Critical Vulnerabilities with Public Exploits
Updated 35m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,109 results
Clear all
CVE-2020-35545
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.08
Spotweb - SQL Injection
Time-based SQL injection exists in Spotweb 1.4.9 via the query string.
CWE-89
Dec 17, 2020
CVE-2020-24148
9.1
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.93
WordPress import-xml-feed <2.0.1 - SSRF
Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.
CWE-918
Jul 07, 2021
CVE-2020-7115
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.61
Arubanetworks Clearpass Policy Manager - Missing Authentication
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.
CWE-306
Jun 03, 2020
CVE-2020-7750
9.6
CRITICAL
1 PoC
Analysis
EPSS 0.06
MIT Scratch-svg-renderer - XSS
This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.
CWE-79
Oct 21, 2020
CVE-2020-35948
9.9
CRITICAL
1 PoC
Analysis
EPSS 0.49
Xcloner < 4.2.13 - Incorrect Authorization
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config.php, for example. Alternatively, an attacker could create an exploit chain to obtain a database dump.
CWE-863
Jan 01, 2021
CVE-2020-13957
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.85
Apache Solr < 6.6.6 - Incorrect Authorization
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be circumvented by using a combination of UPLOAD/CREATE actions.
CWE-863
Oct 13, 2020
CVE-2020-35775
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.26
Citsmart < 9.1.2.23 - Injection
CITSmart before 9.1.2.23 allows LDAP Injection.
CWE-74
Feb 15, 2021
CVE-2020-15160
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.19
PrestaShop <1.7.6.8 - Blind SQL Injection
PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with location parameter. The problem is fixed in 1.7.6.8
CWE-89
Sep 24, 2020
CVE-2020-11819
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.27
Rukovoditel - Path Traversal
In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution.
CWE-22
Apr 16, 2020
CVE-2020-28926
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.66
Readymedia < 1.3.0 - Buffer Overflow
ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove.
CWE-120
Nov 30, 2020
CVE-2020-25787
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.16
Tt-rss Tiny Tiny Rss < 2020-09-16 - Improper Input Validation
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting them.
CWE-20
Sep 19, 2020
CVE-2020-8637
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
TestLink <1.9.20 - SQL Injection
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.
CWE-89
Apr 03, 2020
CVE-2020-25782
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.20
Accfly 720p Firmware < 4.15.77 - Out-of-Bounds Write
An issue was discovered on Accfly Wireless Security IR Camera 720P System with software versions v3.10.73 through v4.15.77. There is an unauthenticated stack-based buffer overflow in the function CNetClientManage::ServerIP_Proto_Set during incoming message handling.
CWE-787
Jan 28, 2021
CVE-2020-11851
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.04
Microfocus Arcsight Logger < 7.1.1 - Code Injection
Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in the execution of arbitrary code.
CWE-94
Nov 17, 2020
CVE-2020-24032
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.17
LPAR2RRD/STOR2RRD 2.70 - Command Injection
tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.
CWE-78
Aug 18, 2020
CVE-2020-35713
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.94
Linksys Re6500 Firmware < 1.0.012.001 - OS Command Injection
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.
CWE-78
Dec 26, 2020
CVE-2020-7048
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.47
Webfactoryltd WP Database Reset < 3.1 - Missing Authentication
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in that table), as demonstrated by a wp-admin/admin-post.php?db-reset-tables[]=comments URI.
CWE-306
Jan 16, 2020
CVE-2020-35131
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.91
Cockpit <0.6.1 - RCE
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.
CWE-94
Jan 08, 2021
CVE-2020-36084
9.8
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.01
Jkev Responsive E-learning System - SQL Injection
SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql query in /elearning/delete_teacher_students.php?id= parameter via id field.
CWE-89
Feb 05, 2025
CVE-2020-29597
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.85
IncomCMS 2.0 - File Upload
IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upload files into the server.
CWE-434
Dec 07, 2020