Critical Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,682 CVEs tracked 53,700 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,389 vendors 43,933 researchers
4,118 results Clear all
CVE-2021-46362 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Magnolia <6.2.3 - RCE
A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.
CWE-94 Feb 11, 2022
CVE-2021-35296 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
PTCL HG150-Ub v3.0 - Auth Bypass
An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via modification of the cookie value and Response Path.
CWE-287 Oct 04, 2021
CVE-2021-32305 9.8 CRITICAL EXPLOITED 3 PoCs Analysis NUCLEI EPSS 0.92
Websvn < 2.6.1 - OS Command Injection
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.
CWE-78 May 18, 2021
CVE-2021-44790 9.8 CRITICAL 2 PoCs Analysis EPSS 0.86
Apache HTTP Server < 2.4.52 - Out-of-Bounds Write
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
CWE-787 Dec 20, 2021
CVE-2021-30461 9.8 CRITICAL EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.93
VoIPmonitor <24.61 - RCE
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configuration.php.
CWE-94 May 29, 2021
CVE-2021-43609 9.9 CRITICAL SSVC PoC 1 PoC Analysis EPSS 0.04
Spiceworks Help Desk Server <1.3.3 - Blind Boolean SQL Injection
An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute arbitrary SQL commands via the sort parameter. This can be leveraged to leak local files from the host system, leading to remote code execution (RCE) through deserialization of malicious data.
CWE-89 Nov 09, 2023
CVE-2021-27198 9.8 CRITICAL 1 PoC Analysis EPSS 0.14
Visualware Myconnection Server < 11.1a - Unrestricted File Upload
An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a myspeed/sf?filename= URI. This application is written in Java and is thus cross-platform. The Windows installation runs as SYSTEM, which means that exploitation gives one Administrator privileges on the target system.
CWE-434 Feb 26, 2021
CVE-2021-38278 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Tenda AC10-1200 <15.03.06.23 - Buffer Overflow
Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentControlInfo function.
CWE-787 Mar 23, 2022
CVE-2021-37388 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Dlink Dir-615 Firmware - Buffer Overflow
A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution.
CWE-120 Aug 06, 2021
CVE-2021-37580 9.8 CRITICAL EXPLOITED 7 PoCs Analysis NUCLEI EPSS 0.94
Apache Shenyu < 2.4.1 - Authentication Bypass
A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0
CWE-287 Nov 16, 2021
CVE-2021-44906 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Substack Minimist < 1.2.6 - Prototype Pollution
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
CWE-1321 Mar 17, 2022
CVE-2021-34621 9.8 CRITICAL EXPLOITED SSVC PoC 4 PoCs Analysis NUCLEI EPSS 0.93
Properfraction Profilepress < 3.1.3 - Missing Authentication
A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. .
CWE-269 Jul 07, 2021
CVE-2021-20021 9.8 CRITICAL KEV SSVC ACTIVE RANSOMWARE 1 PoC Analysis NUCLEI EPSS 0.92
Sonicwall Email Security < 10.0.9.6103 - Improper Privilege Management
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CWE-269 Apr 09, 2021
CVE-2021-29003 9.8 CRITICAL EXPLOITED 2 PoCs Analysis EPSS 0.36
Genexis Platinum 4410 Firmware - OS Command Injection
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as demonstrated by the sys_config_valid.xgi?exeshell=%60telnetd%20%26%60 URI.
CWE-78 Apr 13, 2021
CVE-2021-25032 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.82
PublishPress Capabilities <2.3.1 - CSRF
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.
CWE-862 Jan 10, 2022
CVE-2021-45232 9.8 CRITICAL 9 PoCs Analysis NUCLEI EPSS 0.94
Apache Apisix Dashboard < 2.10.1 - Missing Authentication
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.
CWE-306 Dec 27, 2021
CVE-2021-46704 9.8 CRITICAL 2 PoCs Analysis NUCLEI EPSS 0.87
GenieACS <1.2.8 - Command Injection
In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input validation combined with a missing authorization check.
CWE-78 Mar 06, 2022
CVE-2021-3064 9.8 CRITICAL 1 PoC Analysis EPSS 0.53
Palo Alto Networks <8.1.17 - Memory Corruption
A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges. The attacker must have network access to the GlobalProtect interface to exploit this issue. This issue impacts PAN-OS 8.1 versions earlier than PAN-OS 8.1.17. Prisma Access customers are not impacted by this issue.
CWE-121 Nov 10, 2021
CVE-2021-46422 9.8 CRITICAL EXPLOITED 16 PoCs Analysis NUCLEI EPSS 0.94
Telesquare SDT-CW3B1 1.1.0 - Command Injection
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.
CWE-78 Apr 27, 2022
CVE-2021-43617 9.8 CRITICAL 4 PoCs Analysis EPSS 0.56
Laravel Framework <8.70.2 - Code Injection
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.
CWE-434 Nov 14, 2021