Critical Vulnerabilities with Public Exploits
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2014-1511
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
EPSS 0.70
Mozilla Firefox < 28.0 - Improper Privilege Management
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.
CWE-269
Mar 19, 2014
CVE-2014-5381
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.46
Granding Grand Ma300 Firmware - Insufficiently Protected Credentials
Grand MA 300 allows a brute-force attack on the PIN.
CWE-522
Jan 13, 2020
CVE-2014-2595
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.57
Barracuda WAF 7.8.1.013 - Auth Bypass
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.
CWE-613
Feb 12, 2020
CVE-2014-4170
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.48
ArticleFR 11.06.2014 - Privilege Escalation
A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information.
CWE-269
Feb 13, 2020
CVE-2014-5091
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.47
Status2k - Improper Input Validation
A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code.
CWE-20
Feb 07, 2020
CVE-2014-5087
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.16
Sphider < 1.3.6 - Improper Input Validation
A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code.
CWE-20
Feb 07, 2020
CVE-2014-5081
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.07
Sphider < 1.3.6 - Authentication Bypass
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
CWE-287
Jan 10, 2020
CVE-2014-4912
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.08
Frog CMS 0.9.5 - Code Injection
An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.
CWE-434
Mar 22, 2018
CVE-2014-4650
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.07
Python <3.3.4 - Path Traversal
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.
CWE-22
Feb 20, 2020
CVE-2014-3205
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Seagate Blackarmor Nas 220 Firmware - Hard-coded Credentials
backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.
CWE-798
Feb 23, 2018
CVE-2014-2072
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.28
Dassault Systemes Catia V5-6R2013 - Buffer Overflow
Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks
CWE-787
Jan 08, 2020
CVE-2014-9558
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
SmartCMS <2. - SQL Injection
Multiple SQL injection vulnerabilities in SmartCMS v.2.
CWE-89
Aug 28, 2017
CVE-2013-3215
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.74
vtiger CRM <5.4.0 - Auth Bypass
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
CWE-287
Jan 29, 2020
CVE-2013-2251
9.8
CRITICAL
KEV
5 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache Archiva < 1.3.8 - Injection
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
CWE-74
Jul 20, 2013
CVE-2013-7390
9.8
CRITICAL
4 PoCs
Analysis
EPSS 0.67
ManageEngine DesktopCentral <8.0.0 - RCE
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot.
CWE-434
Jan 27, 2020
CVE-2013-3214
9.8
CRITICAL
4 PoCs
Analysis
EPSS 0.88
vtiger CRM <5.4.0 - Code Injection
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
CWE-74
Jan 28, 2020
CVE-2013-0625
9.8
CRITICAL
KEV
1 PoC
Analysis
EPSS 0.78
Adobe ColdFusion <9.0.2 - Auth Bypass
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.
CWE-287
Jan 09, 2013
CVE-2013-2568
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.58
Zavio IP Cameras <1.6.3 - Command Injection
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code.
CWE-78
Jan 29, 2020
CVE-2013-1595
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.04
Vivotek Pt7135 Firmware - Buffer Overflow
A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field sent to the RTSP service, which could let a remote malicious user execute arbitrary code or cause a Denial of Service.
CWE-120
Jan 24, 2020
CVE-2013-4976
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.08
Hikvision DS-2CD7153-E - Auth Bypass
Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials
CWE-287
Dec 27, 2019