Critical Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,391 CVEs tracked 53,627 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,294 vendors 43,856 researchers
4,101 results Clear all
CVE-2017-3077 9.8 CRITICAL 1 PoC Analysis EPSS 0.54
Adobe Flash Player < 25.0.0.171 - Memory Corruption
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. Successful exploitation could lead to arbitrary code execution.
CWE-119 Jun 20, 2017
CVE-2017-3076 9.8 CRITICAL 1 PoC Analysis EPSS 0.54
Adobe Flash Player < 25.0.0.171 - Memory Corruption
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC module. Successful exploitation could lead to arbitrary code execution.
CWE-119 Jun 20, 2017
CVE-2017-8543 9.8 CRITICAL KEV 1 PoC Analysis EPSS 0.85
Microsoft Windows 10 1507 - Remote Code Execution
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to take control of the affected system when Windows Search fails to handle objects in memory, aka "Windows Search Remote Code Execution Vulnerability".
CWE-281 Jun 15, 2017
CVE-2017-9602 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
KBVault Mysql Free Knowledge Base <0.16a - RCE
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this functionality, a user can upload an ASPX script to Uploads/Documents/ to run any arbitrary code.
CWE-732 Jun 16, 2017
CVE-2017-4914 9.8 CRITICAL 1 PoC Analysis EPSS 0.13
VMware VDP <6.1 - Deserialization
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.
CWE-502 Jun 07, 2017
CVE-2017-9730 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
nuevoMailer <6.0 - SQL Injection
SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the "r" parameter.
CWE-89 Jun 19, 2017
CVE-2017-11471 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
IDERA Uptime Monitor 7.8 - SQL Injection
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter.
CWE-89 Jul 20, 2017
CVE-2017-6542 9.8 CRITICAL 1 PoC Analysis EPSS 0.22
Putty < 0.67 - Memory Corruption
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect to the Unix-domain socket representing the forwarded agent connection, which trigger a buffer overflow.
CWE-119 Mar 27, 2017
CVE-2017-8837 9.8 CRITICAL 1 PoC Analysis EPSS 0.11
Peplink B305hw2 Firmware - Insufficiently Protected Credentials
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass and /etc/roapass. In case one of these devices is compromised, the attacker can gain access to passwords and abuse them to compromise further systems.
CWE-522 Jun 05, 2017
CVE-2017-5815 9.8 CRITICAL 1 PoC Analysis EPSS 0.59
HP Intelligent Management Center < 7.3 - Improper Input Validation
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
CWE-20 Feb 15, 2018
CVE-2017-18346 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Cms Web-gooroo < 2013-01-19 - SQL Injection
SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows remote attackers to execute arbitrary SQL commands via the wbg_login parameter.
CWE-89 Jul 03, 2019
CVE-2017-20225 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
TiEmu 2.08 Stack-Based Buffer Overflow Vulnerability
TiEmu 2.08 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can trigger the overflow through command-line arguments passed to the application, leveraging ROP gadgets to bypass protections and execute shellcode in the application context.
CWE-787 Mar 28, 2026
CVE-2017-9426 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Piwigo Facetag <0.0.3 - SQL Injection
ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action.
CWE-89 Feb 26, 2018
CVE-2017-5465 9.1 CRITICAL 1 PoC Analysis EPSS 0.23
Debian Linux < 45.9.0 - Out-of-Bounds Read
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
CWE-125 Jun 11, 2018
CVE-2017-5447 9.1 CRITICAL 1 PoC Analysis EPSS 0.17
Debian Linux < 45.9.0 - Use After Free
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
CWE-416 Jun 11, 2018
CVE-2017-2527 9.8 CRITICAL 1 PoC Analysis EPSS 0.09
Apple Mac OS X < 10.12.4 - Memory Corruption
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "CoreAnimation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption and application crash) via crafted data.
CWE-119 May 22, 2017
CVE-2017-2524 9.8 CRITICAL 1 PoC Analysis EPSS 0.18
Apple Iphone OS < 10.3.2 - Memory Corruption
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "TextInput" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data.
CWE-119 May 22, 2017
CVE-2017-2523 9.8 CRITICAL 1 PoC Analysis EPSS 0.13
Apple Iphone OS < 10.3.2 - Memory Corruption
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Foundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data.
CWE-119 May 22, 2017
CVE-2017-2522 9.8 CRITICAL 1 PoC Analysis EPSS 0.13
Apple Iphone OS < 10.3.2 - Memory Corruption
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreFoundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data.
CWE-119 May 22, 2017
CVE-2017-12930 9.8 CRITICAL 2 PoCs Analysis EPSS 0.03
Tecnovision Dlx Spot Player4 - SQL Injection
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users to access the web interface as administrator via a crafted password.
CWE-89 Sep 21, 2017