Critical Vulnerabilities with Public Exploits

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,432 CVEs tracked 53,633 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,306 vendors 43,872 researchers
4,101 results Clear all
CVE-2018-6394 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Techjoomla Invitex - SQL Injection
SQL Injection exists in the InviteX 3.0.5 component for Joomla! via the invite_type parameter in a view=invites action.
CWE-89 Feb 17, 2018
CVE-2018-6373 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Fastball - SQL Injection
SQL Injection exists in the Fastball 2.5 component for Joomla! via the season parameter in a view=player action.
CWE-89 Feb 17, 2018
CVE-2018-6372 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Joombooking JB Bus - SQL Injection
SQL Injection exists in the JB Bus 2.3 component for Joomla! via the order_number parameter.
CWE-89 Feb 17, 2018
CVE-2018-6370 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Neojoomla Neorecruit - SQL Injection
SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under the all-offers/ URI.
CWE-89 Feb 17, 2018
CVE-2018-6368 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Comdev Jomestate Pro < 3.7 - SQL Injection
SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action.
CWE-89 Feb 17, 2018
CVE-2018-6006 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
JS Autoz 1.0.9 - SQL Injection
SQL Injection exists in the JS Autoz 1.0.9 component for Joomla! via the vtype, pre, or prs parameter.
CWE-89 Feb 17, 2018
CVE-2018-6005 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Realpin <1.5.04 - SQL Injection
SQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter.
CWE-89 Feb 17, 2018
CVE-2018-6004 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Joomla! File Download Tracker 3.0 - SQL Injection
SQL Injection exists in the File Download Tracker 3.0 component for Joomla! via the dynfield[phone] or sess parameter.
CWE-89 Feb 17, 2018
CVE-2018-5994 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
JS Jobs 1.1.9 - SQL Injection
SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or the ta parameter in a view_resume request.
CWE-89 Feb 17, 2018
CVE-2018-5993 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Joomla! - SQL Injection
SQL Injection exists in the Aist through 2.0 component for Joomla! via the id parameter in a view=showvacancy request.
CWE-89 Feb 17, 2018
CVE-2018-5992 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Joomla! <1.0 RC 1 - SQL Injection
SQL Injection exists in the Staff Master through 1.0 RC 1 component for Joomla! via the name parameter in a view=staff request.
CWE-89 Feb 17, 2018
CVE-2018-5991 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Joomla! Form Maker 3.6.12 - SQL Injection
SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerability than CVE-2015-2798.
CWE-89 Feb 17, 2018
CVE-2018-5990 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
AllVideos Reloaded <1.2.x - SQL Injection
SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter.
CWE-89 Feb 17, 2018
CVE-2018-5989 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
ccNewsletter 2.x - Joomla! - SQL Injection
SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011-5099.
CWE-89 Feb 17, 2018
CVE-2018-5987 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Pinterest Clone Social Pinboard 2.0 - SQL Injection
SQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id parameter in a task=getlikeinfo action, the ends parameter in a view=gift action, the category parameter in a view=home action, the uid parameter in a view=pindisplay action, the searchVal parameter in a view=search action, or the uid parameter in a view=likes action.
CWE-89 Feb 17, 2018
CVE-2018-5983 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Joomla! - SQL Injection
SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request.
CWE-89 Feb 17, 2018
CVE-2018-5982 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Advertisement Board 3.1.0 - Joomla! - SQL Injection
SQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= request.
CWE-89 Feb 17, 2018
CVE-2018-5981 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Gallery WD 1.3.6 - SQL Injection
SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter.
CWE-89 Feb 17, 2018
CVE-2018-5980 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Solidres 2.5.1 - SQL Injection
SQL Injection exists in the Solidres 2.5.1 component for Joomla! via the direction parameter in a hub.search action.
CWE-89 Feb 17, 2018
CVE-2018-5975 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Joomla! Smart Shoutbox 3.0.0 - SQL Injection
SQL Injection exists in the Smart Shoutbox 3.0.0 component for Joomla! via the shoutauthor parameter to the archive URI.
CWE-89 Feb 17, 2018