Critical Vulnerabilities with Public Exploits
Updated 17m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,105 results
Clear all
CVE-2020-21994
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.05
AVE Dominaplus < 1.10.77 - Insufficiently Protected Credentials
AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.
CWE-522
Apr 28, 2021
CVE-2020-21991
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.05
AVE Dominaplus < 1.10.77 - Authentication Bypass
AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.
CWE-287
Apr 28, 2021
CVE-2020-22001
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Homeautomation - Authentication Bypass by Spoofing
HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address value allowing remote control of the smart home solution.
CWE-290
Apr 27, 2021
CVE-2020-21995
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Inim Smartliving 505 Firmware < 6.0 - Hard-coded Credentials
Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to gain Telnet, SSH and FTP access to the system.
CWE-798
Apr 29, 2021
CVE-2019-0230
9.8
CRITICAL
7 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache Struts < 2.5.20 - Prototype Pollution
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
CWE-1321
Sep 14, 2020
CVE-2019-18935
9.8
CRITICAL
KEV
RANSOMWARE
20 PoCs
Analysis
EPSS 0.94
Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)
CWE-502
Dec 11, 2019
CVE-2019-16759
9.8
CRITICAL
KEV
17 PoCs
Analysis
NUCLEI
EPSS 0.94
vBulletin 5.x /ajax/render/widget_tabbedcontainer_tab_panel PHP remote code execution.
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
CWE-94
Sep 24, 2019
CVE-2019-15107
9.8
CRITICAL
KEV
49 PoCs
Analysis
NUCLEI
EPSS 0.94
Webmin < 1.920 - OS Command Injection
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
CWE-78
Aug 16, 2019
CVE-2019-0708
9.8
CRITICAL
KEV
RANSOMWARE
161 PoCs
Analysis
EPSS 0.94
CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
CWE-416
May 16, 2019
CVE-2019-7195
9.8
CRITICAL
KEV
RANSOMWARE
2 PoCs
Analysis
NUCLEI
EPSS 0.94
QNAP Photo Station - Path Traversal
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
CWE-22
Dec 05, 2019
CVE-2019-7192
9.8
CRITICAL
KEV
RANSOMWARE
3 PoCs
Analysis
NUCLEI
EPSS 0.94
QNAP Photo Station - Info Disclosure
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
CWE-863
Dec 05, 2019
CVE-2019-10945
9.8
CRITICAL
5 PoCs
Analysis
EPSS 0.81
Joomla! < 3.9.4 - Path Traversal
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root directory.
CWE-22
Apr 10, 2019
CVE-2019-10068
9.8
CRITICAL
KEV
2 PoCs
Analysis
NUCLEI
EPSS 0.94
Kentico <12.0.15, 11.0.48, 10.0.52, 9.x - Code Injection
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.
CWE-502
Mar 26, 2019
CVE-2019-3980
9.8
CRITICAL
EXPLOITED
4 PoCs
Analysis
EPSS 0.50
Solarwinds Dameware Mini Remote Control - Origin Validation Error
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System account.
CWE-346
Oct 08, 2019
CVE-2019-9762
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.54
PHPSHE 1.7 - SQL Injection
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication.
CWE-89
Mar 14, 2019
CVE-2019-9626
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
PHPSHE 1.7 - SQL Injection
PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.
CWE-89
Mar 07, 2019
CVE-2019-7684
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
inxedu <2018-12-24 - Code Injection
inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is com.inxedu.os.common.controller.VideoUploadController#gok4 (com/inxedu/os/common/controller/VideoUploadController.java). The attacker uses the /video/uploadvideo fileType parameter to change the list of acceptable extensions from jpg,gif,png,jpeg to jpg,gif,png,jsp,jpeg.
CWE-434
Feb 09, 2019
CVE-2019-3576
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Inxedu < 2018-12-24 - SQL Injection
inxedu through 2018-12-24 has a SQL Injection vulnerability that can lead to information disclosure via the deleteFaveorite/ PATH_INFO. The vulnerable code location is com.inxedu.os.edu.controller.user.UserController#deleteFavorite (aka deleteFavorite in com/inxedu/os/edu/controller/user/UserController.java), where courseFavoritesService.deleteCourseFavoritesById is mishandled during use of MyBatis. NOTE: UserController.java has a spelling variation in an annotation: a @RequestMapping("/deleteFaveorite/{ids}") line followed by a "public ModelAndView deleteFavorite" line.
CWE-89
Jan 02, 2019
CVE-2019-18818
9.8
CRITICAL
EXPLOITED
10 PoCs
Analysis
NUCLEI
EPSS 0.94
Strapi CMS Unauthenticated Password Reset
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
CWE-640
Nov 07, 2019
CVE-2019-15597
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.04
Node-df - Code Injection
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
CWE-94
Dec 18, 2019