Critical Vulnerabilities with Public Exploits
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2018-6576
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Ezcode Event Manager - SQL Injection
SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.
CWE-89
Feb 02, 2018
CVE-2018-6575
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Jextn Classified - SQL Injection
SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request.
CWE-89
Feb 02, 2018
CVE-2018-6398
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Joomlacalendars Event Calendar - SQL Injection
SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action.
CWE-89
Jan 30, 2018
CVE-2018-6395
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Joomlacalendars Visual Calendar - SQL Injection
SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action.
CWE-89
Jan 30, 2018
CVE-2018-6367
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Vastal I-tech Buddy Zone Facebook Clone - SQL Injection
SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parameter or the /search_events.php category parameter.
CWE-89
Jan 29, 2018
CVE-2018-6365
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Datacomponents Tsitebuilder - SQL Injection
SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php.
CWE-89
Jan 29, 2018
CVE-2018-6364
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Multilanguage Real Estate Mlm Script < 3.0 - SQL Injection
SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
CWE-89
Jan 29, 2018
CVE-2018-6363
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Taskrabbit Clone - SQL Injection
SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter.
CWE-89
Jan 29, 2018
CVE-2018-5997
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.33
RAVPower Filehub <2.000.056 - RCE
An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal vulnerability, it is possible to upload a file on a filesystem with root privileges: this will lead to remote code execution as root.
CWE-22
Jan 25, 2018
CVE-2018-5973
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Professional Local Directory Script 1.0 - SQL Injection
SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryID or CategoryID parameter.
CWE-89
Jan 25, 2018
CVE-2018-5988
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Flexible Poll 1.2 - SQL Injection
SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php.
CWE-89
Jan 24, 2018
CVE-2018-5986
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Easy Car Script 2014 - SQL Injection
SQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php.
CWE-89
Jan 24, 2018
CVE-2018-5985
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
LiveCRM SaaS Cloud 1.0 - SQL Injection
SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request.
CWE-89
Jan 24, 2018
CVE-2018-5984
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Tumder 2.1 - Joomla! - SQL Injection
SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI.
CWE-89
Jan 24, 2018
CVE-2018-5979
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.05
Wchat Fully Responsive PHP AJAX Chat Script 1.5 - SQL Injection
SQL Injection exists in Wchat Fully Responsive PHP AJAX Chat Script 1.5 via the login.php User field.
CWE-89
Jan 24, 2018
CVE-2018-5978
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Facebook Style Php Ajax Chat Zechat 1.5 - SQL Injection
SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.
CWE-89
Jan 24, 2018
CVE-2018-5977
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Affiligator Affiliate Webshop Mgmt Sys <2.1.0 - SQL Injection
SQL Injection exists in Affiligator Affiliate Webshop Management System 2.1.0 via a search/?q=&price_type=range&price= request.
CWE-89
Jan 24, 2018
CVE-2018-5972
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Classified Ads CMS Quickad 4.0 - SQL Injection
SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI.
CWE-89
Jan 24, 2018
CVE-2018-5726
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.58
MASTER IPCAMERA01 <3.3.4.2103 - Info Disclosure
MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request, as demonstrated by the username, password, and configuration settings.
CWE-200
Jan 16, 2018
CVE-2018-5724
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.39
MASTER IPCAMERA01 <3.3.4.2103 - Info Disclosure
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi.
CWE-434
Jan 16, 2018