Critical Vulnerabilities with Public Exploits

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,432 CVEs tracked 53,633 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,306 vendors 43,872 researchers
4,101 results Clear all
CVE-2018-6576 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Ezcode Event Manager - SQL Injection
SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.
CWE-89 Feb 02, 2018
CVE-2018-6575 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Jextn Classified - SQL Injection
SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request.
CWE-89 Feb 02, 2018
CVE-2018-6398 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Joomlacalendars Event Calendar - SQL Injection
SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action.
CWE-89 Jan 30, 2018
CVE-2018-6395 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Joomlacalendars Visual Calendar - SQL Injection
SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action.
CWE-89 Jan 30, 2018
CVE-2018-6367 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Vastal I-tech Buddy Zone Facebook Clone - SQL Injection
SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parameter or the /search_events.php category parameter.
CWE-89 Jan 29, 2018
CVE-2018-6365 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Datacomponents Tsitebuilder - SQL Injection
SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php.
CWE-89 Jan 29, 2018
CVE-2018-6364 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Multilanguage Real Estate Mlm Script < 3.0 - SQL Injection
SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
CWE-89 Jan 29, 2018
CVE-2018-6363 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Taskrabbit Clone - SQL Injection
SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter.
CWE-89 Jan 29, 2018
CVE-2018-5997 9.8 CRITICAL 1 PoC Analysis EPSS 0.33
RAVPower Filehub <2.000.056 - RCE
An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal vulnerability, it is possible to upload a file on a filesystem with root privileges: this will lead to remote code execution as root.
CWE-22 Jan 25, 2018
CVE-2018-5973 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Professional Local Directory Script 1.0 - SQL Injection
SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryID or CategoryID parameter.
CWE-89 Jan 25, 2018
CVE-2018-5988 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Flexible Poll 1.2 - SQL Injection
SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php.
CWE-89 Jan 24, 2018
CVE-2018-5986 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Easy Car Script 2014 - SQL Injection
SQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php.
CWE-89 Jan 24, 2018
CVE-2018-5985 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
LiveCRM SaaS Cloud 1.0 - SQL Injection
SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request.
CWE-89 Jan 24, 2018
CVE-2018-5984 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Tumder 2.1 - Joomla! - SQL Injection
SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI.
CWE-89 Jan 24, 2018
CVE-2018-5979 9.8 CRITICAL 1 PoC Analysis EPSS 0.05
Wchat Fully Responsive PHP AJAX Chat Script 1.5 - SQL Injection
SQL Injection exists in Wchat Fully Responsive PHP AJAX Chat Script 1.5 via the login.php User field.
CWE-89 Jan 24, 2018
CVE-2018-5978 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Facebook Style Php Ajax Chat Zechat 1.5 - SQL Injection
SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.
CWE-89 Jan 24, 2018
CVE-2018-5977 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Affiligator Affiliate Webshop Mgmt Sys <2.1.0 - SQL Injection
SQL Injection exists in Affiligator Affiliate Webshop Management System 2.1.0 via a search/?q=&price_type=range&price= request.
CWE-89 Jan 24, 2018
CVE-2018-5972 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Classified Ads CMS Quickad 4.0 - SQL Injection
SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI.
CWE-89 Jan 24, 2018
CVE-2018-5726 9.8 CRITICAL 1 PoC Analysis EPSS 0.58
MASTER IPCAMERA01 <3.3.4.2103 - Info Disclosure
MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request, as demonstrated by the username, password, and configuration settings.
CWE-200 Jan 16, 2018
CVE-2018-5724 9.8 CRITICAL 1 PoC Analysis EPSS 0.39
MASTER IPCAMERA01 <3.3.4.2103 - Info Disclosure
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi.
CWE-434 Jan 16, 2018