Critical Vulnerabilities with Public Exploits

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,378 CVEs tracked 53,627 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,849 researchers
4,101 results Clear all
CVE-2016-10108 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.91
Western Digital MyCloud unauthenticated command injection
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data.
CWE-77 Jan 03, 2017
CVE-2016-7456 9.8 CRITICAL 1 PoC Analysis EPSS 0.82
Vmware Vsphere Data Protection - Credentials Management
VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attackers to obtain login access via an SSH session.
CWE-255 Dec 29, 2016
CVE-2016-8582 9.8 CRITICAL 2 PoCs Analysis EPSS 0.81
AlienVault OSSIM & USM <5.3.2 - SQL Injection
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.
CWE-89 Oct 28, 2016
CVE-2016-5675 9.8 CRITICAL 2 PoCs Analysis EPSS 0.73
NUUO <3.2.0 - RCE
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.
CWE-20 Aug 31, 2016
CVE-2016-5674 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.89
NUUO NVRmini <3.0.0 - RCE
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.
CWE-20 Aug 31, 2016
CVE-2016-15042 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.74
WordPress <4.0, WordPress <1.1 - Unauthenticated RCE
The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
CWE-434 Oct 16, 2024
CVE-2016-4464 9.8 CRITICAL 2 PoCs Analysis EPSS 0.02
Apache Cxf Fediz < 1.2.3 - Improper Access Control
The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might allow remote attackers to have bypass intended restrictions and have unspecified other impact via a crafted SAML token with a trusted signature.
CWE-284 Sep 21, 2016
CVE-2016-6809 9.8 CRITICAL 2 PoCs Analysis EPSS 0.07
Apache Tika < 1.13 - Insecure Deserialization
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
CWE-502 Apr 06, 2017
CVE-2016-1000031 9.8 CRITICAL 2 PoCs Analysis EPSS 0.50
Apache Commons FileUpload <1.3.3 - RCE
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
CWE-284 Oct 25, 2016
CVE-2016-10204 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Zoneminder < 1.30.0 - SQL Injection
SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php.
CWE-89 Mar 03, 2017
CVE-2016-0856 9.8 CRITICAL 1 PoC EPSS 0.51
Advantech WebAccess <8.1 - RCE
Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.
CWE-119 Jan 15, 2016
CVE-2016-5180 9.8 CRITICAL 3 PoCs Analysis EPSS 0.18
C-ares < 0.10.48 - Out-of-Bounds Write
Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.
CWE-787 Oct 03, 2016
CVE-2016-0638 9.8 CRITICAL 3 PoCs Analysis EPSS 0.71
Oracle WebLogic Server - Info Disclosure
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.
Apr 21, 2016
CVE-2016-2338 9.8 CRITICAL 1 PoC Analysis EPSS 0.13
Ruby - Out-of-Bounds Write
An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can increase this array size after mentioned allocation and cause heap overflow.
CWE-787 Sep 29, 2022
CVE-2016-10191 9.8 CRITICAL 1 PoC Analysis EPSS 0.09
Ffmpeg < 2.8.9 - Memory Corruption
Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches.
CWE-119 Feb 09, 2017
CVE-2016-6195 9.8 CRITICAL EXPLOITED 3 PoCs Analysis NUCLEI EPSS 0.85
vBulletin <4.2.2 PL5 & <4.2.3 PL1 - SQL Injection
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, as exploited in the wild in July 2016.
CWE-89 Aug 30, 2016
CVE-2016-10190 9.8 CRITICAL 1 PoC Analysis EPSS 0.10
Ffmpeg < 2.8.9 - Memory Corruption
Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.
CWE-119 Feb 09, 2017
CVE-2016-10229 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Linux kernel <4.5 - RCE
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
CWE-358 Apr 04, 2017
CVE-2016-6725 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Google Android < 7.0 - Improper Access Control
A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Android ID: A-30515053. References: Qualcomm QC-CR#1050970.
CWE-284 Nov 25, 2016
CVE-2016-2419 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Google Android - Access Control
media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize a certain key-request data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26323455.
CWE-264 Apr 18, 2016