Critical Vulnerabilities with Public Exploits

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,391 CVEs tracked 53,627 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,294 vendors 43,856 researchers
4,101 results Clear all
CVE-2017-3195 9.8 CRITICAL 1 PoC Analysis EPSS 0.46
Commvault Edge - Memory Corruption
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.
CWE-119 Dec 16, 2017
CVE-2017-1002008 9.8 CRITICAL 1 PoC Analysis EPSS 0.40
Membership Simplified - Unrestricted File Upload
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.
CWE-434 Sep 14, 2017
CVE-2017-6880 9.8 CRITICAL 1 PoC Analysis EPSS 0.06
Cerberus FTP Server <8.0.10.3 - Buffer Overflow
Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long MLST command.
CWE-119 Mar 17, 2017
CVE-2017-6550 9.8 CRITICAL 1 PoC Analysis EPSS 0.06
Kinsey Infor-lawson - SQL Injection
Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitrary SQL commands via the (1) TABLE parameter to esbus/servlet/GetSQLData or (2) QUERY parameter to KK_LS9ReportingPortal/GetData.
CWE-89 Mar 20, 2017
CVE-2017-6548 9.8 CRITICAL 1 PoC Analysis EPSS 0.48
Asus Rt-ac53 Firmware - Memory Corruption
Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers with firmware before 3.0.0.4.380.7378; RT-AC68W routers with firmware before 3.0.0.4.380.7266; and RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers with firmware before 3.0.0.4.380.9488; and Asuswrt-Merlin firmware before 380.65_2 allow remote attackers to execute arbitrary code on the router via a long host or port in crafted multicast messages.
CWE-119 Mar 09, 2017
CVE-2017-6506 9.8 CRITICAL 1 PoC Analysis EPSS 0.22
Azure DEX Data Expert Ultimate - Memory Corruption
In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.
CWE-119 Mar 10, 2017
CVE-2017-1002003 9.8 CRITICAL 1 PoC Analysis EPSS 0.48
Wp2android-turn-wp-site-into-android-app - Unrestricted File Upload
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
CWE-434 Sep 14, 2017
CVE-2017-1002002 9.8 CRITICAL 1 PoC Analysis EPSS 0.51
WordPress Plugin Webapp-Builder v2.0 - Info Disclosure
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/
CWE-434 Sep 14, 2017
CVE-2017-1002001 9.8 CRITICAL 1 PoC Analysis EPSS 0.45
WordPress Plugin Mobile-App-Build By Wappress <1.05 - Info Disclosure
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
CWE-434 Sep 14, 2017
CVE-2017-1002000 9.8 CRITICAL 1 PoC Analysis EPSS 0.64
Mobile-friendly-app-builder-by-easytouch - Unrestricted File Upload
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content.
CWE-434 Sep 14, 2017
CVE-2017-5358 9.8 CRITICAL 1 PoC Analysis EPSS 0.35
EasyCom for PHP 4.0.0.29 - Buffer Overflow
Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the server argument to the (1) i5_connect, (2) i5_pconnect, or (3) i5_private_connect API function.
CWE-119 Mar 15, 2017
CVE-2017-5496 9.8 CRITICAL 1 PoC Analysis EPSS 0.11
Sawmill - Information Disclosure
Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash.
CWE-200 Mar 15, 2017
CVE-2017-6077 9.8 CRITICAL KEV 1 PoC Analysis EPSS 0.83
Netgear Dgn2200 Firmware < 10.0.0.50 - OS Command Injection
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.
CWE-78 Feb 22, 2017
CVE-2017-6095 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
Mail-masta - SQL Injection
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/csvexport.php (Unauthenticated) with the GET Parameter: list_id.
CWE-89 Feb 21, 2017
CVE-2017-5344 9.8 CRITICAL 1 PoC Analysis EPSS 0.08
dotCMS <3.6.1 - SQL Injection
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist were implemented in a new class, SQLUtil (main/java/com/dotmarketing/common/util/SQLUtil.java), as part of the remediation of CVE-2016-8902; however, these can be overcome in the case of the q and inode parameters to the /categoriesServlet path. Overcoming these controls permits a number of blind boolean SQL injection vectors in either parameter. The /categoriesServlet web path can be accessed remotely and without authentication in a default dotCMS deployment.
CWE-89 Feb 17, 2017
CVE-2017-5174 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.65
Geutebruck IP Camera G-Cam/EFD-2250 <1.11.0.12 - Auth Bypass
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has been identified. The existing file system architecture could allow attackers to bypass the access control that may allow remote code execution.
CWE-288 May 19, 2017
CVE-2017-5173 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.85
Geutebruck IP Camera G-Cam/EFD-2250 <1.11.0.12 - Command Injection
An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An improper neutralization of special elements vulnerability has been identified. If special elements are not properly neutralized, an attacker can call multiple parameters that can allow access to the root level operating system which could allow remote code execution.
CWE-78 May 19, 2017
CVE-2017-5586 9.8 CRITICAL 1 PoC Analysis EPSS 0.35
Opentext Documentum D2 - Improper Input Validation
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries.
CWE-20 Feb 22, 2017
CVE-2017-5971 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Newsbee - SQL Injection
SQL injection vulnerability in NewsBee CMS allow remote attackers to execute arbitrary SQL commands.
CWE-89 Jan 08, 2018
CVE-2016-2555 9.8 CRITICAL 6 PoCs Analysis EPSS 0.82
Atutor - SQL Injection
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.
CWE-89 Apr 13, 2017