Critical Vulnerabilities with Public Exploits

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,363 CVEs tracked 53,626 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,844 researchers
4,101 results Clear all
CVE-2013-6924 9.8 CRITICAL 2 PoCs Analysis EPSS 0.48
Seagate Blackarmor Nas 220 Firmware - Command Injection
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php.
CWE-77 Oct 11, 2017
CVE-2013-5945 9.8 CRITICAL 1 PoC Analysis EPSS 0.10
Dlink Dsr-150 Firmware < 1.08b44 - SQL Injection
Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to execute arbitrary SQL commands via the password to (1) the login.authenticate function in share/lua/5.1/teamf1lualib/login.lua or (2) captivePortal.lua.
CWE-89 Feb 11, 2020
CVE-2013-6225 9.8 CRITICAL 1 PoC Analysis EPSS 0.54
Livezilla - Path Traversal
LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability
CWE-22 Jan 13, 2020
CVE-2013-6792 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Google Android <4.4 - Code Injection
Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability
Jan 23, 2020
CVE-2013-6236 9.8 CRITICAL 1 PoC Analysis EPSS 0.44
Izoncam Izon IP Firmware - Hard-coded Credentials
IZON IP 2.0.2: hard-coded password vulnerability
CWE-798 Feb 12, 2020
CVE-2013-4810 9.8 CRITICAL KEV RANSOMWARE 1 PoC Analysis EPSS 0.90
HP ProCurve Manager <4.0 - RCE
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.
CWE-94 Sep 16, 2013
CVE-2013-4982 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.40
AVTECH AVN801 DVR - Auth Bypass
AVTECH AVN801 DVR has a security bypass via the administration login captcha
CWE-287 Dec 27, 2019
CVE-2013-4864 9.8 CRITICAL 1 PoC Analysis EPSS 0.30
MiCasaVerde VeraLite <1.5.408 - SSRF
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue.
CWE-918 Jan 28, 2020
CVE-2013-4659 9.8 CRITICAL 1 PoC Analysis EPSS 0.12
Broadcom ACSD - RCE
Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on routers of multiple vendors including ASUS RT-AC66U and TRENDnet TEW-812DRU.
CWE-119 Mar 14, 2017
CVE-2013-7471 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.20
D-Link DIR-* - Command Injection
An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST request.
CWE-77 Jun 11, 2019
CVE-2013-2739 9.8 CRITICAL 1 PoC Analysis EPSS 0.08
MiniDLNA - Buffer Overflow
MiniDLNA has heap-based buffer overflow
CWE-119 Nov 01, 2019
CVE-2013-4743 9.8 CRITICAL 1 PoC Analysis EPSS 0.08
Static HTTP Server 1.0 - Buffer Overflow
Static HTTP Server 1.0 has a Local Overflow
CWE-120 Dec 27, 2019
CVE-2013-3684 9.8 CRITICAL 1 PoC Analysis EPSS 0.43
Imagely Nextgen Gallery < 1.9.13 - Unrestricted File Upload
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
CWE-434 Feb 11, 2020
CVE-2013-2571 9.8 CRITICAL 1 PoC Analysis EPSS 0.62
Iris 3.8 <build 1548 - RCE
Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer.
CWE-20 Jan 28, 2020
CVE-2013-2573 9.8 CRITICAL 1 PoC Analysis EPSS 0.22
TP-Link IP Camera - Command Injection
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, 3171G. and 4171G 1.6.18P12s, which could let a malicious user execute arbitrary code.
CWE-78 Jan 29, 2020
CVE-2013-2570 9.8 CRITICAL 1 PoC Analysis EPSS 0.29
Zavio IP Cameras <1.6.3 - Command Injection
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the binary /opt/cgi/view/param, which could let a remove malicious user execute arbitrary code.
CWE-78 Jan 29, 2020
CVE-2013-1599 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.92
Dlink Dcs-3411 Firmware - OS Command Injection
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01, DCS-1100L/1130L 1.04, DCS-1100/1130 1.03, DCS-1100/1130 1.04_US, DCS-2102/2121 1.05_RU, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L 1.02, DCS-6410 1.00, DCS-7410 1.00, DCS-7510 1.00, and WCS-1100 1.02, which could let a remote malicious user execute arbitrary commands through the camera’s web interface.
CWE-78 Jan 28, 2020
CVE-2013-2748 9.8 CRITICAL 1 PoC Analysis EPSS 0.44
Belkin Wemo Switch <WeMo_US_2.00.2176.PVT - Code Injection
Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.
CWE-434 Jan 28, 2020
CVE-2013-3317 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Netgear WNR1000v3 <1.0.2.60 - Auth Bypass
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.
CWE-287 Jan 29, 2020
CVE-2013-3316 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Netgear WNR1000v3 <1.0.2.60 - Auth Bypass
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".
CWE-287 Jan 29, 2020