Critical Vulnerabilities with Public Exploits
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2018-7584
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.83
Php < 5.6.33 - Memory Corruption
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. This subsequently results in copying a large string.
CWE-119
Mar 01, 2018
CVE-2018-11586
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.33
Searchblox - SSRF
XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
CWE-611
Jun 05, 2018
CVE-2018-6411
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Machform - Unrestricted File Upload
An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.
CWE-434
May 26, 2018
CVE-2018-6410
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.08
Machform - SQL Injection
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
CWE-89
May 26, 2018
CVE-2018-25154
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
GNU Barcode 0.99 - Buffer Overflow
GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system.
CWE-787
Dec 24, 2025
CVE-2018-11535
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Sitemakin Slac - SQL Injection
An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.php is exploitable using SQL injection.
CWE-89
May 29, 2018
CVE-2018-11523
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.21
Nuuo Nvrmini 2 Firmware < 3.6.5 - Unrestricted File Upload
upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
CWE-434
May 29, 2018
CVE-2018-11444
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Easyservice Billing - SQL Injection
A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.
CWE-89
May 25, 2018
CVE-2018-5159
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.38
Skia - Buffer Overflow
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
CWE-190
Jun 11, 2018
CVE-2018-8898
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.15
D-Link DSL-3782 - Auth Bypass
A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer="TT_77616E6771696F6E67") allows unauthenticated attackers to perform arbitrary modification (read, write) to passwords and configurations meanwhile an administrator is logged into the web panel.
CWE-287
May 23, 2018
CVE-2018-11094
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.56
Intelbras Ncloud 300 Firmware - Hard-coded Credentials
An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. For example, when an HTTP POST request is made to /cgi-bin/ExportSettings.sh, the username, password, and other details are retrieved.
CWE-798
May 15, 2018
CVE-2018-10757
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.04
Csp Mysql User Manager - SQL Injection
CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt.
CWE-89
May 05, 2018
CVE-2018-10561
9.8
CRITICAL
KEV
RANSOMWARE
1 PoC
Analysis
EPSS 0.93
Dasan GPON - Auth Bypass
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.
CWE-287
May 04, 2018
CVE-2018-9302
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.11
Cockpit < 0.5.5 - SSRF
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14611, which was about version 0.13.0, which (surprisingly) is an earlier version than 0.4.4.
CWE-918
May 02, 2018
CVE-2018-9245
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.12
Ericssonlg Ipecs Nms - SQL Injection
The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the login page and execute remote code on the operating system.
CWE-89
Apr 22, 2018
CVE-2018-10285
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.41
Ericsson-LG iPECS NMS A.1Ac - Auth Bypass
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attacker might bypass authentication.
CWE-732
Apr 22, 2018
CVE-2018-8057
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.05
Western Bridge Cobub Razor 0.8.0 - SQL Injection
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/addchannel request, related to /application/controllers/manage/channel.php.
CWE-89
Mar 11, 2018
CVE-2018-6546
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.43
Plays.tv < 1.27.7.0 - Authentication Bypass
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, executes code at a user-defined (local or SMB) path as SYSTEM when the execute_installer parameter is used in an HTTP message. This occurs without properly authenticating the user.
CWE-287
Apr 13, 2018
CVE-2018-1217
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.66
Dell Emc Avamar - Missing Authorization
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the Local Download Service (LDLS) credentials. The LDLS credentials are used to connect to Dell EMC Online Support. If the LDLS configuration was changed to an invalid configuration, then Avamar Installation Manager may not be able to connect to Dell EMC Online Support web site successfully. The remote unauthenticated attacker can also read and use the credentials to login to Dell EMC Online Support, impersonating the AVI service actions using those credentials.
CWE-862
Apr 09, 2018
CVE-2018-9843
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.09
Cyberark Password Vault < 9.9.5 - Insecure Deserialization
The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serialized .NET object in an Authorization HTTP header.
CWE-502
Apr 12, 2018