Critical Vulnerabilities with Public Exploits

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,682 CVEs tracked 53,700 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,389 vendors 43,933 researchers
4,118 results Clear all
CVE-2021-42224 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Phpgurukul Ifsc Code Finder - SQL Injection
SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.
CWE-89 Oct 13, 2021
CVE-2021-32172 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.65
Maianscriptworld Maian Cart - Missing Authorization
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.
CWE-862 Oct 07, 2021
CVE-2021-3625 9.6 CRITICAL 1 PoC Analysis EPSS 0.06
Zephyr < 2.7.0 - Out-of-Bounds Write
Buffer overflow in Zephyr USB DFU DNLOAD. Zephyr versions >= v2.5.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-c3gr-hgvr-f363
CWE-122 Oct 05, 2021
CVE-2021-41647 9.1 CRITICAL 1 PoC Analysis EPSS 0.01
Online Food Ordering Web App - SQL Injection
An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.
CWE-89 Oct 01, 2021
CVE-2021-41649 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.92
Online-shopping-system-advanced - SQL Injection
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
CWE-89 Oct 01, 2021
CVE-2021-34730 9.8 CRITICAL EXPLOITED RANSOMWARE 1 PoC Analysis EPSS 0.37
Cisco Application Extension Platform - Out-of-Bounds Write
A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of incoming UPnP traffic. An attacker could exploit this vulnerability by sending a crafted UPnP request to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a DoS condition. Cisco has not released software updates that address this vulnerability.
CWE-121 Aug 18, 2021
CVE-2021-47785 9.8 CRITICAL SSVC PoC 1 PoC Analysis EPSS 0.00
Ethersoftware Ether Mp3 CD Burner - Out-of-Bounds Write
Ether MP3 CD Burner 1.3.8 contains a buffer overflow vulnerability in the registration name field that allows remote code execution. Attackers can craft a malicious payload to overwrite SEH handlers and execute a bind shell on port 3110 by exploiting improper input validation.
CWE-787 Jan 16, 2026
CVE-2021-40323 9.8 CRITICAL 1 PoC 1 Writeup Analysis NUCLEI EPSS 0.93
Cobbler <3.3.0 - RCE
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
CWE-94 Oct 04, 2021
CVE-2021-2302 9.8 CRITICAL 1 PoC Analysis EPSS 0.53
Oracle Fusion Middleware <12.2.1.4.0 - RCE
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Apr 22, 2021
CVE-2021-1994 9.8 CRITICAL 1 PoC Analysis EPSS 0.28
Oracle WebLogic Server <12.1.3.0.0 - RCE
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Jan 20, 2021
CVE-2021-38833 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
PHPGurukul AVMS <1.0 - SQL Injection
SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL statements and to gain RCE.
CWE-89 Sep 13, 2021
CVE-2021-24040 9.8 CRITICAL 1 PoC Analysis EPSS 0.36
Facebook Parlai < 1.1.0 - Insecure Deserialization
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. This issue affects ParlAI prior to v1.1.0.
CWE-502 Sep 10, 2021
CVE-2021-40353 9.8 CRITICAL 1 PoC Analysis EPSS 0.09
openSIS 8.0 - SQL Injection
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the index.php USERNAME parameter. NOTE: this issue may exist because of an incomplete fix for CVE-2020-6637.
CWE-89 Sep 01, 2021
CVE-2021-39377 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
Os4ed Opensis - SQL Injection
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the index.php username parameter.
CWE-89 Sep 01, 2021
CVE-2021-39378 9.8 CRITICAL 1 PoC Analysis EPSS 0.09
Os4ed Opensis - SQL Injection
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the NamesList.php str parameter.
CWE-89 Sep 01, 2021
CVE-2021-39379 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
Os4ed Opensis - SQL Injection
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the ResetUserInfo.php password_stn_id parameter.
CWE-89 Sep 01, 2021
CVE-2021-38840 9.8 CRITICAL 2 PoCs Analysis EPSS 0.00
Simple Water Refilling Station Management System 1.0 - SQL Injection
SQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.php username parameter.
CWE-89 Sep 07, 2021
CVE-2021-37425 9.1 CRITICAL 1 PoC Analysis EPSS 0.09
Altova Mobiletogether Server < 7.3 - XXE
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.
CWE-611 Aug 10, 2021
CVE-2021-29281 9.8 CRITICAL 1 PoC Analysis EPSS 0.04
GFI Archiver < 15.2 - Unrestricted File Upload
File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317.
CWE-434 Jul 07, 2022
CVE-2021-36351 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Care2x Hospital Information Management System < 2.7 - SQL Injection
SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth, and (3) pyear parameters in GET requests sent to /modules/nursing/nursing-station.php.
CWE-89 Aug 06, 2021