Critical Vulnerabilities with Public Exploits
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2017-16930
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.54
Claymore Dual GPU miner 10.1 - RCE
The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the request handler. This can be exploited via a long API request that is mishandled during logging.
CWE-119
Dec 05, 2017
CVE-2017-17111
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.18
Posty Readymade Classifieds Script 1.0 - SQL Injection
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request.
CWE-89
Dec 11, 2017
CVE-2017-17110
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.18
Techno Portfolio Management Panel 1.0 - SQL Injection
Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.
CWE-89
Dec 11, 2017
CVE-2017-17055
9.0
CRITICAL
1 PoC
Analysis
EPSS 0.04
Artica Web Proxy <3.06.112911 - XSS
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php.
CWE-78
Dec 07, 2017
CVE-2017-9430
9.8
CRITICAL
4 PoCs
Analysis
EPSS 0.15
dnstracer <1.9 - DoS
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a command line with a long name argument that is mishandled in a strcpy call for argv[0]. An example threat model is a web application that launches dnstracer with an untrusted name string.
CWE-119
Jun 05, 2017
CVE-2017-9097
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.10
Anti-Web <3.8.7 - Path Traversal
In Anti-Web through 3.8.7, as used on NetBiter FGW200 devices through 3.21.2, WS100 devices through 3.30.5, EC150 devices through 1.40.0, WS200 devices through 3.30.4, EC250 devices through 1.40.0, and other products, an LFI vulnerability allows a remote attacker to read or modify files through a path traversal technique, as demonstrated by reading the password file, or using the template parameter to cgi-bin/write.cgi to write to an arbitrary file.
CWE-22
Jun 16, 2017
CVE-2017-16934
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.18
DBL DBLTek - RCE
The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and then using this password for the HTTP Basic Authentication needed for a change_password.csp request, which supports a "<%%25call system.exec:" string in the passwd parameter.
CWE-78
Nov 24, 2017
CVE-2017-16780
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
MyBB <1.8.13 - RCE
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
CWE-352
Nov 10, 2017
CVE-2017-16935
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.07
Ametys <4.0.3 - Auth Bypass
Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to bypass intended access restrictions via a direct request to /plugins/core-ui/servercomm/messages.xml, as demonstrated by changing the admin password by obtaining account details via a users/search.json request, and then modifying the account via an editUser request.
CWE-20
Nov 24, 2017
CVE-2017-16543
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Zoho ManageEngine Applications Manager <13 - SQL Injection
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
CWE-89
Nov 05, 2017
CVE-2017-11309
9.6
CRITICAL
1 PoC
Analysis
EPSS 0.25
Avaya IP Office < 10.1.1 - Memory Corruption
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.
CWE-119
Nov 10, 2017
CVE-2017-16562
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
EPSS 0.48
UserPro plugin <4.9.17.1 - Auth Bypass
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log parameter in the QUERY_STRING to the default URI.
CWE-287
Nov 10, 2017
CVE-2017-16561
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Ingenious School Management System 2.3.0 - SQL Injection
/view/friend_profile.php in Ingenious School Management System 2.3.0 is vulnerable to Boolean-based and Time-based SQL injection in the 'friend_index' parameter of a GET request.
CWE-89
Nov 07, 2017
CVE-2017-14491
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.58
dnsmasq <2.78 - Buffer Overflow
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
CWE-787
Oct 04, 2017
CVE-2017-15993
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Zomato Clone Script - SQL Injection
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.
CWE-89
Oct 31, 2017
CVE-2017-15992
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Website Broker Script - SQL Injection
Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.
CWE-89
Oct 31, 2017
CVE-2017-15991
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Vastal Agent Zone - SQL Injection
Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type, city, or bedroom parameter, a different vulnerability than CVE-2008-3951, CVE-2009-3497, and CVE-2012-0982.
CWE-89
Oct 31, 2017
CVE-2017-15990
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.09
Savsofteproducts Phpinventory - Unrestricted File Upload
Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
CWE-434
Oct 31, 2017
CVE-2017-15989
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Online Exam Test Application - SQL Injection
Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.
CWE-89
Oct 31, 2017
CVE-2017-15988
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Nicephpscripts Nice Php Faq Script - SQL Injection
Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525.
CWE-89
Oct 31, 2017