Critical Vulnerabilities with Public Exploits
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,105 results
Clear all
CVE-2020-37043
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
10-Strike Bandwidth Monitor 3.9 - Buffer Overflow
10-Strike Bandwidth Monitor 3.9 contains a buffer overflow vulnerability that allows attackers to bypass SafeSEH, ASLR, and DEP protections through carefully crafted input. Attackers can exploit the vulnerability by sending a malicious payload to the application's registration key input, enabling remote code execution and launching arbitrary system commands.
CWE-120
Jan 30, 2026
CVE-2020-37050
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Quick Player 1.3 - Buffer Overflow
Quick Player 1.3 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious .m3l file with carefully constructed payload. Attackers can trigger the vulnerability by loading a specially crafted file through the application's file loading mechanism, potentially enabling remote code execution.
CWE-120
Jan 30, 2026
CVE-2020-37052
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
AirControl 1.4.2 - RCE
AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through malicious Java expression injection. Attackers can exploit the /.seam endpoint by crafting a specially constructed URL with embedded Java expressions to run commands with the application's system privileges.
CWE-94
Jan 30, 2026
CVE-2020-5510
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.00
PHPGurukul Hostel Mgt Sys <2.0 - SQL Injection
PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.
CWE-89
Jan 08, 2020
CVE-2020-12753
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.06
LG Android OS <10 - RCE
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Arbitrary code execution can occur via the bootloader because of an EL1/EL3 coldboot vulnerability involving raw_resources. The LG ID is LVE-SMP-200006 (May 2020).
CWE-787
May 11, 2020
CVE-2020-13693
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.41
bbPress <2.6.5 - Privilege Escalation
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.
May 29, 2020
CVE-2020-1947
9.8
CRITICAL
4 PoCs
Analysis
EPSS 0.85
Apache Shardingsphere < 4.0.1 - Insecure Deserialization
In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. SnakeYAML allows to unmarshal data to a Java type By using the YAML tag. Unmarshalling untrusted data can lead to security flaws of RCE.
CWE-502
Mar 11, 2020
CVE-2020-37056
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Crystal Shard http-protection 0.2.0 - SSRF
Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating request headers. Attackers can hardcode consistent IP values across X-Forwarded-For, X-Client-IP, and X-Real-IP headers to circumvent security checks and gain unauthorized access.
CWE-290
Jan 30, 2026
CVE-2020-37065
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
StreamRipper32 <2.6 - Buffer Overflow
StreamRipper32 version 2.6 contains a buffer overflow vulnerability in the Station/Song Section that allows attackers to overwrite memory by manipulating the SongPattern input. Attackers can craft a malicious payload exceeding 256 bytes to potentially execute arbitrary code and compromise the application.
CWE-120
Feb 03, 2026
CVE-2020-37066
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
GoldWave 5.70 - Buffer Overflow
GoldWave 5.70 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting malicious input in the File Open URL dialog. Attackers can generate a specially crafted text file with Unicode-encoded shellcode to trigger a stack-based overflow and execute commands when the file is opened.
CWE-121
Feb 03, 2026
CVE-2020-37069
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Konica Minolta FTP Utility 1.0 - Buffer Overflow
Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.
CWE-120
Feb 03, 2026
CVE-2020-37068
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Konica Minolta FTP Utility 1.0 - Buffer Overflow
Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.
CWE-120
Feb 03, 2026
CVE-2020-37067
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Filetto 1.0 - DoS
Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the service. Attackers can send an oversized FEAT command with 11,008 bytes of repeated characters to trigger a buffer overflow and terminate the FTP service.
CWE-770
Feb 03, 2026
CVE-2020-37070
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
CloudMe 1.11.2 - RCE
CloudMe 1.11.2 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code through crafted network packets. Attackers can exploit the vulnerability by sending a specially crafted payload to the CloudMe service running on port 8888, enabling remote code execution.
CWE-120
Feb 03, 2026
CVE-2020-37071
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
CraftCMS 3 vCard Plugin 1.0.0 - Code Injection
CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code execution by exploiting the plugin's vCard download functionality with a specially crafted request.
CWE-502
Feb 03, 2026
CVE-2020-13118
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.04
Mikrotik Router Monitoring System <2018-10-22 - SQL Injection
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.
CWE-89
May 16, 2020
CVE-2020-37074
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Remote Desktop Audit 2.3.0.157 - RCE
Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code during the Add Computers Wizard file import process. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) bypass and execute shellcode when importing computer lists.
CWE-120
Feb 03, 2026
CVE-2020-37075
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
LanSend 3.2 - RCE
LanSend 3.2 contains a buffer overflow vulnerability in the Add Computers Wizard file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) overwrite and execute shellcode when importing computers from a file.
CWE-120
Feb 03, 2026
CVE-2020-28140
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Online Clothing Store - Unrestricted File Upload
SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Products.php.
CWE-434
Nov 17, 2020
CVE-2020-14972
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Sourcecodester Pisay Online E-Learning System 1.0 - SQL Injection
Multiple SQL injection vulnerabilities in Sourcecodester Pisay Online E-Learning System 1.0 allow remote unauthenticated attackers to bypass authentication and achieve Remote Code Execution (RCE) via the user_email, user_pass, and id parameters on the admin login-portal and the edit-lessons webpages.
CWE-89
Jun 22, 2020