Critical Vulnerabilities with Public Exploits
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2018-6228
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Trendmicro Email Encryption Gateway - SQL Injection
A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.
CWE-89
Mar 15, 2018
CVE-2018-6223
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.05
Trendmicro Email Encryption Gateway - Missing Authentication
A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate the registration process of the product to reset configuration parameters.
CWE-306
Mar 15, 2018
CVE-2018-6220
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.10
Trendmicro Email Encryption Gateway - Injection
An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to gaining code execution on vulnerable systems.
CWE-74
Mar 15, 2018
CVE-2018-7319
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
OS Property Real Estate - SQL Injection
SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter.
CWE-89
Feb 22, 2018
CVE-2018-7318
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.25
Belitsoft Checklist - SQL Injection
SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order parameter.
CWE-89
Feb 22, 2018
CVE-2018-7316
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Christianwebministries Proclaim - Unrestricted File Upload
Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.
CWE-434
Feb 22, 2018
CVE-2018-7315
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Harmistechnology EK Rishta - SQL Injection
SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, caste, or country parameter.
CWE-89
Feb 22, 2018
CVE-2018-7314
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.91
Mlwebtechnologies Prayercenter - SQL Injection
SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429.
CWE-89
Feb 22, 2018
CVE-2018-7312
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Alexandriabooklibrary Alexandria Book Library - SQL Injection
SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter.
CWE-89
Feb 22, 2018
CVE-2018-7313
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Cwjoomla CW Tags - SQL Injection
SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.
CWE-89
Feb 22, 2018
CVE-2018-25221
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
EChat Server 3.1 Buffer Overflow via chat.ghp username Parameter
EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplying an oversized username parameter. Attackers can send a GET request to chat.ghp with a malicious username value containing shellcode and ROP gadgets to achieve code execution in the application context.
CWE-787
Mar 28, 2026
CVE-2018-13818
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Symfony Twig < 2.4.4 - Code Injection
Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the responsibility of web applications using Twig to properly wrap input to it
CWE-94
Jul 10, 2018
CVE-2018-6024
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Joomla! Project Log 1.5.3 - SQL Injection
SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter.
CWE-89
Feb 18, 2018
CVE-2018-7180
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Saxum2003 Astro - SQL Injection
SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter.
CWE-89
Feb 17, 2018
CVE-2018-7179
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Squadmanagement - SQL Injection
SQL Injection exists in the SquadManagement 1.0.3 component for Joomla! via the id parameter.
CWE-89
Feb 17, 2018
CVE-2018-7178
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Saxum2003 Saxum Picker - SQL Injection
SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter.
CWE-89
Feb 17, 2018
CVE-2018-7177
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Saxum2003 Numerology - SQL Injection
SQL Injection exists in the Saxum Numerology 3.0.4 component for Joomla! via the publicid parameter.
CWE-89
Feb 17, 2018
CVE-2018-6585
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Techjoomla Jticketing - SQL Injection
SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or filter_events_cat parameter.
CWE-89
Feb 17, 2018
CVE-2018-6584
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Dthdevelopment DT Register - SQL Injection
SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request.
CWE-89
Feb 17, 2018
CVE-2018-6583
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Quanticalabs Timetable Responsive Schedule - SQL Injection
SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request.
CWE-89
Feb 17, 2018