Critical Vulnerabilities with Public Exploits
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,118 results
Clear all
CVE-2021-27828
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.01
In4Suite ERP <3.2.74.1370 - SQL Injection
SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
CWE-89
Jun 01, 2021
CVE-2021-33470
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
COVID19 Testing Management System 1.0 - SQL Injection
COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.
CWE-89
May 26, 2021
CVE-2021-45411
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Printable Staff ID Card Creator System - Unrestricted File Upload
In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.
CWE-434
Jan 12, 2022
CVE-2021-31856
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.79
Layer5 Meshery - SQL Injection
A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/meshery_pattern_persister.go).
CWE-89
Apr 28, 2021
CVE-2021-47748
9.8
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Hasura Graphql Engine - OS Command Injection
Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject commands into the run_sql endpoint by crafting malicious GraphQL queries that execute system commands through PostgreSQL's COPY FROM PROGRAM functionality.
CWE-78
Jan 21, 2026
CVE-2021-30149
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.17
Composr 10.0.36 - Code Injection
Composr 10.0.36 allows upload and execution of PHP files.
CWE-434
Apr 06, 2021
CVE-2021-47851
9.8
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.01
Yodinfo Mini Mouse - OS Command Injection
Mini Mouse 9.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands through an unauthenticated HTTP endpoint. Attackers can leverage the /op=command endpoint to download and execute payloads by sending crafted JSON requests with malicious script commands.
CWE-78
Jan 21, 2026
CVE-2021-34166
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Simple Food Website - SQL Injection
A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin.
CWE-89
Jul 30, 2021
CVE-2021-34165
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Basic Shopping Cart - SQL Injection
A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin.
CWE-89
Jul 30, 2021
CVE-2021-47854
9.8
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.00
DD-WRT <45723 - Buffer Overflow
DD-WRT version 45723 contains a buffer overflow vulnerability in the UPNP network discovery service that allows remote attackers to potentially execute arbitrary code. Attackers can send crafted M-SEARCH packets with oversized UUID payloads to trigger buffer overflow conditions on the target device.
CWE-120
Jan 21, 2026
CVE-2021-47875
9.8
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.00
GeoGebra CAS Calculator <6.0.631.0 - DoS
GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a payload with 8000 repeated characters and paste it into the calculator's input field to trigger an application crash.
CWE-770
Jan 21, 2026
CVE-2021-26830
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.01
Tribalsystems Zenario < 8.8.53370 - SQL Injection
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.
CWE-89
Apr 16, 2021
CVE-2021-28940
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.05
MagpieRSS 0.72 - Command Injection
Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command to the curl binary. This creates an issue on the /scripts/magpie_debug.php and /scripts/magpie_simple.php page that if you send a specific https url in the RSS URL field, you are able to execute arbitrary commands.
CWE-116
Apr 02, 2021
CVE-2021-27964
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.82
SonLogger - Arbitrary File Upload
SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for the file extension or content of the uploaded file.
CWE-434
Mar 05, 2021
CVE-2021-26705
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.00
Squarebox Catdv < 9.2 - Missing Authentication
An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getConnections without authentication, the results of which can be used to generate valid authentication tokens. These tokens can then be used to invoke administrative tasks within the application, such as disclosing password hashes.
CWE-306
Mar 05, 2021
CVE-2021-28294
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Online Ordering System 1.0 - RCE
Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).
CWE-434
Mar 16, 2021
CVE-2021-4462
9.8
CRITICAL
EXPLOITED
SSVC PoC
1 PoC
Analysis
NUCLEI
EPSS 0.18
Skittles Employee Records System - Unrestricted File Upload
Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.
CWE-434
Nov 10, 2025
CVE-2021-26904
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Isida Retriever - SQL Injection
LMA ISIDA Retriever 5.2 allows SQL Injection.
CWE-89
Feb 26, 2021
CVE-2021-47891
9.8
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Unified Remote 3.9.0.2463 - RCE
Unified Remote 3.9.0.2463 contains a remote code execution vulnerability that allows attackers to send crafted network packets to execute arbitrary commands. Attackers can exploit the service by connecting to port 9512 and sending specially crafted packets to open a command prompt and download and execute malicious payloads.
CWE-306
Jan 23, 2026
CVE-2021-21110
9.6
CRITICAL
1 PoC
Analysis
EPSS 0.23
Google Chrome <87.0.4280.141 - Use After Free
Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CWE-416
Jan 08, 2021