Critical Vulnerabilities with Public Exploits
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2017-14942
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.01
Intelbras WRN 150 - Authentication Bypass
Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg containing an admin:language=pt cookie.
CWE-552
Sep 30, 2017
CVE-2017-6622
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.31
Cisco Prime Collaboration Provisioning - Missing Authorization
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraints in certain HTTP request methods, which could allow access to files via the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases prior to 12.1. Cisco Bug IDs: CSCvc98724.
CWE-862
May 18, 2017
CVE-2017-20216
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
EPSS 0.01
FLIR Thermal Camera PT-Series <8.0.0.64 - Command Injection
FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple unauthenticated remote command injection vulnerabilities in the controllerFlirSystem.php script. Attackers can execute arbitrary system commands as root by exploiting unsanitized POST parameters in the execFlirSystem() function through shell_exec() calls. Exploitation evidence was observed by the Shadowserver Foundation on 2026-01-06 (UTC).
CWE-78
Jan 08, 2026
CVE-2017-11282
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.21
Adobe Flash Player < 26.0.0.151 - Memory Corruption
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
CWE-119
Dec 01, 2017
CVE-2017-11281
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.61
Adobe Flash Player < 26.0.0.151 - Memory Corruption
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
CWE-119
Dec 01, 2017
CVE-2017-11120
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.24
Broadcom Bcm4355c0 Firmware < 11.0 - Memory Corruption
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor report frame to trigger an internal buffer overflow in the Wi-Fi firmware, aka B-V2017061204.
CWE-119
Sep 28, 2017
CVE-2017-9417
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.31
BCM43xx - RCE
Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.
Jun 04, 2017
CVE-2017-14703
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Cash Back Comparison Script 1.0 - SQL Injection
SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/.
CWE-89
Sep 26, 2017
CVE-2017-14702
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.12
ERS Data System <1.8.1.0 - Code Injection
ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.UpdateRequest" object deserialization.
CWE-502
Sep 30, 2017
CVE-2017-14244
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.51
iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 - Auth Bypass
An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and /password.cgi.
CWE-425
Sep 17, 2017
CVE-2017-7912
9.8
CRITICAL
1 PoC
EPSS 0.01
Hanwhasecurity Srn-4000 Firmware - Improper Access Control
Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges without proper authentication.
CWE-284
Apr 08, 2019
CVE-2017-14507
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.08
Content Timeline plugin 4.4.2 - SQL Injection
Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timeline_edit.php or (3) pages/content_timeline_index.php.
CWE-89
Sep 29, 2017
CVE-2017-14243
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.60
UTStar WA3002G4 ADSL Broadband Modem - Auth Bypass
An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administrative settings and obtain cleartext credentials from HTML source, as demonstrated by info.cgi, upload.cgi, backupsettings.cgi, pppoe.cgi, resetrouter.cgi, and password.cgi.
CWE-287
Sep 17, 2017
CVE-2017-11435
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.20
Humaxdigital Hg100r Firmware - Information Disclosure
The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console. The bug is exploitable remotely when the router is configured to expose the management console. The router is not validating the session token while returning answers for some methods in url '/api'. An attacker can use this vulnerability to retrieve sensitive information such as private/public IP addresses, SSID names, and passwords.
CWE-200
Jul 19, 2017
CVE-2017-6315
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.09
Sophos Astaro Security Gateway Firmware - Improper Input Validation
Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx.
CWE-20
Sep 19, 2017
CVE-2017-14396
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
osTicket <1.10.1 - SQL Injection
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.
CWE-89
Sep 12, 2017
CVE-2017-14147
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.73
FiberHome User End Router AN1020-25 - Info Disclosure
An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its factory settings by simply browsing to the link http://[Default-Router-IP]/restoreinfo.cgi & execute it. Due to improper authentication on this page, the software accepts the request hence allowing attacker to reset the router to its default configurations which later could allow attacker to login to router by using default username/password.
CWE-287
Sep 07, 2017
CVE-2017-12965
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.22
Apache2Triad 1.5.4 - Info Disclosure
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
CWE-384
Aug 23, 2017
CVE-2017-12759
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Ynetinteractive Soa School Management - SQL Injection
Ynet Interactive - http://demo.ynetinteractive.com/soa/ SOA School Management 3.0 is affected by: SQL Injection. The impact is: Code execution (remote).
CWE-89
May 09, 2019
CVE-2017-12758
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Joomlaextensions Component Appointment - SQL Injection
https://www.joomlaextensions.co.in/ Joomla! Component Appointment 1.1 is affected by: SQL Injection. The impact is: Code execution (remote). The component is: com_appointment component.
CWE-89
May 09, 2019