the…

▾ MidnightEPSS 0.65%via NVD
CVE-2024-13985NonePoC
1y ago

A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface

A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation…

▾ TwilightEPSS 15%via NVD
CVE-2025-9531Medium· 6.3PoC
1y ago

A vulnerability was detected in Portabilis i-Educar up to 2.10

A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/agenda.php of the component Agenda Module. Performing a manipulation of the argument cod_agenda results in sql injecti…

▾ Twilightportabilis · i-educarEPSS 0.40%via NVD
CVE-2025-34161High· 8.8PoC
1y ago

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell …

▾ Midnightcoollabs · coolifyEPSS 3.0%via NVD
CVE-2025-34159High· 8.8PoC
1y ago

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Do…

▾ Midnightcoollabs · coolifyEPSS 0.96%via NVD
CVE-2025-34157Critical· 9.0PoC
1y ago

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name con…

▾ Abyssalcoollabs · coolifyEPSS 0.46%via NVD
CVE-2025-9236Medium· 6.3PoC
1y ago

A vulnerability has been found in Portabilis i-Educar up to 2.10

A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usuàrio Page. Such manipulation of the argument nm_tipo/descri…

▾ Twilightportabilis · i-educarEPSS 0.39%via NVD
CVE-2010-20103Critical· 9.8PoC
1y ago

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute a…

▾ Abyssalproftpd · proftpdEPSS 5.1%via NVD
CVE-2025-51529Medium· 5.3PoC
1y ago

Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial of service (database server resource exhaustion) via unl…

Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial of service (database server resource exhaustion) via unl…

▾ Twilightfollowmedarling · cookies_and_content_security_policyEPSS 0.44%via NVD
CVE-2025-8875High· 7.8CISA KEV0dayPoC
1y ago

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

▾ Abyssaln-able · n-centralEPSS 1.9%via NVD
CVE-2025-25256Critical· 9.8PoC
1y ago

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, F…

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, F…

▾ Abyssalfortinet · fortisiemEPSS 65%via NVD
CVE-2025-8088High· 8.8CISA KEVPoC
1y ago

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepano…

▾ Abyssalrarlab · winrarEPSS 94%via NVD
CVE-2025-8539Low· 2.4PoC
1y ago

A weakness has been identified in Portabilis i-Educar 2.10

A weakness has been identified in Portabilis i-Educar 2.10. This affects an unknown function of the file /intranet/public_distrito_cad.php. This manipulation of the argument nome causes cross site scripting. The attack is possible to be …

▾ Twilightportabilis · i-educarEPSS 0.29%via NVD
CVE-2025-8538Low· 2.4PoC
1y ago

A security flaw has been discovered in Portabilis i-Educar 2.10

A security flaw has been discovered in Portabilis i-Educar 2.10. The impacted element is an unknown function of the file /usuarios/tipos/novo. The manipulation of the argument name/description results in cross site scripting. The attack …

▾ Twilightportabilis · i-educarEPSS 0.29%via NVD
CVE-2025-20701High· 8.8PoC
1y ago

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not nee…

▾ MidnightAiroha Technology Corp. · AB156x, AB157x, AB158x, AB159x seriesEPSS 8.7%via NVD
CVE-2025-50460Critical· 9.8PoC
1y ago

MS SWIFT Remote Code Execution via unsafe PyYAML deserialization

MS SWIFT Remote Code Execution via unsafe PyYAML deserialization

▾ Abyssalms-swift · ms-swiftEPSS 2.5%via OSV
CVE-2025-54589Medium· 6.3PoC
1y ago

copyparty Reflected XSS via Filter Parameter

copyparty Reflected XSS via Filter Parameter

▾ Twilightcopyparty · copypartyEPSS 2.4%via OSV
CVE-2025-31277High· 8.8CISA KEVPoC
1y ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory…

▾ Abyssalapple · safariEPSS 1.6%via NVD
CVEs tagged “exploit-available” — page 99 · VulnSea