Critical Vulnerabilities with Public Exploits

Updated 9m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,649 CVEs tracked 53,649 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,377 vendors 43,908 researchers
4,109 results Clear all
CVE-2020-29583 9.8 CRITICAL KEV 1 PoC Analysis NUCLEI EPSS 0.94
Zyxel USG <4.60 - Privilege Escalation
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
CWE-522 Dec 22, 2020
CVE-2020-36941 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Knockpy 4.1.1 - Code Injection
Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports through unfiltered server headers. Attackers can manipulate server response headers to include spreadsheet formulas that will execute when the CSV is opened in spreadsheet applications.
CWE-1236 Jan 27, 2026
CVE-2020-36940 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Easy CD & DVD Cover Creator 4.13 - Buffer Overflow
Easy CD & DVD Cover Creator 4.13 contains a buffer overflow vulnerability in the serial number input field that allows attackers to crash the application. Attackers can generate a 6000-byte payload and paste it into the serial number field to trigger an application crash.
CWE-120 Jan 27, 2026
CVE-2020-36925 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Arteco Web Client DVR/NVR - Auth Bypass
Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.
CWE-331 Jan 06, 2026
CVE-2020-3161 9.8 CRITICAL KEV 2 PoCs Analysis EPSS 0.87
Cisco IP Phones - RCE/DoS
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.
CWE-20 Apr 15, 2020
CVE-2020-36112 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.89
Cse Bookstore - SQL Injection
CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of this vulnerability will lead to an attacker dumping the entire database on which the web application is running.
CWE-89 Jan 04, 2021
CVE-2020-25494 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.61
Xinuos Openserver - OS Command Injection
Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels parameter to cgi-bin/printbook.
CWE-78 Dec 18, 2020
CVE-2020-29667 9.8 CRITICAL 1 PoC Analysis EPSS 0.04
Lan ATMService M3 ATM Monitoring System 6.1.0 - Info Disclosure
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.
CWE-613 Dec 10, 2020
CVE-2020-17531 9.8 CRITICAL 1 PoC Analysis EPSS 0.69
Apache Tapestry 4 - Deserialization
A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008 and no update to address this issue will be released. Apache Tapestry 5 versions are not vulnerable to this issue. Users of Apache Tapestry 4 should upgrade to the latest Apache Tapestry 5 version.
CWE-502 Dec 08, 2020
CVE-2020-36948 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
VestaCP 0.9.8-26 - Auth Bypass
VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper administrative permissions.
CWE-863 Jan 27, 2026
CVE-2020-29659 9.8 CRITICAL 1 PoC Analysis EPSS 0.04
Flexense DupScout Enterprise 10.0.18 - Buffer Overflow
A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack.
CWE-120 Dec 09, 2020
CVE-2020-29007 9.8 CRITICAL 1 PoC Analysis EPSS 0.17
Mediawiki Score < 0.3.0 - Code Injection
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted {{Image data to generate musical scores containing malicious code.
CWE-94 Apr 15, 2023
CVE-2020-35378 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Online Bus Ticket Reservation - SQL Injection
SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.
CWE-89 Dec 14, 2020
CVE-2020-29474 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
EGavilan Media EGM Address Book 1.0 - SQL Injection
EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
CWE-89 Dec 24, 2020
CVE-2020-35427 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Phpgurukul Employee Record Management System - SQL Injection
SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
CWE-89 Jul 20, 2021
CVE-2020-35313 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
Wondercms - SSRF
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.
CWE-918 Apr 20, 2021
CVE-2020-35270 9.1 CRITICAL 1 PoC Analysis EPSS 0.00
Student Result Management System - SQL Injection
Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of Admin Panel and manage every account of Result.
CWE-89 Jan 26, 2021
CVE-2020-29472 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
cPanel 1.0 - SQL Injection
EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
CWE-89 Dec 24, 2020
CVE-2020-27422 9.8 CRITICAL 1 PoC Analysis EPSS 0.10
Anuko Time Tracker <1.19.23.5311 - Info Disclosure
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.
CWE-613 Nov 16, 2020
CVE-2020-11975 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.88
Apache Unomi - RCE
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
Jun 05, 2020