Critical Vulnerabilities with Public Exploits

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,682 CVEs tracked 53,700 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,389 vendors 43,933 researchers
4,118 results Clear all
CVE-2021-36394 9.8 CRITICAL 2 PoCs Analysis EPSS 0.12
Moodle - RCE
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
CWE-94 Mar 06, 2023
CVE-2021-0516 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Android - Use After Free
In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-181660448
CWE-125 Jun 21, 2021
CVE-2021-24507 9.8 CRITICAL 1 PoC Analysis EPSS 0.44
Brainstormforce Astra < 3.5.2 - SQL Injection
The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues
CWE-89 Aug 09, 2021
CVE-2021-32157 9.6 CRITICAL 2 PoCs Analysis EPSS 0.25
Webmin - XSS
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
CWE-79 Apr 11, 2022
CVE-2021-0474 9.8 CRITICAL 2 PoCs Analysis EPSS 0.04
Android -11,8.1,9,10 - Buffer Overflow
In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-177611958
CWE-787 Jun 11, 2021
CVE-2021-42136 9.0 CRITICAL 1 PoC Analysis EPSS 0.02
Vanderbilt Redcap < 11.4.0 - XSS
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a Cross-Site Request Forgery attack to escalate privileges to administrator.
CWE-79 Apr 13, 2022
CVE-2021-4039 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.61
Zyxel NWA-1100-NH - Command Injection
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.
CWE-78 Mar 01, 2022
CVE-2021-0316 9.8 CRITICAL 1 PoC Analysis EPSS 0.05
Android -11, Android-8.0, Android-8.1, Android-9, Android-10 - RCE
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11, Android-8.0, Android-8.1, Android-9, Android-10; Android ID: A-168802990.
CWE-787 Jan 11, 2021
CVE-2021-46419 9.1 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.88
Telesquare TLR-2855KS6 - Info Disclosure
An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.
Apr 07, 2022
CVE-2021-0397 9.8 CRITICAL 1 PoC Analysis EPSS 0.14
Android -11, 8.1, 9, 10 - RCE
In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-174052148
CWE-415 Mar 10, 2021
CVE-2021-26599 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.04
Impresscms < 1.4.4 - SQL Injection
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
CWE-89 Mar 28, 2022
CVE-2021-43936 10.0 CRITICAL EXPLOITED 2 PoCs Analysis EPSS 0.28
WebHMI - Code Injection
The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.
CWE-434 Dec 06, 2021
CVE-2021-40373 9.8 CRITICAL 1 PoC Analysis EPSS 0.25
playSMS <1.4.5 - RCE
playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via the index.php?app=main&inc=core_welcome URI.
CWE-94 Sep 10, 2021
CVE-2021-44088 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Attendance And Payroll System - SQL Injection
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.
CWE-89 Mar 17, 2022
CVE-2021-44087 9.8 CRITICAL 1 PoC Analysis EPSS 0.21
Attendance And Payroll System - Remote Code Execution
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.
Mar 17, 2022
CVE-2021-45092 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.79
Thinfinity VirtualUI <3.0 - Code Injection
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.
Dec 16, 2021
CVE-2021-26102 9.8 CRITICAL 1 PoC Analysis EPSS 0.61
Fortinet Fortiwan < 4.5.8 - Path Traversal
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In particular, deleting specific configuration files will reset the Admin password to its default value.
CWE-22 Dec 19, 2024
CVE-2021-46428 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Sourcecodester Simple Chatbot App <1.0 - RCE
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php.
CWE-434 Jan 27, 2022
CVE-2021-46427 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Sourcecodester Simple Chatbot App 1.0 - SQL Injection
An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.
CWE-89 Jan 27, 2022
CVE-2021-46067 9.8 CRITICAL 1 PoC Analysis EPSS 0.14
In Vehicle Service Management System 1.0 - Info Disclosure
In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.
Jan 06, 2022