Critical Vulnerabilities with Public Exploits
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,103 results
Clear all
CVE-2018-19361
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.02
FasterXML jackson-databind <2.9.8 - Deserialization
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
CWE-502
Jan 02, 2019
CVE-2018-1000822
10.0
CRITICAL
2 PoCs
Analysis
EPSS 0.00
codelibs fess <faa265b - XSS
codelibs fess version before commit faa265b contains a XML External Entity (XXE) vulnerability in GSA XML file parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via specially crafted GSA XML files. This vulnerability appears to have been fixed in after commit faa265b.
CWE-611
Dec 20, 2018
CVE-2018-12544
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.01
Eclipse Vert.x <3.5.4 - SSRF
In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type validator to validate a provided schema.
CWE-611
Oct 10, 2018
CVE-2018-1337
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.03
Apache Directory Ldap API < 1.0.2 - Information Disclosure
In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials when sending a BIND request).
CWE-200
Jul 10, 2018
CVE-2018-1000844
9.1
CRITICAL
3 PoCs
Analysis
EPSS 0.01
Squareup Retrofit < 2.5.0 - XXE
Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerability in JAXB that can result in An attacker could use this to remotely read files from the file system or to perform SSRF.. This vulnerability appears to have been fixed in After commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437.
CWE-611
Dec 20, 2018
CVE-2018-19360
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.07
FasterXML jackson-databind <2.9.8 - Code Injection
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
CWE-502
Jan 02, 2019
CVE-2018-12542
9.8
CRITICAL
4 PoCs
Analysis
EPSS 0.01
Eclipse Vert.x <3.5.3 - Path Traversal
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\' (forward slashes) sequences that can resolve to a location that is outside of that directory when running on Windows Operating Systems.
CWE-22
Oct 10, 2018
CVE-2018-19362
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.04
FasterXML jackson-databind <2.9.8 - Use After Free
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
CWE-502
Jan 02, 2019
CVE-2018-14721
10.0
CRITICAL
2 PoCs
Analysis
EPSS 0.09
FasterXML jackson-databind <2.9.7 - SSRF
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
CWE-918
Jan 02, 2019
CVE-2018-20318
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.00
.weixin-java-tools <3.2.0 - Info Disclosure
An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file.
CWE-611
Dec 21, 2018
CVE-2018-14718
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.15
FasterXML Jackson <2.9.7 - Code Injection
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
CWE-502
Jan 02, 2019
CVE-2018-14720
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.03
FasterXML Jackson <2.9.7 - SSRF
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
CWE-502
Jan 02, 2019
CVE-2018-14719
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.03
FasterXML Jackson <2.9.7 - RCE
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
CWE-502
Jan 02, 2019
CVE-2018-1000125
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.00
inversoft prime-jwt <1.3.0 - Info Disclosure
inversoft prime-jwt version prior to version 1.3.0 or prior to commit 0d94dcef0133d699f21d217e922564adbb83a227 contains an input validation vulnerability in JWTDecoder.decode that can result in a JWT that is decoded and thus implicitly validated even if it lacks a valid signature. This attack appear to be exploitable via an attacker crafting a token with a valid header and body and then requests it to be validated. This vulnerability appears to have been fixed in 1.3.0 and later or after commit 0d94dcef0133d699f21d217e922564adbb83a227.
CWE-20
Mar 13, 2018
CVE-2018-1273
9.8
CRITICAL
KEV
RANSOMWARE
10 PoCs
Analysis
NUCLEI
EPSS 0.94
Pivotal Software Spring Data Commons < 1.12.10 - Code Injection
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
CWE-94
Apr 11, 2018
CVE-2018-11307
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.12
Fasterxml Jackson-databind < 2.6.7.3 - Insecure Deserialization
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
CWE-502
Jul 09, 2019
CVE-2018-13379
9.1
CRITICAL
KEV
RANSOMWARE
14 PoCs
Analysis
NUCLEI
EPSS 0.94
Fortinet Fortiproxy < 1.2.9 - Path Traversal
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
CWE-22
Jun 04, 2019
CVE-2018-11736
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.12
Pluck < 4.7.7 - Unrestricted File Upload
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.
CWE-434
Jun 05, 2018
CVE-2018-17254
9.8
CRITICAL
EXPLOITED
5 PoCs
Analysis
NUCLEI
EPSS 0.85
JCK Editor <6.4.4 - SQL Injection
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
CWE-89
Sep 20, 2018
CVE-2018-14324
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Oracle GlassFish Open Source Edition 5.0 - Info Disclosure
The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This allows remote attackers to obtain potentially sensitive information, perform database operations, or manipulate the demo via a JMX RMI session, aka a "jmx_rmi remote monitoring and control problem." NOTE: this is not an Oracle supported product.
CWE-798
Jul 16, 2018