Critical Vulnerabilities with Public Exploits
Updated 9m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,109 results
Clear all
CVE-2020-29583
9.8
CRITICAL
KEV
1 PoC
Analysis
NUCLEI
EPSS 0.94
Zyxel USG <4.60 - Privilege Escalation
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
CWE-522
Dec 22, 2020
CVE-2020-36941
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Knockpy 4.1.1 - Code Injection
Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports through unfiltered server headers. Attackers can manipulate server response headers to include spreadsheet formulas that will execute when the CSV is opened in spreadsheet applications.
CWE-1236
Jan 27, 2026
CVE-2020-36940
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Easy CD & DVD Cover Creator 4.13 - Buffer Overflow
Easy CD & DVD Cover Creator 4.13 contains a buffer overflow vulnerability in the serial number input field that allows attackers to crash the application. Attackers can generate a 6000-byte payload and paste it into the serial number field to trigger an application crash.
CWE-120
Jan 27, 2026
CVE-2020-36925
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Arteco Web Client DVR/NVR - Auth Bypass
Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.
CWE-331
Jan 06, 2026
CVE-2020-3161
9.8
CRITICAL
KEV
2 PoCs
Analysis
EPSS 0.87
Cisco IP Phones - RCE/DoS
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.
CWE-20
Apr 15, 2020
CVE-2020-36112
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.89
Cse Bookstore - SQL Injection
CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of this vulnerability will lead to an attacker dumping the entire database on which the web application is running.
CWE-89
Jan 04, 2021
CVE-2020-25494
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
EPSS 0.61
Xinuos Openserver - OS Command Injection
Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels parameter to cgi-bin/printbook.
CWE-78
Dec 18, 2020
CVE-2020-29667
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.04
Lan ATMService M3 ATM Monitoring System 6.1.0 - Info Disclosure
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.
CWE-613
Dec 10, 2020
CVE-2020-17531
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.69
Apache Tapestry 4 - Deserialization
A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008 and no update to address this issue will be released. Apache Tapestry 5 versions are not vulnerable to this issue. Users of Apache Tapestry 4 should upgrade to the latest Apache Tapestry 5 version.
CWE-502
Dec 08, 2020
CVE-2020-36948
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
VestaCP 0.9.8-26 - Auth Bypass
VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper administrative permissions.
CWE-863
Jan 27, 2026
CVE-2020-29659
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.04
Flexense DupScout Enterprise 10.0.18 - Buffer Overflow
A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack.
CWE-120
Dec 09, 2020
CVE-2020-29007
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.17
Mediawiki Score < 0.3.0 - Code Injection
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted {{Image data to generate musical scores containing malicious code.
CWE-94
Apr 15, 2023
CVE-2020-35378
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Online Bus Ticket Reservation - SQL Injection
SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.
CWE-89
Dec 14, 2020
CVE-2020-29474
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
EGavilan Media EGM Address Book 1.0 - SQL Injection
EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
CWE-89
Dec 24, 2020
CVE-2020-35427
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Phpgurukul Employee Record Management System - SQL Injection
SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
CWE-89
Jul 20, 2021
CVE-2020-35313
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.07
Wondercms - SSRF
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.
CWE-918
Apr 20, 2021
CVE-2020-35270
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.00
Student Result Management System - SQL Injection
Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of Admin Panel and manage every account of Result.
CWE-89
Jan 26, 2021
CVE-2020-29472
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
cPanel 1.0 - SQL Injection
EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
CWE-89
Dec 24, 2020
CVE-2020-27422
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.10
Anuko Time Tracker <1.19.23.5311 - Info Disclosure
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.
CWE-613
Nov 16, 2020
CVE-2020-11975
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.88
Apache Unomi - RCE
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
Jun 05, 2020