Critical Vulnerabilities with Public Exploits
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,103 results
Clear all
CVE-2018-1002105
9.8
CRITICAL
8 PoCs
Analysis
EPSS 0.90
Kubernetes <1.10.11-1.12.3 - SSRF
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.
CWE-388
Dec 05, 2018
CVE-2018-9021
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.10
Broadcom Privileged Access Manager - Improper Privilege Management
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests.
CWE-269
Jun 18, 2018
CVE-2018-20062
9.8
CRITICAL
KEV
5 PoCs
Analysis
NUCLEI
EPSS 0.94
NoneCms V1.3 - RCE
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&filter=phpinfo&data=1 query string.
Dec 11, 2018
CVE-2018-15708
9.8
CRITICAL
4 PoCs
Analysis
EPSS 0.91
Nagios XI Magpie_debug.php Root Remote Code Execution
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.
Nov 14, 2018
CVE-2018-20218
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.31
Teracue ENC-400 <2.56 - Command Injection
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform command injection using the "password" parameter in the login form.
CWE-78
Mar 21, 2019
CVE-2018-5955
9.8
CRITICAL
7 PoCs
Analysis
EPSS 0.87
GitStack <2.3.10 - Privilege Escalation
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unauthenticated attacker to add a user to the server via the username and password fields to the rest/user/ URI.
CWE-20
Jan 21, 2018
CVE-2018-9160
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.74
Sickrage < 9.2.101 - Insufficiently Protected Credentials
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
CWE-522
Mar 31, 2018
CVE-2018-17179
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.12
OpenEMR <5.0.1.7 - SQL Injection
An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.php.
CWE-89
May 17, 2019
CVE-2018-17934
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.68
Nuuo Cms < 3.3 - Path Traversal
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an attacker to impersonate a legitimate user, obtain restricted information, or execute arbitrary code.
CWE-22
Nov 27, 2018
CVE-2018-17888
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.42
NUUO CMS <3.1 - RCE
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.
CWE-330
Oct 12, 2018
CVE-2018-16158
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.70
Eaton Power Xpert Meter 4000 Firmware - Hard-coded Credentials
Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the PubkeyAuthentication option.
CWE-798
Aug 30, 2018
CVE-2018-11138
9.8
CRITICAL
KEV
RANSOMWARE
2 PoCs
Analysis
NUCLEI
EPSS 0.93
Quest Kace System Management Appliance - OS Command Injection
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
CWE-78
May 31, 2018
CVE-2018-10094
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.74
Dolibarr <7.0.2 - SQL Injection
SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes.
CWE-89
May 22, 2018
CVE-2018-19276
9.8
CRITICAL
EXPLOITED
4 PoCs
Analysis
NUCLEI
EPSS 0.93
OpenMRS Java Deserialization RCE
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.
CWE-502
Mar 21, 2019
CVE-2018-17456
9.8
CRITICAL
9 PoCs
Analysis
EPSS 0.65
Malicious Git HTTP Server For CVE-2018-17456
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.
CWE-88
Oct 06, 2018
CVE-2018-17552
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.88
Naviwebs Navigate CMS 2.8 - SQL Injection
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie.
CWE-89
Oct 03, 2018
CVE-2018-15961
9.8
CRITICAL
KEV
7 PoCs
Analysis
NUCLEI
EPSS 0.94
Adobe Coldfusion - Unrestricted File Upload
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.
CWE-434
Sep 25, 2018
CVE-2018-17207
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.91
Snap Creek Duplicator <1.2.42 - Code Injection
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.
CWE-94
Sep 19, 2018
CVE-2018-14933
9.8
CRITICAL
KEV
3 PoCs
Analysis
NUCLEI
EPSS 0.94
NUUO NVRmini - RCE
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
CWE-78
Aug 04, 2018
CVE-2018-1000533
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.92
klaussilveira GitList <=0.6 - RCE
klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as PHP user. This attack appear to be exploitable via Send POST request using search form. This vulnerability appears to have been fixed in 0.7 after commit 87b8c26b023c3fc37f0796b14bb13710f397b322.
CWE-20
Jun 26, 2018