Critical Vulnerabilities with Public Exploits
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,118 results
Clear all
CVE-2021-40531
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.07
Sketch <75 - RCE
Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to Terminal.app.
CWE-434
Sep 06, 2021
CVE-2021-4455
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Smart Product Review <1.0.4 - RCE
The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
CWE-434
Apr 19, 2025
CVE-2021-42580
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Oretnom23 Online Learning System - SQL Injection
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution.
CWE-89
Nov 15, 2021
CVE-2021-43616
9.0
CRITICAL
1 PoC
Analysis
EPSS 0.02
npm 7.x-8.1.3 - Info Disclosure
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI.
CWE-345
Nov 13, 2021
CVE-2021-43329
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.09
Mumara Classic <2.93 - SQL Injection
A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attacker to execute arbitrary SQL commands via the license parameter.
CWE-89
Aug 25, 2022
CVE-2021-43136
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.13
FormaLMS <= 2.4.4 - Auth Bypass
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.
CWE-798
Nov 10, 2021
CVE-2021-37678
9.3
CRITICAL
1 PoC
Analysis
EPSS 0.01
Google Tensorflow < 2.3.4 - Insecure Deserialization
TensorFlow is an end-to-end open source platform for machine learning. In affected versions TensorFlow and Keras can be tricked to perform arbitrary code execution when deserializing a Keras model from YAML format. The [implementation](https://github.com/tensorflow/tensorflow/blob/460e000de3a83278fb00b61a16d161b1964f15f4/tensorflow/python/keras/saving/model_config.py#L66-L104) uses `yaml.unsafe_load` which can perform arbitrary code execution on the input. Given that YAML format support requires a significant amount of work, we have removed it for now. We have patched the issue in GitHub commit 23d6383eb6c14084a8fc3bdf164043b974818012. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.
CWE-502
Aug 12, 2021
CVE-2021-47774
9.8
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Kingdia CD Extractor 3.0.2 - RCE
Kingdia CD Extractor 3.0.2 contains a buffer overflow vulnerability in the registration name field that allows attackers to execute arbitrary code. Attackers can craft a malicious payload exceeding 256 bytes to overwrite Structured Exception Handler and gain remote code execution through a bind shell.
CWE-787
Jan 15, 2026
CVE-2021-47772
9.8
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.00
10-strike Network Inventory Explorer - Out-of-Bounds Write
10-Strike Network Inventory Explorer Pro 9.31 contains a buffer overflow vulnerability in the text file import functionality that allows remote code execution. Attackers can craft a malicious text file with carefully constructed payload to trigger a reverse shell and execute arbitrary code on the target system.
CWE-787
Jan 15, 2026
CVE-2021-43451
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
PHPGURUKUL Employee Record Management System 1.2 - SQL Injection
SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php.
CWE-89
Dec 01, 2021
CVE-2021-41646
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.04
Online Reviewer System - Unrestricted File Upload
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..
CWE-434
Oct 29, 2021
CVE-2021-41644
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.01
Online Food Ordering System - Unrestricted File Upload
Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.
CWE-434
Oct 29, 2021
CVE-2021-41643
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.11
Church Management System - Unrestricted File Upload
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.
CWE-434
Oct 29, 2021
CVE-2021-40239
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Miniftpd - Buffer Overflow
A Buffer Overflow vulnerability exists in the latest version of Miniftpd in the do_retr function in ftpproto.c
CWE-120
Oct 11, 2021
CVE-2021-20034
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.06
Sonicwall Sma 200 Firmware < 9.0.0.10-28sv - Improper Access Control
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
CWE-284
Sep 27, 2021
CVE-2021-24884
9.6
CRITICAL
1 PoC
Analysis
EPSS 0.19
Formidable Form Builder <4.09.05 - HTML Injection
The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to follow the link. If the Link gets clicked, Javascript code can be executed. The vulnerability is due to insufficient sanitization of the "data-frmverify" tag for links in the web-based entry inspection page of affected systems. A successful exploitation incomibantion with CSRF could allow the attacker to perform arbitrary actions on an affected system with the privileges of the user. These actions include stealing the users account by changing their password or allowing attackers to submit their own code through an authenticated user resulting in Remote Code Execution. If an authenticated user who is able to edit Wordpress PHP Code in any kind, clicks the malicious link, PHP code can be edited.
CWE-352
Oct 25, 2021
CVE-2021-44249
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Online Motorcycle (bike) Rental System - SQL Injection
Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login portal. This can lead attackers to remotely dump MySQL database credentials.
CWE-89
Jan 28, 2022
CVE-2021-42071
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.91
Visual-tools Dvr Vx16 Firmware - OS Command Injection
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.
CWE-78
Oct 07, 2021
CVE-2021-42169
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Simple Payroll System With Dynamic Tax Bracket - SQL Injection
The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and escaping from malicious payloads.
CWE-89
Oct 22, 2021
CVE-2021-47781
9.8
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Cmder Console Emulator 1.3.18 - DoS
Cmder Console Emulator 1.3.18 contains a buffer overflow vulnerability that allows attackers to trigger a denial of service condition through a maliciously crafted .cmd file. Attackers can create a specially constructed .cmd file with repeated characters to overwhelm the console emulator's buffer and crash the application.
CWE-787
Jan 15, 2026