Critical Vulnerabilities with Public Exploits

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,468 CVEs tracked 53,663 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,324 vendors 43,878 researchers
4,103 results Clear all
CVE-2018-9355 9.8 CRITICAL 1 PoC Analysis EPSS 0.08
Google Android - Out-of-Bounds Write
In bta_dm_sdp_result of bta_dm_act.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74016921.
CWE-787 Nov 06, 2018
CVE-2018-20433 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Mchange C3p0 < 0.9.5.3 - XXE
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
CWE-611 Dec 24, 2018
CVE-2018-19987 9.8 CRITICAL 1 PoC Analysis EPSS 0.82
D-Link DIR-* - Command Injection
D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, and DIR-890L Rev.A 1.21B02_BETA devices mishandle IsAccessPoint in /HNAP1/SetAccessPointMode. In the SetAccessPointMode.php source code, the IsAccessPoint parameter is saved in the ShellPath script file without any regex checking. After the script file is executed, the command injection occurs. A vulnerable /HNAP1/SetAccessPointMode XML message could have shell metacharacters in the IsAccessPoint element such as the `telnetd` string.
CWE-78 May 13, 2019
CVE-2018-20555 9.8 CRITICAL 1 PoC Analysis EPSS 0.45
Designchemical Social Network Tabs - Information Disclosure
The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover.
CWE-200 Mar 21, 2019
CVE-2018-12421 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
LTB Self Service Password <1.3 - Auth Bypass
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string.
CWE-640 Jun 14, 2018
CVE-2018-5353 9.8 CRITICAL 1 PoC Analysis EPSS 0.15
Zoho ManageEngine ADSelfService Plus <5.5.5517 - Privilege Escalation
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required
CWE-290 Sep 30, 2020
CVE-2018-11311 9.1 CRITICAL 2 PoCs Analysis EPSS 0.36
Myscada Mypro - Hard-coded Credentials
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.
CWE-798 May 20, 2018
CVE-2018-3786 9.8 CRITICAL 1 PoC Analysis EPSS 0.10
Eggjs Egg-scripts < 2.8.1 - Command Injection
A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command line argument.
CWE-78 Aug 24, 2018
CVE-2018-10388 9.8 CRITICAL 1 PoC Analysis EPSS 0.18
TFTP Server <1.66 - RCE
Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.
CWE-134 Dec 23, 2019
CVE-2018-1160 9.8 CRITICAL 4 PoCs Analysis EPSS 0.90
Netatalk <3.1.12 - RCE
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
CWE-787 Dec 20, 2018
CVE-2018-19466 9.8 CRITICAL 1 PoC Analysis EPSS 0.13
Portainer <1.20.0 - Info Disclosure
A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master password, in cleartext and allows their retrieval via API calls.
CWE-522 Mar 27, 2019
CVE-2018-18649 9.8 CRITICAL 1 PoC Analysis EPSS 0.55
Gitlab < 11.3.8 - Remote Code Execution
An issue was discovered in the wiki API in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for remote code execution.
Nov 29, 2018
CVE-2018-10653 9.8 CRITICAL 1 PoC Analysis EPSS 0.11
Citrix XenMobile Server <10.8 - XSS
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
CWE-611 May 23, 2018
CVE-2018-9022 9.8 CRITICAL 1 PoC Analysis EPSS 0.20
Broadcom Privileged Access Manager - Improper Privilege Management
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file.
CWE-269 Jun 18, 2018
CVE-2018-12798 9.8 CRITICAL 1 PoC Analysis EPSS 0.24
Adobe Acrobat and Reader <2018.011.20040 - RCE
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
CWE-787 Jul 20, 2018
CVE-2018-14442 9.8 CRITICAL 2 PoCs Analysis EPSS 0.05
Foxit Reader <9.2 - PhantomPDF <9.2 - Use After Free
Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
CWE-416 Jul 20, 2018
CVE-2018-7251 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.91
Anchor < 0.12.7 - Information Disclosure
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.
CWE-200 Feb 19, 2018
CVE-2018-14667 9.8 CRITICAL KEV 6 PoCs Analysis EPSS 0.89
RichFaces Framework 3.X-3.3.4 - Code Injection
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
CWE-94 Nov 06, 2018
CVE-2018-25159 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Epross AVCON6 - Command Injection
Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting malicious OGNL expressions. Attackers can send crafted requests to the login.action endpoint with OGNL payloads in the redirect parameter to instantiate ProcessBuilder objects and execute system commands with root privileges.
CWE-1334 Mar 11, 2026
CVE-2018-20718 9.8 CRITICAL 1 PoC Analysis EPSS 0.09
Pydio < 8.2.2 - Insecure Deserialization
In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs a "public link" of a file, or access to any unprivileged user account for creation of such a link.
CWE-502 Jan 15, 2019