Critical Vulnerabilities with Public Exploits

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,432 CVEs tracked 53,633 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,306 vendors 43,872 researchers
4,101 results Clear all
CVE-2018-7584 9.8 CRITICAL 1 PoC Analysis EPSS 0.83
Php < 5.6.33 - Memory Corruption
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. This subsequently results in copying a large string.
CWE-119 Mar 01, 2018
CVE-2018-11586 9.8 CRITICAL 1 PoC Analysis EPSS 0.33
Searchblox - SSRF
XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
CWE-611 Jun 05, 2018
CVE-2018-6411 9.8 CRITICAL 1 PoC Analysis EPSS 0.11
Machform - Unrestricted File Upload
An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.
CWE-434 May 26, 2018
CVE-2018-6410 9.8 CRITICAL 1 PoC Analysis EPSS 0.08
Machform - SQL Injection
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
CWE-89 May 26, 2018
CVE-2018-25154 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
GNU Barcode 0.99 - Buffer Overflow
GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system.
CWE-787 Dec 24, 2025
CVE-2018-11535 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Sitemakin Slac - SQL Injection
An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.php is exploitable using SQL injection.
CWE-89 May 29, 2018
CVE-2018-11523 9.8 CRITICAL 1 PoC Analysis EPSS 0.21
Nuuo Nvrmini 2 Firmware < 3.6.5 - Unrestricted File Upload
upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
CWE-434 May 29, 2018
CVE-2018-11444 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Easyservice Billing - SQL Injection
A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.
CWE-89 May 25, 2018
CVE-2018-5159 9.8 CRITICAL 1 PoC Analysis EPSS 0.38
Skia - Buffer Overflow
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
CWE-190 Jun 11, 2018
CVE-2018-8898 9.8 CRITICAL 1 PoC Analysis EPSS 0.15
D-Link DSL-3782 - Auth Bypass
A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer="TT_77616E6771696F6E67") allows unauthenticated attackers to perform arbitrary modification (read, write) to passwords and configurations meanwhile an administrator is logged into the web panel.
CWE-287 May 23, 2018
CVE-2018-11094 9.8 CRITICAL 1 PoC Analysis EPSS 0.56
Intelbras Ncloud 300 Firmware - Hard-coded Credentials
An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. For example, when an HTTP POST request is made to /cgi-bin/ExportSettings.sh, the username, password, and other details are retrieved.
CWE-798 May 15, 2018
CVE-2018-10757 9.8 CRITICAL 1 PoC Analysis EPSS 0.04
Csp Mysql User Manager - SQL Injection
CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt.
CWE-89 May 05, 2018
CVE-2018-10561 9.8 CRITICAL KEV RANSOMWARE 1 PoC Analysis EPSS 0.93
Dasan GPON - Auth Bypass
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.
CWE-287 May 04, 2018
CVE-2018-9302 9.1 CRITICAL 1 PoC Analysis EPSS 0.11
Cockpit < 0.5.5 - SSRF
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14611, which was about version 0.13.0, which (surprisingly) is an earlier version than 0.4.4.
CWE-918 May 02, 2018
CVE-2018-9245 9.8 CRITICAL 1 PoC Analysis EPSS 0.12
Ericssonlg Ipecs Nms - SQL Injection
The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the login page and execute remote code on the operating system.
CWE-89 Apr 22, 2018
CVE-2018-10285 9.8 CRITICAL 1 PoC Analysis EPSS 0.41
Ericsson-LG iPECS NMS A.1Ac - Auth Bypass
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attacker might bypass authentication.
CWE-732 Apr 22, 2018
CVE-2018-8057 9.8 CRITICAL 1 PoC Analysis EPSS 0.05
Western Bridge Cobub Razor 0.8.0 - SQL Injection
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/addchannel request, related to /application/controllers/manage/channel.php.
CWE-89 Mar 11, 2018
CVE-2018-6546 9.8 CRITICAL 2 PoCs Analysis EPSS 0.43
Plays.tv < 1.27.7.0 - Authentication Bypass
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, executes code at a user-defined (local or SMB) path as SYSTEM when the execute_installer parameter is used in an HTTP message. This occurs without properly authenticating the user.
CWE-287 Apr 13, 2018
CVE-2018-1217 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.66
Dell Emc Avamar - Missing Authorization
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the Local Download Service (LDLS) credentials. The LDLS credentials are used to connect to Dell EMC Online Support. If the LDLS configuration was changed to an invalid configuration, then Avamar Installation Manager may not be able to connect to Dell EMC Online Support web site successfully. The remote unauthenticated attacker can also read and use the credentials to login to Dell EMC Online Support, impersonating the AVI service actions using those credentials.
CWE-862 Apr 09, 2018
CVE-2018-9843 9.8 CRITICAL 1 PoC Analysis EPSS 0.09
Cyberark Password Vault < 9.9.5 - Insecure Deserialization
The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serialized .NET object in an Authorization HTTP header.
CWE-502 Apr 12, 2018