VulnSea

Tagged “in-the-wild”

CVEs tagged in-the-wild, newest first.

357 CVEsRSS

CVE-2024-49039High· 8.8CISA KEV0dayPoC
1y ago

Windows Task Scheduler Elevation of Privilege Vulnerability

Windows Task Scheduler Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 14%via NVD
CVE-2024-51378Critical· 10.0CISA KEV0dayPoC
1y ago

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…

▾ Hadalcyberpanel · cyberpanelEPSS 95%via NVD
CVE-2024-51567Critical· 10.0CISA KEV0dayPoC
1y ago

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…

▾ Hadalcyberpanel · cyberpanelEPSS 87%via NVD
CVE-2024-50623Critical· 9.8CISA KEVPoC
1y ago

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

▾ Hadalcleo · harmonyEPSS 99%via NVD
CVE-2024-10234Medium· 6.1⚠ Exploited0day
1y ago

A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system

A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired…

▾ Midnightredhat · build_of_keycloakEPSS 0.64%via NVD
CVE-2024-41713Critical· 9.1CISA KEVPoC
1y ago

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A succes…

▾ Hadalmitel · micollabEPSS 98%via NVD
CVE-2024-9680Critical· 9.8CISA KEV0dayPoC
1y ago

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.…

▾ Hadalmozilla · firefoxEPSS 23%via NVD
CVE-2024-40766Critical· 9.8CISA KEVPoC
2y ago

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects So…

▾ Hadalsonicwall · sonicosEPSS 18%via NVD
CVE-2024-35250High· 7.8CISA KEVPoC
2y ago

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 25%via NVD
CVE-2024-30088High· 7.0CISA KEVPoC
2y ago

Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 68%via NVD
CVE-2024-23692Critical· 9.8CISA KEVPoC
2y ago

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending…

▾ Hadalrejetto · http_file_serverEPSS 99%via NVD
CVE-2024-24919High· 8.6CISA KEVPoC
2y ago

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerab…

▾ Abyssalcheckpoint · cloudguard_network_securityEPSS 100%via NVD
CVE-2023-50224Medium· 6.5CISA KEV0day
2y ago

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Au…

▾ Midnighttp-link · tl-wr841n_firmwareEPSS 16%via NVD
CVE-2024-1212Critical· 10.0CISA KEVPoC
2y ago

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

▾ Hadalprogress · loadmasterEPSS 95%via NVD
CVE-2024-21338High· 7.8CISA KEV0dayPoC
2y ago

Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1809EPSS 60%via NVD
CVE-2024-21762Critical· 9.8CISA KEV0dayPoC
2y ago

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…

▾ Hadalfortinet · fortiproxyEPSS 83%via NVD
CVE-2021-43798High· 7.5CISA KEVPoC
2y ago

Grafana path traversal

Grafana path traversal

▾ Abyssalgrafana · github.com/grafana/grafanaEPSS 89%via OSV
CVE-2024-1086High· 7.8CISA KEVPoC
2y ago

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …

▾ Abyssalnetapp · h300s_firmwareEPSS 28%via NVD
CVE-2024-21893High· 8.2CISA KEV0dayPoC
2y ago

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…

▾ Abyssalivanti · connect_secureEPSS 100%via NVD
CVE-2024-21887Critical· 9.1CISA KEV0dayPoC
2y ago

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…

▾ Hadalivanti · connect_secureEPSS 100%via NVD
CVE-2023-46805High· 8.2CISA KEV0dayPoC
2y ago

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

▾ Abyssalivanti · connect_secureEPSS 100%via NVD
CVE-2022-2586Medium· 5.3CISA KEV0dayPoC
2y ago

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

▾ Midnightlinux · linux_kernelEPSS 10%via NVD
CVE-2023-49105Critical· 9.8CISA KEVPoC
2y ago

An issue was discovered in ownCloud owncloud/core before 10.13.1

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs b…

▾ Hadalowncloud · owncloud_serverEPSS 43%via NVD
CVE-2023-47630High· 7.1⚠ Exploited0day
2y ago

Attacker can cause Kyverno user to unintentionally consume insecure image

Attacker can cause Kyverno user to unintentionally consume insecure image

▾ Abyssalkyverno · github.com/kyverno/kyvernoEPSS 0.26%via OSV
CVE-2023-47246Critical· 9.8CISA KEV0dayPoC
2y ago

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

▾ Hadalsysaid · sysaidEPSS 99%via NVD
CVE-2023-4966Critical· 9.4CISA KEVPoC
2y ago

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

▾ Hadalcitrix · netscaler_application_delivery_controllerEPSS 100%via NVD
CVE-2023-4863High· 8.8CISA KEV0dayPoC
3y ago

libwebp: OOB write in BuildHuffmanTable

libwebp: OOB write in BuildHuffmanTable

▾ Abyssallibwebp-sys2 · libwebp-sys2EPSS 100%via OSV
CVE-2023-20269Medium· 5.0CISA KEV
3y ago

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …

▾ Midnightcisco · adaptive_security_appliance_softwareEPSS 25%via NVD
CVE-2023-28434High· 8.8CISA KEVPoC
3y ago

Privilege Escalation on Linux/MacOS

Privilege Escalation on Linux/MacOS

▾ Abyssalminio · github.com/minio/minioEPSS 7.9%via OSV
CVE-2023-41266High· 8.2CISA KEVPoC
3y ago

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an un…

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an un…

▾ Abyssalqlik · qlik_senseEPSS 85%via NVD
CVEs tagged “in-the-wild” — page 6 · VulnSea