Critical Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,682 CVEs tracked 53,700 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,389 vendors 43,933 researchers
4,118 results Clear all
CVE-2021-27828 9.1 CRITICAL 1 PoC Analysis EPSS 0.01
In4Suite ERP <3.2.74.1370 - SQL Injection
SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
CWE-89 Jun 01, 2021
CVE-2021-33470 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
COVID19 Testing Management System 1.0 - SQL Injection
COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.
CWE-89 May 26, 2021
CVE-2021-45411 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Printable Staff ID Card Creator System - Unrestricted File Upload
In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.
CWE-434 Jan 12, 2022
CVE-2021-31856 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.79
Layer5 Meshery - SQL Injection
A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/meshery_pattern_persister.go).
CWE-89 Apr 28, 2021
CVE-2021-47748 9.8 CRITICAL SSVC PoC 1 PoC Analysis EPSS 0.00
Hasura Graphql Engine - OS Command Injection
Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject commands into the run_sql endpoint by crafting malicious GraphQL queries that execute system commands through PostgreSQL's COPY FROM PROGRAM functionality.
CWE-78 Jan 21, 2026
CVE-2021-30149 9.8 CRITICAL 1 PoC Analysis EPSS 0.17
Composr 10.0.36 - Code Injection
Composr 10.0.36 allows upload and execution of PHP files.
CWE-434 Apr 06, 2021
CVE-2021-47851 9.8 CRITICAL SSVC PoC 1 PoC Analysis EPSS 0.01
Yodinfo Mini Mouse - OS Command Injection
Mini Mouse 9.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands through an unauthenticated HTTP endpoint. Attackers can leverage the /op=command endpoint to download and execute payloads by sending crafted JSON requests with malicious script commands.
CWE-78 Jan 21, 2026
CVE-2021-34166 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Simple Food Website - SQL Injection
A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin.
CWE-89 Jul 30, 2021
CVE-2021-34165 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Basic Shopping Cart - SQL Injection
A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin.
CWE-89 Jul 30, 2021
CVE-2021-47854 9.8 CRITICAL SSVC PoC 1 PoC Analysis EPSS 0.00
DD-WRT <45723 - Buffer Overflow
DD-WRT version 45723 contains a buffer overflow vulnerability in the UPNP network discovery service that allows remote attackers to potentially execute arbitrary code. Attackers can send crafted M-SEARCH packets with oversized UUID payloads to trigger buffer overflow conditions on the target device.
CWE-120 Jan 21, 2026
CVE-2021-47875 9.8 CRITICAL SSVC PoC 1 PoC Analysis EPSS 0.00
GeoGebra CAS Calculator <6.0.631.0 - DoS
GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a payload with 8000 repeated characters and paste it into the calculator's input field to trigger an application crash.
CWE-770 Jan 21, 2026
CVE-2021-26830 9.1 CRITICAL 1 PoC Analysis EPSS 0.01
Tribalsystems Zenario < 8.8.53370 - SQL Injection
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.
CWE-89 Apr 16, 2021
CVE-2021-28940 9.8 CRITICAL 1 PoC Analysis EPSS 0.05
MagpieRSS 0.72 - Command Injection
Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command to the curl binary. This creates an issue on the /scripts/magpie_debug.php and /scripts/magpie_simple.php page that if you send a specific https url in the RSS URL field, you are able to execute arbitrary commands.
CWE-116 Apr 02, 2021
CVE-2021-27964 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.82
SonLogger - Arbitrary File Upload
SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for the file extension or content of the uploaded file.
CWE-434 Mar 05, 2021
CVE-2021-26705 9.1 CRITICAL 1 PoC Analysis EPSS 0.00
Squarebox Catdv < 9.2 - Missing Authentication
An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getConnections without authentication, the results of which can be used to generate valid authentication tokens. These tokens can then be used to invoke administrative tasks within the application, such as disclosing password hashes.
CWE-306 Mar 05, 2021
CVE-2021-28294 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Online Ordering System 1.0 - RCE
Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).
CWE-434 Mar 16, 2021
CVE-2021-4462 9.8 CRITICAL EXPLOITED SSVC PoC 1 PoC Analysis NUCLEI EPSS 0.18
Skittles Employee Records System - Unrestricted File Upload
Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.
CWE-434 Nov 10, 2025
CVE-2021-26904 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Isida Retriever - SQL Injection
LMA ISIDA Retriever 5.2 allows SQL Injection.
CWE-89 Feb 26, 2021
CVE-2021-47891 9.8 CRITICAL SSVC PoC 1 PoC Analysis EPSS 0.00
Unified Remote 3.9.0.2463 - RCE
Unified Remote 3.9.0.2463 contains a remote code execution vulnerability that allows attackers to send crafted network packets to execute arbitrary commands. Attackers can exploit the service by connecting to port 9512 and sending specially crafted packets to open a command prompt and download and execute malicious payloads.
CWE-306 Jan 23, 2026
CVE-2021-21110 9.6 CRITICAL 1 PoC Analysis EPSS 0.23
Google Chrome <87.0.4280.141 - Use After Free
Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CWE-416 Jan 08, 2021