Critical Vulnerabilities with Public Exploits
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2018-13862
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.61
Touchpad / Trivum WebTouch Setup V9 V2.53 - Auth Bypass
Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attackers to reset the authentication via the "/xml/system/setAttribute.xml" URL, using the GET request "?id=0&attr=protectAccess&newValue=0" (a successful attack will allow attackers to login without authorization).
Jul 17, 2018
CVE-2018-13784
9.1
CRITICAL
3 PoCs
Analysis
EPSS 0.50
PrestaShop <1.6.1.20 & <1.7.3.4 - Info Disclosure
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.
Jul 09, 2018
CVE-2018-14064
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.77
VelotiSmart WiFi B-380 - Path Traversal
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../../etc/passwd on TCP port 80.
CWE-22
Jul 15, 2018
CVE-2018-15137
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.27
CeLa Link CLR-M20 - RCE
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it is possible to upload arbitrary files by utilizing the PUT method.
CWE-434
Aug 08, 2018
CVE-2018-13981
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.37
Zeta-producer Zeta Producer Desktop Cms - Unrestricted File Upload
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default component that permits arbitrary upload of PHP files, because the formmailer widget blocks .php files but not .php5 or .phtml files. This is related to /assets/php/formmailer/SendEmail.php and /assets/php/formmailer/functions.php.
CWE-434
Jul 16, 2018
CVE-2018-14012
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
WolfSight CMS 3.2 - SQL Injection
WolfSight CMS 3.2 allows SQL injection via the PATH_INFO to the default URI.
CWE-89
Jul 12, 2018
CVE-2018-10718
10.0
CRITICAL
1 PoC
Analysis
EPSS 0.58
Activision Call OF Duty Modern Warfare 2 - Out-of-Bounds Write
Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary code via crafted packets.
CWE-787
May 03, 2018
CVE-2018-12908
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.20
Brynamics - Information Disclosure
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for the /dashboard/deposit URI, as demonstrated by discovering database credentials.
CWE-200
Jun 27, 2018
CVE-2018-12984
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.04
Hycus Cms - Authentication Bypass
Hycus CMS 1.0.4 allows Authentication Bypass via "'=' 'OR'" credentials.
CWE-287
Jun 29, 2018
CVE-2018-12706
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.19
DIGISOL DG-BR4000NG - Buffer Overflow
DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.
CWE-119
Jun 24, 2018
CVE-2018-12689
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
phpLDAPadmin 1.2.2 - SQL Injection
phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.
Jun 22, 2018
CVE-2018-12630
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
NEWMARK NMCMS 2.1 - SQL Injection
NEWMARK (aka New Mark) NMCMS 2.1 allows SQL Injection via the sect_id parameter to the /catalog URI.
CWE-89
Jun 21, 2018
CVE-2018-12327
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.16
NTP 4.2.8p11 - Buffer Overflow
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argument for an IPv4 or IPv6 command-line parameter. NOTE: It is unclear whether there are any common situations in which ntpq or ntpdc is used with a command line from an untrusted source.
CWE-787
Jun 20, 2018
CVE-2018-12292
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Pale Moon <27.9.3 - Use After Free
A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
CWE-416
Jun 13, 2018
CVE-2018-11652
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.22
Nikto <2.1.6 - Command Injection
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.
CWE-1236
Jun 01, 2018
CVE-2018-10969
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.19
Genetechsolutions Pie Register < 3.0.10 - SQL Injection
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.
CWE-89
Jun 17, 2018
CVE-2018-12055
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
PHP Scripts Mall Schools Alert Mgmt - SQL Injection
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php, about.php, photo_gallery.php, privacy.php, and so on.
CWE-89
Jun 08, 2018
CVE-2018-12052
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
PHP Scripts Mall Schools Alert Mgt - SQL Injection
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
CWE-89
Jun 08, 2018
CVE-2018-10088
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.89
XiongMai uc-httpd 1.0.0 - Buffer Overflow
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.
CWE-119
Jun 08, 2018
CVE-2018-11544
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Theolivetree FTP Server - Insufficiently Protected Credentials
The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences.xml file as the prefUsername and prefUserpass strings.
CWE-522
May 29, 2018