Critical Vulnerabilities with Public Exploits
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2016-4999
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.07
Redhat Dashbuilder < 0.5.0 - SQL Injection
SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.
CWE-89
Aug 05, 2016
CVE-2016-8863
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.24
Portable UPnP SDK <1.6.21 - Buffer Overflow
Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.
CWE-119
Mar 07, 2017
CVE-2016-5636
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.39
CPython <2.7.12, <3.4.5, <3.5.2 - Buffer Overflow
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow.
CWE-190
Sep 02, 2016
CVE-2016-9488
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.04
Manageengine Applications Manager - SQL Injection
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users' password hashes, which are MD5 hashes without salt, and, depending on the database type and its configuration, could also execute operating system commands using SQL queries.
CWE-89
Jun 05, 2018
CVE-2016-8735
9.8
CRITICAL
KEV
1 PoC
NUCLEI
EPSS 0.94
Apache Tomcat , 7.x , 8.x , 8.5.x , 9.x <6.0.48 <7.0.73 <8.0.39 <8.5.7 - Remote Code Execution
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
Apr 06, 2017
CVE-2016-5640
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.52
Crestron AirMedia AM-100 <1.4.0.13 - Path Traversal
Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the ATE_COMMAND parameter.
CWE-77
Aug 03, 2016
CVE-2016-2783
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Avaya Fabric Connect Virtual Services Platform - Info Disclosure
Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle VLAN and I-SIS indexes, which allows remote attackers to obtain unauthorized access via crafted Ethernet frames.
CWE-19
Jan 23, 2017
CVE-2016-3957
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.13
web2py <2.14.2 - Code Injection
The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, which might allow remote attackers to execute arbitrary code by leveraging knowledge of encryption_key.
CWE-502
Feb 06, 2018
CVE-2016-6798
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Apache Sling < 1.0.10 - XXE
In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input, potentially allowing an attacker to read sensitive data on the filesystem, perform same-site-request-forgery (SSRF), port-scanning behind the firewall or DoS the application.
CWE-611
Jul 19, 2017
CVE-2016-4438
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.62
Apache Struts 2 <2.3.28.1 - RCE
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
CWE-20
Jul 04, 2016
CVE-2016-7567
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Openslp - Memory Corruption
Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact via a crafted string.
CWE-119
Jan 23, 2017
CVE-2016-10036
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.14
JFrog Artifactory <4.16 - RCE
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary files and cause a denial of service by uploading an HTML file.
CWE-434
May 01, 2018
CVE-2016-4372
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.10
HPE iMC PLAT <7.2 - RCE
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
CWE-20
Jul 15, 2016
CVE-2016-1000125
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Huge-IT Catalog <1.0.7 - SQL Injection
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
CWE-89
Oct 06, 2016
CVE-2016-1000124
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Huge-IT Portfolio Gallery Plugin <1.0.6 - SQL Injection
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
CWE-89
Oct 06, 2016
CVE-2016-1000123
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.06
Huge-IT Video Gallery v1.0.9 - SQL Injection
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
CWE-89
Oct 06, 2016
CVE-2016-9682
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.20
Dell Sonicwall Secure Remote Access Server - Command Injection
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component responsible for emailing out information about the state of the system. The application doesn't properly escape the information passed in the 'tsrDeleteRestartedFile' or 'currentTSREmailTo' variables before making a call to system(), allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.
CWE-77
Feb 22, 2017
CVE-2016-10034
9.8
CRITICAL
4 PoCs
Analysis
EPSS 0.82
Zend Mail <2.7.2 - RCE
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.
CWE-77
Dec 30, 2016
CVE-2016-10074
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.76
Swift Mailer <5.4.5 - RCE
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address in the (1) From, (2) ReturnPath, or (3) Sender header.
CWE-77
Dec 30, 2016
CVE-2016-10045
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.93
PHPMailer <5.2.20 - RCE
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.
CWE-77
Dec 30, 2016