Critical Vulnerabilities with Public Exploits
Updated 47m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,103 results
Clear all
CVE-2018-17383
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Joomla! - SQL Injection
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.
CWE-89
Sep 28, 2018
CVE-2018-17382
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Jobs Factory 2.0.4 - SQL Injection
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
CWE-89
Sep 28, 2018
CVE-2018-17380
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Article Factory Manager 4.3.9 - SQL Injection
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.
CWE-89
Sep 28, 2018
CVE-2018-17379
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Raffle Factory 3.5.2 - SQL Injection
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
CWE-89
Sep 28, 2018
CVE-2018-17378
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Penny Auction Factory 2.0.4 - SQL Injection
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.
CWE-89
Sep 28, 2018
CVE-2018-17377
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Joomla! 1.4.3 - SQL Injection
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
CWE-89
Sep 28, 2018
CVE-2018-17376
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Joomla! Reverse Auction Factory 4.3.8 - SQL Injection
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.
CWE-89
Sep 28, 2018
CVE-2018-17375
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Music Collection 3.0.3 - SQL Injection
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
CWE-89
Sep 28, 2018
CVE-2018-17386
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Micro Deal Factory 2.4.0 - SQL Injection
SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.
CWE-89
Jun 19, 2019
CVE-2018-17374
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Auction Factory 4.5.5 - SQL Injection
SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.
CWE-89
Jun 19, 2019
CVE-2018-17398
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
AMGallery 1.2.3 - SQL Injection
SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter.
CWE-89
Jun 19, 2019
CVE-2018-14592
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
CWJoomla <2.0.7, <1.0.6 - SQL Injection
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.
CWE-89
Sep 20, 2018
CVE-2018-25254
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
NICO-FTP 3.0.1.19 Buffer Overflow SEH
NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.
CWE-787
Apr 04, 2026
CVE-2018-15691
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.42
Broadcom Release Automation < 6.3.0.9945 - Insecure Deserialization
Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.
CWE-502
Aug 30, 2018
CVE-2018-1000802
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.22
Python Software Foundation Python <2.7 - Command Injection
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace.
CWE-77
Sep 18, 2018
CVE-2018-10575
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
WatchGuard AP100-AP200 <1.2.9.15 - Info Disclosure
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged SSH account with a shell of /bin/false.
CWE-798
Apr 30, 2018
CVE-2018-16669
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
CIRCONTROL OCPP <1.5.0 - Info Disclosure
An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML files, an unprivileged user can look at /services/config/config.xml for the admin credentials of the ocpp and circarlife panels.
CWE-522
Sep 18, 2018
CVE-2018-16836
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.90
Rubedo <3.4.0 - Path Traversal
Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI.
CWE-22
Sep 11, 2018
CVE-2018-12634
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.92
CirCarLife Scada <4.3 - Info Disclosure
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI.
CWE-200
Jun 22, 2018
CVE-2018-16370
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Pescms Team - Unrestricted File Upload
In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a ZIP archive.
CWE-434
Sep 03, 2018