Critical Vulnerabilities with Public Exploits

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,468 CVEs tracked 53,663 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,324 vendors 43,878 researchers
4,103 results Clear all
CVE-2018-25138 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
FLIR AX8 Thermal Camera 1.32.16 - Auth Bypass
FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent credentials to gain unauthorized shell access and login to multiple camera interfaces using predefined username and password combinations.
CWE-798 Dec 24, 2025
CVE-2018-18322 9.8 CRITICAL 1 PoC Analysis EPSS 0.16
Webpanel - OS Command Injection
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, or service_stop parameter.
CWE-78 Oct 15, 2018
CVE-2018-10824 9.8 CRITICAL 1 PoC Analysis EPSS 0.44
Dlink Dwr-116 Firmware < 1.06 - Path Traversal
An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. The administrative password is stored in plaintext in the /tmp/csman/0 file. An attacker having a directory traversal (or LFI) can easily get full router access.
CWE-22 Oct 17, 2018
CVE-2018-12596 9.8 CRITICAL 2 PoCs Analysis EPSS 0.41
Episerver Ektron Cms - Improper Privilege Management
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via the "activateuser.aspx" page, even if a page is located under the /WorkArea/ path, which is forbidden (normally available exclusively for local admins).
CWE-269 Oct 10, 2018
CVE-2018-18075 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Wikidforum - SQL Injection
WikidForum 2.20 has SQL Injection via the rpc.php parent_post_id or num_records parameter, or the index.php?action=search select_sort parameter.
CWE-89 Oct 09, 2018
CVE-2018-19646 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Imperva SecureSphere <13.2.10 - Command Injection
The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands because command-line arguments are mishandled.
CWE-78 Nov 28, 2018
CVE-2018-17440 9.8 CRITICAL 1 PoC Analysis EPSS 0.15
D-Link Central WiFi Manager <1.03r0100-Beta1 - RCE
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin). Taking advantage of this, a remote unauthenticated attacker could execute arbitrary PHP code by uploading any file in the web root directory and then accessing it via a request.
CWE-434 Oct 08, 2018
CVE-2018-17988 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Layerbb - SQL Injection
LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter.
CWE-89 Mar 07, 2019
CVE-2018-17399 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Jimtawl 2.2.7 - SQL Injection
SQL Injection exists in the Jimtawl 2.2.7 component for Joomla! via the id parameter.
CWE-89 Jun 19, 2019
CVE-2018-17428 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
OPAC EasyWeb Five <5.7 - SQL Injection
An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter.
CWE-89 Oct 03, 2018
CVE-2018-17842 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Scriptzee Hotel Booking Engine 1.0 - SQL Injection
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
CWE-89 Jun 19, 2019
CVE-2018-17840 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Scriptzee Education Website 1.0 - SQL Injection
SQL injection exists in Scriptzee Education Website 1.0 via the college_list.html subject, city, or country parameter.
CWE-89 Jun 19, 2019
CVE-2018-17843 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
ADD Clicking MLM Software <1.0 - SQL Injection
SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM Software 1.0, Autopool MLM Software 1.0, Investment MLM Software 1.0, Bidding MLM Software 1.0, Moneyorder MLM Software 1.0, Repurchase MLM Software 1.0, and Gift MLM Software 1.0 via the member/readmsg.php msg_id parameter, the member/tree.php pid parameter, or the member/downline.php m_id parameter.
CWE-89 May 24, 2019
CVE-2018-16659 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Rausoft ID.prove <2.95 - SQL Injection
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. Hypothetically, an attacker can utilize master..xp_cmdshell for the further privilege elevation.
CWE-89 Sep 28, 2018
CVE-2018-17381 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Dutch Auction Factory 2.0.2 - SQL Injection
SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
CWE-89 Jun 19, 2019
CVE-2018-17397 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
AlphaIndex Dictionaries <1.0 - SQL Injection
SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.
CWE-89 Sep 28, 2018
CVE-2018-17394 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Joomla! Timetable Schedule <3.6.8 - SQL Injection
SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.
CWE-89 Sep 28, 2018
CVE-2018-17391 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Super Cms Blog Pro 1.0 - SQL Injection
SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.
CWE-89 Sep 28, 2018
CVE-2018-17385 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Social Factory 3.8.3 - SQL Injection
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.
CWE-89 Sep 28, 2018
CVE-2018-17384 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Swap Factory 2.2.1 - SQL Injection
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
CWE-89 Sep 28, 2018