Critical Vulnerabilities with Public Exploits
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2016-3974
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.14
SAP NetWeaver Java AS <7.5 - DoS
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of service, conduct SMB Relay attacks, or access arbitrary files via a crafted XML request to _tc~monitoring~webservice~web/ServerNodesWSService, aka SAP Security Note 2235994.
CWE-611
Apr 07, 2016
CVE-2016-10972
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.63
Tagdiv Newspaper < 6.7.2 - Improper Privilege Management
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
CWE-269
Sep 16, 2019
CVE-2016-5108
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.21
Debian Linux < 2.2.3 - Memory Corruption
Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted QuickTime IMA file.
CWE-119
Jun 08, 2016
CVE-2016-1606
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.57
Micro Focus Rumba <9.4 HF 13960 - Buffer Overflow
Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrary code via (1) the NetworkName property value to ObjectXSNAConfig.ObjectXSNAConfig in iconfig.dll, (2) the CPName property value to ObjectXSNAConfig.ObjectXSNAConfig in iconfig.dll, (3) the PrinterName property value to ProfileEditor.PrintPasteControl in ProfEdit.dll, (4) the Data argument to the WriteRecords function in FTXBIFFLib.AS400FtxBIFF in FtxBIFF.dll, (5) the Serialized property value to NMSECCOMPARAMSLib.SSL3 in NMSecComParams.dll, (6) the UserName property value to NMSECCOMPARAMSLib.FirewallProxy in NMSecComParams.dll, (7) the LUName property value to ProfileEditor.MFSNAControl in ProfEdit.dll, (8) the newVal argument to the Load function in FTPSFTPLib.SFtpSession in FTPSFtp.dll, or (9) a long Host field in the FTP Client.
CWE-119
Jul 03, 2016
CVE-2016-2208
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.53
Symantec Anti-virus Engine < 20151.1.0.32 - Resource Management Error
The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation and system crash) via a malformed PE header file.
CWE-399
May 19, 2016
CVE-2016-2296
9.4
CRITICAL
1 PoC
Analysis
EPSS 0.75
Meteocontrol Web'log Basic 100 - Security Feature Bypass
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.
CWE-254
May 14, 2016
CVE-2016-0801
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.48
Broadcom Wi-Fi driver - Memory Corruption
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25662029.
CWE-20
Feb 07, 2016
CVE-2016-1077
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.13
Adobe Acrobat < 11.0.15 - Memory Corruption
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1037, CVE-2016-1063, CVE-2016-1064, CVE-2016-1071, CVE-2016-1072, CVE-2016-1073, CVE-2016-1074, CVE-2016-1076, CVE-2016-1078, CVE-2016-1080, CVE-2016-1081, CVE-2016-1082, CVE-2016-1083, CVE-2016-1084, CVE-2016-1085, CVE-2016-1086, CVE-2016-1088, CVE-2016-1093, CVE-2016-1095, CVE-2016-1116, CVE-2016-1118, CVE-2016-1119, CVE-2016-1120, CVE-2016-1123, CVE-2016-1124, CVE-2016-1125, CVE-2016-1126, CVE-2016-1127, CVE-2016-1128, CVE-2016-1129, CVE-2016-1130, CVE-2016-4088, CVE-2016-4089, CVE-2016-4090, CVE-2016-4093, CVE-2016-4094, CVE-2016-4096, CVE-2016-4097, CVE-2016-4098, CVE-2016-4099, CVE-2016-4100, CVE-2016-4101, CVE-2016-4103, CVE-2016-4104, and CVE-2016-4105.
CWE-119
May 11, 2016
CVE-2016-3078
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.48
Php < 7.0.6 - Integer Overflow
Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted call to (1) getFromIndex or (2) getFromName in the ZipArchive class.
CWE-190
Aug 07, 2016
CVE-2016-3074
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.55
Libgd < 5.5.35 - Buffer Overflow
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflow.
CWE-681
Apr 26, 2016
CVE-2016-3141
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.72
Apple Mac OS X < 10.11.4 - Memory Corruption
Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.
CWE-119
Mar 31, 2016
CVE-2016-3694
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
modified eCommerce Shopsoftware 2.0.0.0 - SQL Injection
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remote attackers to execute arbitrary SQL commands via the (1) orders_status or (2) customers_status parameter to api/easybill/easybillcsv.php.
CWE-89
Feb 15, 2017
CVE-2016-2417
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.13
Google Android - Access Control
media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26914474.
CWE-264
Apr 18, 2016
CVE-2016-2345
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.53
Dameware Mini Remote Control - Memory Corruption
Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbitrary code via a crafted string.
CWE-119
Mar 17, 2016
CVE-2016-4071
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.33
PHP <5.5.34, <5.6.20, <7.0.5 - RCE
Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via format string specifiers in an SNMP::get call.
CWE-20
May 20, 2016
CVE-2016-2385
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.25
Debian Linux < 4.3.4 - Memory Corruption
Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows remote attackers to cause a denial of service (memory corruption and process crash) or possibly execute arbitrary code via a large SIP packet.
CWE-119
Apr 11, 2016
CVE-2016-1741
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.17
Apple OS X <10.11.4 - RCE/DoS
The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
CWE-119
Mar 24, 2016
CVE-2016-11017
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.19
Akips Network Monitor < 16.5 - OS Command Injection
The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a failed login attempt returns the command-injection output to a limited login failure field). This is fixed in 16.6.
CWE-78
Jan 06, 2020
CVE-2016-2851
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.23
Debian Linux < 4.1.0 - Memory Corruption
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a series of large OTR messages, which triggers a heap-based buffer overflow.
CWE-119
Apr 07, 2016
CVE-2016-2563
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.29
9bis Kitty < 0.66.6.3 - Memory Corruption
Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a denial of service (stack memory corruption) or execute arbitrary code via a crafted SCP-SINK file-size response to an SCP download request.
CWE-119
Apr 07, 2016