Critical Vulnerabilities with Public Exploits
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,103 results
Clear all
CVE-2018-3783
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Flintcms < 1.1.9 - SQL Injection
A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in password reset.
CWE-89
Aug 17, 2018
CVE-2018-14699
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.69
Drobo 5N2 NAS <4.0.5-13.28.96115 - Command Injection
System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter.
CWE-78
Dec 03, 2018
CVE-2018-12463
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.22
Fortify SSC <18.1 - SSRF
An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
CWE-611
Jul 12, 2018
CVE-2018-14009
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.50
Codiad <2.8.4 - RCE
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
CWE-20
Jul 12, 2018
CVE-2018-16809
9.8
CRITICAL
1 PoC
EPSS 0.01
Dolibarr <7.0.0 - SQL Injection
An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit.
CWE-89
Mar 07, 2019
CVE-2018-1285
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.72
Apache Log4net < 2.0.10 - XXE
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
CWE-611
May 11, 2020
CVE-2018-20148
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.55
WordPress <4.9.9, 5.x <5.0.1 - Code Injection
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.
CWE-502
Dec 14, 2018
CVE-2018-9356
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Google Android - Double Free
In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74950468.
CWE-415
Nov 06, 2018
CVE-2018-3744
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Html-pages - Path Traversal
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
CWE-22
May 29, 2018
CVE-2018-2879
9.0
CRITICAL
3 PoCs
Analysis
EPSS 0.44
Oracle Fusion Middleware 11.1.2.3.0-12.2.1.3.0 - Unauthenticated RCE
Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Authentication Engine). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. Note: Please refer to Doc ID <a href="http://support.oracle.com/CSP/main/article?cmd=show&type=NOT&id=2386496.1">My Oracle Support Note 2386496.1 for instructions on how to address this issue. CVSS 3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Apr 19, 2018
CVE-2018-3810
9.8
CRITICAL
EXPLOITED
4 PoCs
Analysis
NUCLEI
EPSS 0.92
Oturia Smart Google Code Inserter < 3.5 - Authentication Bypass
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code.
CWE-287
Jan 01, 2018
CVE-2018-3245
9.8
CRITICAL
4 PoCs
Analysis
EPSS 0.91
Oracle WebLogic Server <12.2.1.3 - RCE
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CWE-502
Oct 17, 2018
CVE-2018-15152
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.09
OpenEMR <5.0.1.4 - Auth Bypass
Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.php, (4) portal/get_amendments.php, (5) portal/get_lab_results.php, (6) portal/get_medications.php, (7) portal/get_patient_documents.php, (8) portal/get_problems.php, (9) portal/get_profile.php, (10) portal/portal_payment.php, (11) portal/messaging/messages.php, (12) portal/messaging/secure_chat.php, (13) portal/report/pat_ledger.php, (14) portal/report/portal_custom_report.php, or (15) portal/report/portal_patient_report.php without authenticating as a patient.
CWE-287
Aug 15, 2018
CVE-2018-16167
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.87
Jpcert Logontracer < 1.2.0 - OS Command Injection
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
CWE-78
Jan 09, 2019
CVE-2018-3811
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.31
Oturia Smart Google Code Inserter < 3.5 - SQL Injection
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL queries in the context of the web server. The saveGoogleAdWords() function in smartgooglecode.php did not use prepared statements and did not sanitize the $_POST["oId"] variable before passing it as input into the SQL query.
CWE-89
Jan 01, 2018
CVE-2018-16283
9.8
CRITICAL
2 PoCs
Analysis
NUCLEI
EPSS 0.77
Wechat Brodcast < 1.2.0 - Path Traversal
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
CWE-22
Sep 24, 2018
CVE-2018-9208
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.15
Tuyoshi Jquery Picture Cut - Unrestricted File Upload
Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1Beta
CWE-434
Nov 05, 2018
CVE-2018-9207
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.29
Hayageek Jquery Upload File < 4.0.2 - Unrestricted File Upload
Arbitrary file upload in jQuery Upload File <= 4.0.2
CWE-434
Nov 19, 2018
CVE-2018-13797
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Node-macaddress < 0.2.9 - OS Command Injection
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
CWE-78
Jul 10, 2018
CVE-2018-16492
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Extend < 2.0.2 - Denial of Service
A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.
CWE-74
Feb 01, 2019