Critical Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,453 CVEs tracked 53,634 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,330 vendors 43,881 researchers
4,103 results Clear all
CVE-2018-1002105 9.8 CRITICAL 8 PoCs Analysis EPSS 0.90
Kubernetes <1.10.11-1.12.3 - SSRF
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.
CWE-388 Dec 05, 2018
CVE-2018-9021 9.8 CRITICAL 1 PoC Analysis EPSS 0.10
Broadcom Privileged Access Manager - Improper Privilege Management
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests.
CWE-269 Jun 18, 2018
CVE-2018-20062 9.8 CRITICAL KEV 5 PoCs Analysis NUCLEI EPSS 0.94
NoneCms V1.3 - RCE
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&filter=phpinfo&data=1 query string.
Dec 11, 2018
CVE-2018-15708 9.8 CRITICAL 4 PoCs Analysis EPSS 0.91
Nagios XI Magpie_debug.php Root Remote Code Execution
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.
Nov 14, 2018
CVE-2018-20218 9.8 CRITICAL 1 PoC Analysis EPSS 0.31
Teracue ENC-400 <2.56 - Command Injection
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform command injection using the "password" parameter in the login form.
CWE-78 Mar 21, 2019
CVE-2018-5955 9.8 CRITICAL 7 PoCs Analysis EPSS 0.87
GitStack <2.3.10 - Privilege Escalation
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unauthenticated attacker to add a user to the server via the username and password fields to the rest/user/ URI.
CWE-20 Jan 21, 2018
CVE-2018-9160 9.8 CRITICAL 3 PoCs Analysis EPSS 0.74
Sickrage < 9.2.101 - Insufficiently Protected Credentials
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
CWE-522 Mar 31, 2018
CVE-2018-17179 9.8 CRITICAL 2 PoCs Analysis EPSS 0.12
OpenEMR <5.0.1.7 - SQL Injection
An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.php.
CWE-89 May 17, 2019
CVE-2018-17934 9.8 CRITICAL 1 PoC Analysis EPSS 0.68
Nuuo Cms < 3.3 - Path Traversal
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an attacker to impersonate a legitimate user, obtain restricted information, or execute arbitrary code.
CWE-22 Nov 27, 2018
CVE-2018-17888 9.8 CRITICAL 1 PoC Analysis EPSS 0.42
NUUO CMS <3.1 - RCE
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.
CWE-330 Oct 12, 2018
CVE-2018-16158 9.8 CRITICAL 1 PoC Analysis EPSS 0.70
Eaton Power Xpert Meter 4000 Firmware - Hard-coded Credentials
Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the PubkeyAuthentication option.
CWE-798 Aug 30, 2018
CVE-2018-11138 9.8 CRITICAL KEV RANSOMWARE 2 PoCs Analysis NUCLEI EPSS 0.93
Quest Kace System Management Appliance - OS Command Injection
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
CWE-78 May 31, 2018
CVE-2018-10094 9.8 CRITICAL 2 PoCs Analysis EPSS 0.74
Dolibarr <7.0.2 - SQL Injection
SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes.
CWE-89 May 22, 2018
CVE-2018-19276 9.8 CRITICAL EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.93
OpenMRS Java Deserialization RCE
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.
CWE-502 Mar 21, 2019
CVE-2018-17456 9.8 CRITICAL 9 PoCs Analysis EPSS 0.65
Malicious Git HTTP Server For CVE-2018-17456
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.
CWE-88 Oct 06, 2018
CVE-2018-17552 9.8 CRITICAL 3 PoCs Analysis EPSS 0.88
Naviwebs Navigate CMS 2.8 - SQL Injection
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie.
CWE-89 Oct 03, 2018
CVE-2018-15961 9.8 CRITICAL KEV 7 PoCs Analysis NUCLEI EPSS 0.94
Adobe Coldfusion - Unrestricted File Upload
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.
CWE-434 Sep 25, 2018
CVE-2018-17207 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.91
Snap Creek Duplicator <1.2.42 - Code Injection
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.
CWE-94 Sep 19, 2018
CVE-2018-14933 9.8 CRITICAL KEV 3 PoCs Analysis NUCLEI EPSS 0.94
NUUO NVRmini - RCE
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
CWE-78 Aug 04, 2018
CVE-2018-1000533 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.92
klaussilveira GitList <=0.6 - RCE
klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as PHP user. This attack appear to be exploitable via Send POST request using search form. This vulnerability appears to have been fixed in 0.7 after commit 87b8c26b023c3fc37f0796b14bb13710f397b322.
CWE-20 Jun 26, 2018