Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 25 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

vxcontrol PentAGI Tool Management Protocol pentester.tmpl sandbox

A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management Protocol Handler. Executing a manipulation can lead to sandbox issue. It is possible to launch the attack remotely. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been made available to the public and could be used for attacks. The vendor was co

CWE-264CWE-265Aug 3, 2026
CVSS6.3v4.0EPSS0.266%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Huawei EMUI and Harmony OS Bluetooth Module Permission Control Vulnerability

Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect availability.

CWE-264Jul 15, 2026
CVSS5.1v3.1EPSS0.08%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Huawei HarmonyOS Card Module Permission Bypass Vulnerability

Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability.

CWE-264Jul 15, 2026
CVSS6.6v3.1EPSS0.08%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

vxcontrol PentAGI Docker API client.go sandbox

A vulnerability was identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown function of the file backend/pkg/docker/client.go of the component Docker API. The manipulation leads to sandbox issue. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.

CWE-264CWE-265Jul 6, 2026
CVSS5.3v4.0EPSS0.228%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Huawei EMUI and HarmonyOS Service Notifications Permission Control Vulnerability

Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.

CWE-264Jun 9, 2026
CVSS3.6v3.1EPSS0.074%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

NousResearch hermes-agent Environment Variable code_execution_tool.py execute_code sandbox

A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Handler. Such manipulation leads to sandbox issue. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS6.9v4.0EPSS0.38%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:HarmonyOS App Management Module Permission Control Vulnerability

Permission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CWE-264May 15, 2026
CVSS3.6v3.1EPSS0.077%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ByteDance verl grader.py math_equal sandbox

A vulnerability was identified in ByteDance verl up to 0.7.0. Affected is the function math_equal of the file prime_math/grader.py. The manipulation leads to sandbox issue. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS6.3v4.0EPSS0.333%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

nocobase plugin-workflow-javascript Vm.js createSafeConsole sandbox

A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function createSafeConsole of the file packages/plugins/@nocobase/plugin-workflow-javascript/src/server/Vm.js. Performing a manipulation results in sandbox issue. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CWE-264CWE-265Apr 13, 2026
CVSS6.9v4.0EPSS0.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

AstrBotDevs AstrBot install-upload Endpoint plugin.py install_plugin_upload sandbox

A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1. This issue affects the function install_plugin_upload of the file astrbot/dashboard/routes/plugin.py of the component install-upload Endpoint. The manipulation of the argument File results in sandbox issue. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

CWE-264CWE-265Apr 12, 2026
CVSS5.3v4.0EPSS0.224%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS XR Software CLI Privilege Escalation Vulnerability

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device. This vulnerability is due to incorrect mapping of a command to task groups within the source code. An attacker with a low-privileged account could exploit this vulnerability by using the CLI command to bypass the task group–based checks. A successful exploit could allow

CWE-264Mar 11, 2026
CVSS8.8v3.1EPSS0.135%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Huawei HarmonyOS Cellular Data Module Permission Control Vulnerability

Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may affect availability.

CWE-264Mar 5, 2026
CVSS4.0v3.1EPSS0.087%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Huawei HarmonyOS Resource Scheduling Module Permission Control Vulnerability

Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerability may affect service integrity.

CWE-264Mar 5, 2026
CVSS3.3v3.1EPSS0.109%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:HarmonyOS Print Module Improper Permission Control Vulnerability

Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CWE-264Feb 6, 2026
CVSS6.1v3.1EPSS0.108%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Huawei EMUI and HarmonyOS AMS Module Permission Control Vulnerability

Permission control vulnerability in the AMS module. Impact: Successful exploitation of this vulnerability may affect availability.

CWE-264Feb 6, 2026
CVSS6.2v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Huawei HarmonyOS Card Module Improper Criterion Security Check Vulnerability

Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CWE-264Feb 6, 2026
CVSS5.9v3.1EPSS0.102%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:HarmonyOS HDC Module Permission Control Vulnerability

Permission control vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CWE-264Feb 6, 2026
CVSS6.3v3.1EPSS0.111%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CWE-264Jan 14, 2026
CVSS5.7v3.1EPSS0.105%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Permission control vulnerability in the window management module. Impact: Successful exploitation of this vulnerability may affect availability.

CWE-264Dec 8, 2025
CVSS4.0v3.1EPSS0.085%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Permission control vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CWE-264Dec 8, 2025
CVSS6.2v3.1EPSS0.09%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CWE-264Nov 28, 2025
CVSS8.4v3.1EPSS0.094%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CWE-264Nov 28, 2025
CVSS6.2v3.1EPSS0.09%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CWE-264Nov 28, 2025
CVSS5.5v3.1EPSS0.09%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.

CWE-264Nov 28, 2025
CVSS5.1v3.1EPSS0.077%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

CWE-264Nov 28, 2025
CVSS6.8v3.1EPSS0.088%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX