Critical Vulnerabilities with Public Exploits

Updated 10m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,417 CVEs tracked 53,633 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,306 vendors 43,872 researchers
4,101 results Clear all
CVE-2017-0807 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Android <7.1.2 - Privilege Escalation
An elevation of privilege vulnerability in the Android framework (ui framework). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35056974.
Oct 04, 2017
CVE-2017-17976 9.8 CRITICAL 1 PoC Analysis EPSS 0.17
Perfexcrm Perfex Crm - Unrestricted File Upload
In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.
CWE-434 Jan 26, 2018
CVE-2017-17999 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Fairsketch Rise Ultimate Project Manager - SQL Injection
SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to index.php/knowledge_base/get_article_suggestion/.
CWE-89 Jan 23, 2018
CVE-2017-17970 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Muviko - SQL Injection
Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to login.php; the (2) season_id parameter to themes/flixer/ajax/load_season.php; the (3) movie_id parameter to themes/flixer/ajax/get_rating.php; the (4) rating or (5) movie_id parameter to themes/flixer/ajax/update_rating.php; or the (6) id parameter to themes/flixer/ajax/set_player_source.php.
CWE-89 Jan 12, 2018
CVE-2017-16887 9.8 CRITICAL 1 PoC Analysis EPSS 0.04
FiberHome Mobile WIFI Device - Info Disclosure
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can result in disclosure of the WLAN key/password.
CWE-275 Jan 12, 2018
CVE-2017-16885 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
FiberHome LM53Q1 VH519R05C01S38 - Info Disclosure
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to look for the information without authenticating. The information includes Version of device, Firmware ID, Connected users to device along their MAC Addresses, etc.
CWE-732 Jan 12, 2018
CVE-2017-17098 9.8 CRITICAL 1 PoC Analysis EPSS 0.31
GPS Tracking Software <3.0 - Code Injection
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.
CWE-94 Jan 02, 2018
CVE-2017-17097 9.8 CRITICAL 1 PoC Analysis EPSS 0.37
GPS Tracking Software 2.x - Info Disclosure
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php.
CWE-640 Jan 02, 2018
CVE-2017-20223 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Telesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference
Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resources by manipulating user-supplied input parameters. Attackers can directly reference objects in the system to retrieve sensitive information and access functionalities without proper access controls.
CWE-639 Mar 16, 2026
CVE-2017-18001 9.8 CRITICAL 1 PoC Analysis EPSS 0.21
Trustwave Secure Web Gateway < 11.8.0.27 - Missing Authentication
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI.
CWE-306 Dec 31, 2017
CVE-2017-17875 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Jextn Faq Pro - SQL Injection
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
CWE-89 Dec 27, 2017
CVE-2017-17759 9.8 CRITICAL 1 PoC Analysis EPSS 0.13
Conarc Ichannel - Denial of Service
Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the configuration) via a wc.dll?wwMaint~EditConfig request (which reaches an older version of a West Wind Web Connection HTTP service).
Dec 19, 2017
CVE-2017-17721 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
Zuuse Beims Contractorweb .net - SQL Injection
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter.
CWE-89 Dec 18, 2017
CVE-2017-14097 9.8 CRITICAL 1 PoC Analysis EPSS 0.16
Trend Micro Smart Protection Server <3.2 - Info Disclosure
An improper access control vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to decrypt contents of a database with information that could be used to access a vulnerable system.
Jan 19, 2018
CVE-2017-14094 9.8 CRITICAL 1 PoC Analysis EPSS 0.56
Trend Micro Smart Protection Server <3.2 - Command Injection
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a cron job injection on a vulnerable system.
CWE-78 Jan 19, 2018
CVE-2017-17739 9.8 CRITICAL 1 PoC Analysis EPSS 0.21
Brightsign 4k242 Firmware < 6.2.63 - Path Traversal
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.
CWE-22 Dec 18, 2017
CVE-2017-15708 9.8 CRITICAL 1 PoC Analysis EPSS 0.20
Apache Synapse < 3.0.1 - Injection
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous versions in Synapse distribution makes this exploitable. To mitigate the issue, we need to limit RMI access to trusted users only. Further upgrading to 3.0.1 version will eliminate the risk of having said Commons Collection version. In Synapse 3.0.1, Commons Collection has been updated to 3.2.2 version.
CWE-74 Dec 11, 2017
CVE-2017-18025 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Innotube Itguard Manager - OS Command Injection
cgi-bin/drknow.cgi in Innotube ITGuard-Manager 0.0.0.1 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the username field, as demonstrated by a username beginning with "admin|" to use the '|' metacharacter.
CWE-78 Jan 09, 2018
CVE-2017-17651 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Paid TO Read Script - SQL Injection
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.
CWE-89 Dec 18, 2017
CVE-2017-17645 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Phpautoclassifiedscript Bus Booking Script - SQL Injection
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
CWE-89 Dec 18, 2017