Critical Vulnerabilities with Public Exploits
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,103 results
Clear all
CVE-2018-9355
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.08
Google Android - Out-of-Bounds Write
In bta_dm_sdp_result of bta_dm_act.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74016921.
CWE-787
Nov 06, 2018
CVE-2018-20433
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Mchange C3p0 < 0.9.5.3 - XXE
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
CWE-611
Dec 24, 2018
CVE-2018-19987
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.82
D-Link DIR-* - Command Injection
D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, and DIR-890L Rev.A 1.21B02_BETA devices mishandle IsAccessPoint in /HNAP1/SetAccessPointMode. In the SetAccessPointMode.php source code, the IsAccessPoint parameter is saved in the ShellPath script file without any regex checking. After the script file is executed, the command injection occurs. A vulnerable /HNAP1/SetAccessPointMode XML message could have shell metacharacters in the IsAccessPoint element such as the `telnetd` string.
CWE-78
May 13, 2019
CVE-2018-20555
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.45
Designchemical Social Network Tabs - Information Disclosure
The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover.
CWE-200
Mar 21, 2019
CVE-2018-12421
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
LTB Self Service Password <1.3 - Auth Bypass
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string.
CWE-640
Jun 14, 2018
CVE-2018-5353
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.15
Zoho ManageEngine ADSelfService Plus <5.5.5517 - Privilege Escalation
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required
CWE-290
Sep 30, 2020
CVE-2018-11311
9.1
CRITICAL
2 PoCs
Analysis
EPSS 0.36
Myscada Mypro - Hard-coded Credentials
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.
CWE-798
May 20, 2018
CVE-2018-3786
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.10
Eggjs Egg-scripts < 2.8.1 - Command Injection
A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command line argument.
CWE-78
Aug 24, 2018
CVE-2018-10388
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.18
TFTP Server <1.66 - RCE
Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.
CWE-134
Dec 23, 2019
CVE-2018-1160
9.8
CRITICAL
4 PoCs
Analysis
EPSS 0.90
Netatalk <3.1.12 - RCE
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
CWE-787
Dec 20, 2018
CVE-2018-19466
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.13
Portainer <1.20.0 - Info Disclosure
A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master password, in cleartext and allows their retrieval via API calls.
CWE-522
Mar 27, 2019
CVE-2018-18649
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.55
Gitlab < 11.3.8 - Remote Code Execution
An issue was discovered in the wiki API in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for remote code execution.
Nov 29, 2018
CVE-2018-10653
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Citrix XenMobile Server <10.8 - XSS
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
CWE-611
May 23, 2018
CVE-2018-9022
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.20
Broadcom Privileged Access Manager - Improper Privilege Management
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file.
CWE-269
Jun 18, 2018
CVE-2018-12798
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.24
Adobe Acrobat and Reader <2018.011.20040 - RCE
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
CWE-787
Jul 20, 2018
CVE-2018-14442
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.05
Foxit Reader <9.2 - PhantomPDF <9.2 - Use After Free
Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
CWE-416
Jul 20, 2018
CVE-2018-7251
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.91
Anchor < 0.12.7 - Information Disclosure
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.
CWE-200
Feb 19, 2018
CVE-2018-14667
9.8
CRITICAL
KEV
6 PoCs
Analysis
EPSS 0.89
RichFaces Framework 3.X-3.3.4 - Code Injection
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
CWE-94
Nov 06, 2018
CVE-2018-25159
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Epross AVCON6 - Command Injection
Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting malicious OGNL expressions. Attackers can send crafted requests to the login.action endpoint with OGNL payloads in the redirect parameter to instantiate ProcessBuilder objects and execute system commands with root privileges.
CWE-1334
Mar 11, 2026
CVE-2018-20718
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.09
Pydio < 8.2.2 - Insecure Deserialization
In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs a "public link" of a file, or access to any unprivileged user account for creation of such a link.
CWE-502
Jan 15, 2019