Critical Vulnerabilities with Public Exploits
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2018-9126
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.82
Zldnn Dnnarticle - Information Disclosure
The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credentials, via the /GetCSS.ashx/?CP=%2fweb.config URI.
CWE-200
Apr 04, 2018
CVE-2018-9248
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.69
Fiberhome Vdsl2 Modem HG 150-ub Firmware - Authentication Bypass
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
CWE-287
Apr 04, 2018
CVE-2018-9032
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.86
Dlink Dir-850l Firmware < 2.06 - Authentication Bypass
An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version : 1.02-2.06) devices potentially allows attackers to bypass SharePort Web Access Portal by directly visiting /category_view.php or /folder_view.php.
CWE-287
Mar 27, 2018
CVE-2018-7300
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.12
Eq-3 Homematic Ccu2 Firmware < 2.29.22 - Path Traversal
Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to write arbitrary files to the device's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
CWE-22
Feb 22, 2018
CVE-2018-7297
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
EPSS 0.59
Eq-3 Homematic Central Control Unit C... - Remote Code Execution
Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access and execute system commands on the device. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
Feb 22, 2018
CVE-2018-9148
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Westerndigital MY Cloud Firmware - Authentication Bypass
Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. NOTE: this can be exploited in conjunction with CVE-2018-7171 for remote authentication bypass within a product that uses My Cloud.
CWE-287
Mar 30, 2018
CVE-2018-25223
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Crashmail 1.6 Stack-based Buffer Overflow Remote Code Execution
Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.
CWE-787
Mar 28, 2026
CVE-2018-9162
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Contec-touch Smart Home Firmware - Missing Authentication
Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by changing the admin password and then obtaining control over doors.
CWE-306
Mar 31, 2018
CVE-2018-4879
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.30
Adobe Acrobat < 17.011.30070 - Out-of-Bounds Write
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion module that processes Enhanced Metafile Format Plus (EMF+) data. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.
CWE-787
Feb 27, 2018
CVE-2018-7702
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.37
SecurEnvoy SecurMail <9.2.501 - RCE
SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e-mail messages to arbitrary recipients, or modify arbitrary message bodies and attachments by leveraging missing authentication and authorization.
CWE-862
Mar 15, 2018
CVE-2018-7538
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.12
Enalean Tuleap < 9.18 - SQL Injection
A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 allows attackers to execute arbitrary SQL commands.
CWE-89
Mar 12, 2018
CVE-2018-9161
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.55
Prismaindustriale Checkweigher Prismaweb - Hard-coded Credentials
Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account by reading user/scripts/login_par.js.
CWE-798
Mar 31, 2018
CVE-2018-7756
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.34
DEWESoft X3 SP1 (64-bit) - RCE
RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP port 1999, which allows remote attackers to execute arbitrary code or access internal commands, as demonstrated by a RUN command that launches a .EXE file located at an arbitrary external URL, or a "SETFIREWALL Off" command.
CWE-94
Mar 15, 2018
CVE-2018-7474
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.17
Textpattern < 4.6.2 - SQL Injection
An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php.
CWE-89
Mar 14, 2018
CVE-2018-6396
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.08
Google Map Landkarten < 4.2.3 - SQL Injection
SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or the map parameter in a layout=default action.
CWE-89
Feb 17, 2018
CVE-2018-7739
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.09
antsle antman <0.9.1a - Auth Bypass
antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and password parameters, as demonstrated by a username=>&password=%0a string to the /login URI. This allows obtaining root permissions within the web management console, because the login process uses Java's ProcessBuilder class and a bash script called antsle-auth with insufficient input validation.
CWE-20
Mar 07, 2018
CVE-2018-7264
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.13
Activepdf Toolkit < 8.1.0.19023 - Out-of-Bounds Write
The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF Toolkit to process untrusted images.
CWE-787
Feb 28, 2018
CVE-2018-7477
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
School Management Script - SQL Injection
SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/Parent_module/parent_login.php.
CWE-89
Feb 28, 2018
CVE-2018-5999
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.91
AsusWRT <3.0.0.4.384_10007 - Info Disclosure
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication fails.
Jan 22, 2018
CVE-2018-6229
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Trendmicro Email Encryption Gateway - SQL Injection
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.
CWE-89
Mar 15, 2018