Critical Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,391 CVEs tracked 53,627 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,294 vendors 43,856 researchers
4,101 results Clear all
CVE-2017-3061 9.8 CRITICAL 1 PoC Analysis EPSS 0.54
Adobe Flash Player < 25.0.0.127 - Memory Corruption
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser. Successful exploitation could lead to arbitrary code execution.
CWE-119 Apr 12, 2017
CVE-2017-8798 9.8 CRITICAL 1 PoC Analysis EPSS 0.23
Miniupnpd - Memory Corruption
Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
CWE-119 May 11, 2017
CVE-2017-11502 9.8 CRITICAL 1 PoC Analysis EPSS 0.10
Technicolor DPC3928AD - Info Disclosure
Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321.
CWE-200 Jul 20, 2017
CVE-2017-7312 9.8 CRITICAL 1 PoC Analysis EPSS 0.08
Personify360 e-Business <7.6.1 - Info Disclosure
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords).
CWE-269 Jun 07, 2017
CVE-2017-2800 9.8 CRITICAL 1 PoC Analysis EPSS 0.09
Wolfssl < 3.10.2 - Improper Certificate Validation
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial of service and possible remote code execution. In order to trigger this vulnerability, the attacker needs to supply a malicious x509 certificate to either a server or a client application using this library.
CWE-295 May 24, 2017
CVE-2017-5135 9.1 CRITICAL 1 PoC Analysis EPSS 0.22
Technicolor DPC3928SL - Auth Bypass
Certain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. The Technicolor (formerly Cisco) DPC3928SL with firmware D3928SL-P15-13-A386-c3420r55105-160127a could be reached by any SNMP community string from the Internet; also, you can write in the MIB because it provides write properties, aka Stringbleed. NOTE: the string-bleed/StringBleed-CVE-2017-5135 GitHub repository is not a valid reference as of 2017-04-27; it contains Trojan horse code purported to exploit this vulnerability.
Apr 27, 2017
CVE-2017-3549 9.1 CRITICAL 1 PoC Analysis EPSS 0.31
Oracle E-Business Suite <12.2.6 - RCE
Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Scripting accessible data as well as unauthorized access to critical data or complete access to all Oracle Scripting accessible data. CVSS 3.0 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
CWE-89 Apr 24, 2017
CVE-2017-8051 9.8 CRITICAL 1 PoC Analysis EPSS 0.53
Tenable Appliance - OS Command Injection
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.
CWE-78 Apr 21, 2017
CVE-2017-7588 9.8 CRITICAL 1 PoC Analysis EPSS 0.17
Brother Devices - Auth Bypass
On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW MFC-J4620DW MFC-L8850CDW MFC-J3720 MFC-J6520DW MFC-L2740DW MFC-J5910DW MFC-J6920DW MFC-L2700DW MFC-9130CW MFC-9330CDW MFC-9340CDW MFC-J5620DW MFC-J6720DW MFC-L8600CDW MFC-L9550CDW MFC-L2720DW DCP-L2540DW DCP-L2520DW HL-3140CW HL-3170CDW HL-3180CDW HL-L8350CDW HL-L2380DW ADS-2500W ADS-1000W ADS-1500W.
CWE-287 Apr 12, 2017
CVE-2017-7462 9.8 CRITICAL 1 PoC Analysis EPSS 0.11
Intellinet NFC-30ir IP Camera - RCE
Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.
CWE-22 Apr 11, 2017
CVE-2017-6361 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.91
Qnap Qts < 4.2.4 - OS Command Injection
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
CWE-78 Mar 23, 2017
CVE-2017-6360 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.80
Qnap Qts < 4.2.4 - OS Command Injection
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
CWE-78 Mar 23, 2017
CVE-2017-6359 9.8 CRITICAL 1 PoC Analysis EPSS 0.61
Qnap Qts < 4.2.4 - OS Command Injection
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.
CWE-78 Mar 23, 2017
CVE-2017-2641 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Moodle < 2.7.19 - SQL Injection
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
CWE-89 Mar 26, 2017
CVE-2017-7237 9.8 CRITICAL 1 PoC Analysis EPSS 0.13
Spiceworks Inventory <7.5 - Path Traversal
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directory by leveraging the unauthenticated nature of the TFTP service for all clients who can reach UDP port 69, as demonstrated by a WRQ (aka Write request) operation for a configuration file or an executable file.
Apr 06, 2017
CVE-2017-0561 9.8 CRITICAL 2 PoCs Analysis EPSS 0.39
Linux Kernel - Out-of-Bounds Write
A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due to the possibility of remote code execution in the context of the Wi-Fi SoC. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34199105. References: B-RB#110814.
CWE-787 Apr 07, 2017
CVE-2017-14459 10.0 CRITICAL 1 PoC Analysis EPSS 0.20
Moxa AWK-3131A <1.7 - OS Command Injection
An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client in firmware versions 1.4 to 1.7 (current). An attacker can inject commands via the username parameter of several services (SSH, Telnet, console), resulting in remote, unauthenticated, root-level operating system command execution.
CWE-78 Apr 11, 2018
CVE-2017-7402 9.8 CRITICAL 1 PoC Analysis EPSS 0.09
Pixie 1.0.4 - Command Injection
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.
CWE-94 Apr 03, 2017
CVE-2017-5005 9.8 CRITICAL 1 PoC Analysis EPSS 0.31
Quick Heal Internet Security <10.1.0.316 - Buffer Overflow
Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows remote attackers to execute arbitrary code via a crafted LC_UNIXTHREAD.cmdsize field in a Mach-O file that is mishandled during a Security Scan (aka Custom Scan) operation.
CWE-787 Jan 02, 2017
CVE-2017-5404 9.8 CRITICAL 1 PoC Analysis EPSS 0.21
Debian Linux < 45.8.0 - Use After Free
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
CWE-416 Jun 11, 2018