Critical Vulnerabilities with Public Exploits
Updated 6h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2016-10108
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.91
Western Digital MyCloud unauthenticated command injection
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data.
CWE-77
Jan 03, 2017
CVE-2016-7456
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.82
Vmware Vsphere Data Protection - Credentials Management
VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attackers to obtain login access via an SSH session.
CWE-255
Dec 29, 2016
CVE-2016-8582
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.81
AlienVault OSSIM & USM <5.3.2 - SQL Injection
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.
CWE-89
Oct 28, 2016
CVE-2016-5675
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.73
NUUO <3.2.0 - RCE
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.
CWE-20
Aug 31, 2016
CVE-2016-5674
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.89
NUUO NVRmini <3.0.0 - RCE
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.
CWE-20
Aug 31, 2016
CVE-2016-15042
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.74
WordPress <4.0, WordPress <1.1 - Unauthenticated RCE
The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
CWE-434
Oct 16, 2024
CVE-2016-4464
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.02
Apache Cxf Fediz < 1.2.3 - Improper Access Control
The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might allow remote attackers to have bypass intended restrictions and have unspecified other impact via a crafted SAML token with a trusted signature.
CWE-284
Sep 21, 2016
CVE-2016-6809
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.07
Apache Tika < 1.13 - Insecure Deserialization
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
CWE-502
Apr 06, 2017
CVE-2016-1000031
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.50
Apache Commons FileUpload <1.3.3 - RCE
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
CWE-284
Oct 25, 2016
CVE-2016-10204
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Zoneminder < 1.30.0 - SQL Injection
SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php.
CWE-89
Mar 03, 2017
CVE-2016-0856
9.8
CRITICAL
1 PoC
EPSS 0.51
Advantech WebAccess <8.1 - RCE
Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.
CWE-119
Jan 15, 2016
CVE-2016-5180
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.18
C-ares < 0.10.48 - Out-of-Bounds Write
Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.
CWE-787
Oct 03, 2016
CVE-2016-0638
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.71
Oracle WebLogic Server - Info Disclosure
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.
Apr 21, 2016
CVE-2016-2338
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.13
Ruby - Out-of-Bounds Write
An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can increase this array size after mentioned allocation and cause heap overflow.
CWE-787
Sep 29, 2022
CVE-2016-10191
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.09
Ffmpeg < 2.8.9 - Memory Corruption
Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches.
CWE-119
Feb 09, 2017
CVE-2016-6195
9.8
CRITICAL
EXPLOITED
3 PoCs
Analysis
NUCLEI
EPSS 0.85
vBulletin <4.2.2 PL5 & <4.2.3 PL1 - SQL Injection
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, as exploited in the wild in July 2016.
CWE-89
Aug 30, 2016
CVE-2016-10190
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.10
Ffmpeg < 2.8.9 - Memory Corruption
Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.
CWE-119
Feb 09, 2017
CVE-2016-10229
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Linux kernel <4.5 - RCE
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
CWE-358
Apr 04, 2017
CVE-2016-6725
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Google Android < 7.0 - Improper Access Control
A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Android ID: A-30515053. References: Qualcomm QC-CR#1050970.
CWE-284
Nov 25, 2016
CVE-2016-2419
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Google Android - Access Control
media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize a certain key-request data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26323455.
CWE-264
Apr 18, 2016