Critical Vulnerabilities with Public Exploits
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2017-16088
10.0
CRITICAL
1 PoC
Analysis
EPSS 0.02
safe-eval - Code Injection
The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.
CWE-610
Jun 07, 2018
CVE-2017-9830
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.09
Code42 CrashPlan <5.4 - RCE
Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiation) it creates an RMI server that listens on a TCP port and deserializes objects sent by TCP clients.
CWE-502
Jun 27, 2017
CVE-2017-17417
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.16
Quest NetVault Backup 11.3.0.12 - SQL Injection
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUPhaseStatus Acknowledge method requests. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the underlying database. Was ZDI-CAN-4228.
CWE-89
Feb 08, 2018
CVE-2017-18345
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.02
Joomanager < 2.0.0 - Information Disclosure
The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an index.php?option=com_joomanager&controller=details&task=download&path=configuration.php request.
CWE-200
Aug 26, 2018
CVE-2017-6026
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.19
Schneider Electric Modicon PLCs <4.0.5.11 - Info Disclosure
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The session numbers generated by the web application are lacking randomization and are shared between several users. This may allow a current session to be compromised.
CWE-330
Jun 30, 2017
CVE-2017-16082
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.71
Node-postgres PG < 2.11.2 - Code Injection
A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.
CWE-94
Jun 07, 2018
CVE-2017-6079
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
EPSS 0.32
Edgewater Networks Edgemarc - Command Injection
The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific iptables routes, etc., to be set. You can use this page as a web shell essentially to execute commands, though you get no feedback client-side from the web application: if the command is valid, it executes. An example is the wget command. The page that allows this has been confirmed in firmware as old as 2006.
May 16, 2017
CVE-2017-10366
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.64
Oracle PeopleSoft Products <8.57 - RCE
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Performance Monitor). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Oct 19, 2017
CVE-2017-15580
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.36
Osticket - Unrestricted File Upload
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a .exe extension. An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content.
CWE-434
Oct 23, 2017
CVE-2017-14493
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.05
dnsmasq <2.78 - Buffer Overflow
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.
CWE-119
Oct 03, 2017
CVE-2017-17849
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.35
Getgosoft Getgo Download Manager < 5.3.0.2712 - Memory Corruption
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response.
CWE-119
Dec 27, 2017
CVE-2017-5792
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.81
HP Intelligent Management Center - Insecure Deserialization
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
CWE-502
Feb 15, 2018
CVE-2017-11519
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.13
TP-Link Archer C9(UN) - Privilege Escalation
passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random number generator seed. This is fixed in C9(UN)_V2_170511.
CWE-335
Jul 21, 2017
CVE-2017-14322
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.26
Interspire Email Marketer <6.1.6 - Auth Bypass
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attackers to bypass authentication and obtain administrative access by using the IEM_CookieLogin cookie with a specially crafted value.
CWE-287
Oct 18, 2017
CVE-2017-1000474
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Soyket Chowdhury Vehicle Sales Management System 2017-07-30 - RCE
Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php, login/profile.php, login/Actions.php, login/manage_employee.php, and login/sell.php scripts resulting in the expose of user's login credentials, SQL Injection and Stored XSS vulnerability, which leads to remote code executing.
CWE-89
Jan 24, 2018
CVE-2017-5375
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.61
Thunderbird <45.7, Firefox ESR <45.7, Firefox <51 - Memory Corruption
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
CWE-119
Jun 11, 2018
CVE-2017-15367
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.22
Bacula-web < 7.4.0 - SQL Injection
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.
CWE-89
Mar 07, 2018
CVE-2017-10352
9.9
CRITICAL
1 PoC
Analysis
EPSS 0.28
Oracle Weblogic Server - Denial of Service
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). The supported version that is affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server as well as unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data and unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H).
Oct 19, 2017
CVE-2017-16716
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
WebAccess <8.3 - SQL Injection
A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.
CWE-89
Jan 05, 2018
CVE-2017-17612
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.04
Hot Scripts Clone - SQL Injection
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
CWE-89
Dec 13, 2017