Critical Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,363 CVEs tracked 53,626 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,844 researchers
4,101 results Clear all
CVE-2014-1511 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.70
Mozilla Firefox < 28.0 - Improper Privilege Management
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.
CWE-269 Mar 19, 2014
CVE-2014-5381 9.8 CRITICAL 1 PoC Analysis EPSS 0.46
Granding Grand Ma300 Firmware - Insufficiently Protected Credentials
Grand MA 300 allows a brute-force attack on the PIN.
CWE-522 Jan 13, 2020
CVE-2014-2595 9.8 CRITICAL 1 PoC Analysis EPSS 0.57
Barracuda WAF 7.8.1.013 - Auth Bypass
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.
CWE-613 Feb 12, 2020
CVE-2014-4170 9.8 CRITICAL 1 PoC Analysis EPSS 0.48
ArticleFR 11.06.2014 - Privilege Escalation
A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information.
CWE-269 Feb 13, 2020
CVE-2014-5091 9.8 CRITICAL 1 PoC Analysis EPSS 0.47
Status2k - Improper Input Validation
A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code.
CWE-20 Feb 07, 2020
CVE-2014-5087 9.8 CRITICAL 1 PoC Analysis EPSS 0.16
Sphider < 1.3.6 - Improper Input Validation
A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code.
CWE-20 Feb 07, 2020
CVE-2014-5081 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
Sphider < 1.3.6 - Authentication Bypass
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
CWE-287 Jan 10, 2020
CVE-2014-4912 9.8 CRITICAL 1 PoC Analysis EPSS 0.08
Frog CMS 0.9.5 - Code Injection
An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.
CWE-434 Mar 22, 2018
CVE-2014-4650 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
Python <3.3.4 - Path Traversal
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.
CWE-22 Feb 20, 2020
CVE-2014-3205 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Seagate Blackarmor Nas 220 Firmware - Hard-coded Credentials
backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.
CWE-798 Feb 23, 2018
CVE-2014-2072 9.8 CRITICAL 1 PoC Analysis EPSS 0.28
Dassault Systemes Catia V5-6R2013 - Buffer Overflow
Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks
CWE-787 Jan 08, 2020
CVE-2014-9558 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
SmartCMS <2. - SQL Injection
Multiple SQL injection vulnerabilities in SmartCMS v.2.
CWE-89 Aug 28, 2017
CVE-2013-3215 9.8 CRITICAL 2 PoCs Analysis EPSS 0.74
vtiger CRM <5.4.0 - Auth Bypass
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
CWE-287 Jan 29, 2020
CVE-2013-2251 9.8 CRITICAL KEV 5 PoCs Analysis NUCLEI EPSS 0.94
Apache Archiva < 1.3.8 - Injection
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
CWE-74 Jul 20, 2013
CVE-2013-7390 9.8 CRITICAL 4 PoCs Analysis EPSS 0.67
ManageEngine DesktopCentral <8.0.0 - RCE
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot.
CWE-434 Jan 27, 2020
CVE-2013-3214 9.8 CRITICAL 4 PoCs Analysis EPSS 0.88
vtiger CRM <5.4.0 - Code Injection
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
CWE-74 Jan 28, 2020
CVE-2013-0625 9.8 CRITICAL KEV 1 PoC Analysis EPSS 0.78
Adobe ColdFusion <9.0.2 - Auth Bypass
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.
CWE-287 Jan 09, 2013
CVE-2013-2568 9.8 CRITICAL 1 PoC Analysis EPSS 0.58
Zavio IP Cameras <1.6.3 - Command Injection
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code.
CWE-78 Jan 29, 2020
CVE-2013-1595 9.8 CRITICAL 1 PoC Analysis EPSS 0.04
Vivotek Pt7135 Firmware - Buffer Overflow
A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field sent to the RTSP service, which could let a remote malicious user execute arbitrary code or cause a Denial of Service.
CWE-120 Jan 24, 2020
CVE-2013-4976 9.8 CRITICAL 1 PoC Analysis EPSS 0.08
Hikvision DS-2CD7153-E - Auth Bypass
Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials
CWE-287 Dec 27, 2019