Critical Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,417 CVEs tracked 53,633 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,306 vendors 43,872 researchers
4,101 results Clear all
CVE-2017-9232 9.8 CRITICAL 2 PoCs Analysis EPSS 0.82
Juju <2.1.3 - Privilege Escalation
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.
CWE-862 May 28, 2017
CVE-2017-7722 10.0 CRITICAL 1 PoC Analysis EPSS 0.50
SolarWinds LEM <6.3.1 Hotfix 4 - RCE
In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker can escape from the restricted shell.
CWE-77 Apr 12, 2017
CVE-2017-6526 9.8 CRITICAL 2 PoCs Analysis EPSS 0.84
Dnatools Dnalims - Authentication Bypass
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected administrative web shell (cgi-bin/dna/sysAdmin.cgi POST requests).
CWE-287 Mar 09, 2017
CVE-2017-1000487 9.8 CRITICAL 3 PoCs Analysis EPSS 0.08
Plexus-utils <3.0.16 - Command Injection
Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.
CWE-78 Jan 03, 2018
CVE-2017-17485 9.8 CRITICAL 5 PoCs Analysis EPSS 0.85
Fasterxml Jackson-databind < 2.6.7.3 - Insecure Deserialization
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.
CWE-502 Jan 10, 2018
CVE-2017-15095 9.8 CRITICAL 2 PoCs Analysis EPSS 0.09
jackson-databind <2.8.10, 2.9.1 - Code Injection
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.
CWE-184 Feb 06, 2018
CVE-2017-5929 9.8 CRITICAL 2 PoCs Analysis EPSS 0.10
QOS Logback < 1.2.0 - Insecure Deserialization
QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
CWE-502 Mar 13, 2017
CVE-2017-5941 9.8 CRITICAL 9 PoCs Analysis EPSS 0.78
Node-serialize < 0.0.4 - Insecure Deserialization
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).
CWE-502 Feb 09, 2017
CVE-2017-12149 9.8 CRITICAL KEV RANSOMWARE 12 PoCs Analysis NUCLEI EPSS 0.94
Jboss Application Server - Code Injection
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
CWE-502 Oct 04, 2017
CVE-2017-7679 9.8 CRITICAL 4 PoCs Analysis EPSS 0.30
Apache httpd <2.2.33, <2.4.26 - Buffer Overflow
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.
CWE-119 Jun 20, 2017
CVE-2017-12611 9.8 CRITICAL EXPLOITED 6 PoCs Analysis NUCLEI EPSS 0.94
Apache Struts < 2.3.34 - Improper Input Validation
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
CWE-20 Sep 20, 2017
CVE-2017-12865 9.8 CRITICAL 1 PoC Analysis EPSS 0.04
Intel Connman < 1.34 - Memory Corruption
Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted response query string passed to the "name" variable.
CWE-119 Aug 29, 2017
CVE-2017-12629 9.8 CRITICAL 2 PoCs Analysis NUCLEI EPSS 0.94
Apache Solr < 5.5.4 - XXE
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for any query request with parameters deftype=xmlparser and can be exploited to upload malicious data to the /upload request handler or as Blind XXE using ftp wrapper in order to read arbitrary local files from the Solr server. Note also that the second vulnerability relates to remote code execution using the RunExecutableListener available on all affected versions of Solr.
CWE-611 Oct 14, 2017
CVE-2017-17761 9.8 CRITICAL EXPLOITED 2 PoCs Analysis EPSS 0.05
Ichano AtHome IP Camera - Command Injection
An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. This binary requires the "system" XML element for specifying the command. For example, a <system>id</system> command results in a <system_ack>ok</system_ack> response.
Dec 19, 2017
CVE-2017-11165 9.8 CRITICAL 2 PoCs Analysis NUCLEI EPSS 0.91
Datataker Dt80 Dex Firmware - Information Disclosure
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.
CWE-200 Jul 12, 2017
CVE-2017-7504 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.90
Jboss <4.X - Code Injection
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized data.
CWE-502 May 19, 2017
CVE-2017-7410 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
WebsiteBaker <2.10.0 - SQL Injection
Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username, (2) display_name parameter.
CWE-89 Apr 03, 2017
CVE-2017-16720 9.8 CRITICAL 2 PoCs Analysis EPSS 0.22
WebAccess <8.3.2 - Path Traversal
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the target device.
CWE-22 Jan 05, 2018
CVE-2017-3066 9.8 CRITICAL KEV 3 PoCs Analysis EPSS 0.94
Adobe Coldfusion - Insecure Deserialization
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.
CWE-502 Apr 27, 2017
CVE-2017-3169 9.8 CRITICAL 2 PoCs Analysis EPSS 0.33
Apache HTTP Server - NULL Pointer Dereference
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.
CWE-476 Jun 20, 2017