Critical Vulnerabilities with Public Exploits

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,363 CVEs tracked 53,626 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,844 researchers
4,101 results Clear all
CVE-2013-1592 9.8 CRITICAL 1 PoC Analysis EPSS 0.69
SAP Netweaver - Buffer Overflow
A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Server packets to remote TCP ports 36NN and/or 39NN in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 SP04, which could let a remote malicious user execute arbitrary code.
CWE-120 Jan 23, 2020
CVE-2013-1465 9.8 CRITICAL 1 PoC Analysis EPSS 0.31
Cubecart < 5.2.0 - Insecure Deserialization
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object.
CWE-502 Feb 08, 2013
CVE-2013-1360 9.8 CRITICAL 1 PoC Analysis EPSS 0.58
Sonicwall Analyzer - Authentication Bypass
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain administrative access.
CWE-287 Feb 11, 2020
CVE-2013-1744 9.8 CRITICAL 1 PoC Analysis EPSS 0.20
IRIS <1.3 - RCE
IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands.
Jan 25, 2020
CVE-2013-4103 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
Cryptocat < 2.0.22 - Improper Input Validation
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
CWE-20 Nov 04, 2019
CVE-2012-1823 9.8 CRITICAL KEV 17 PoCs Analysis NUCLEI EPSS 0.94
Php < 5.3.12 - Command Injection
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.
CWE-77 May 11, 2012
CVE-2012-3807 9.8 CRITICAL 1 PoC Analysis EPSS 0.35
Samsung Kies <2.5.0.12094 - Code Injection
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution.
Jan 09, 2020
CVE-2012-5699 9.8 CRITICAL 1 PoC Analysis EPSS 0.08
BabyGekko <1.2.4 - Code Injection
BabyGekko before 1.2.4 allows PHP file inclusion.
CWE-20 Jan 23, 2020
CVE-2012-2926 9.1 CRITICAL 2 PoCs Analysis EPSS 0.68
Atlassian Bamboo < 3.3.4 - Denial of Service
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
May 22, 2012
CVE-2012-10020 9.8 CRITICAL 1 PoC Analysis EPSS 0.69
FoxyPress <0.4.2.1 - File Upload
The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify.php file in versions up to, and including, 0.4.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
CWE-434 Jul 22, 2025
CVE-2012-0694 9.8 CRITICAL 3 PoCs Analysis EPSS 0.84
SugarCRM CE <= 6.3.1 - Code Injection
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.
CWE-20 Oct 29, 2019
CVE-2012-10019 9.8 CRITICAL 1 PoC Analysis EPSS 0.68
Front End Editor <2.3 - File Upload
The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions before 2.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
CWE-434 Jul 19, 2025
CVE-2012-6710 9.8 CRITICAL 1 PoC Analysis EPSS 0.76
Extplorer < 2.1.2 - Authentication Bypass
ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php.
CWE-287 Oct 07, 2018
CVE-2012-0911 9.8 CRITICAL 3 PoCs Analysis EPSS 0.78
TikiWiki CMS/Groupware < 6.7 LTS & < 8.4 - RCE
TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a) tiki-print_multi_pages.php or (b) tiki-print_pages.php; or (4) sendpages, (5) sendstructures, or (6) sendarticles parameter to tiki-send_objects.php, which is not properly handled when processed by the unserialize function.
CWE-502 Jul 12, 2012
CVE-2012-0391 9.8 CRITICAL KEV 3 PoCs Analysis EPSS 0.88
Apache Struts <2.2.3.1 - RCE
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
CWE-94 Jan 08, 2012
CVE-2012-10054 9.8 CRITICAL 2 PoCs Analysis EPSS 0.76
Umbraco CMS <4.7.1 - RCE
Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the fileName parameter, attackers can write malicious ASPX scripts directly into the web-accessible /umbraco/ directory and execute them remotely.
CWE-22 Aug 13, 2025
CVE-2012-6664 9.1 CRITICAL 2 PoCs Analysis EPSS 0.73
Distinct Intranet Servers <3.10 - Path Traversal
Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via a .. (dot dot) in the (1) get or (2) put commands.
CWE-22 Jun 21, 2024
CVE-2012-5357 9.8 CRITICAL 2 PoCs Analysis EPSS 0.83
Ektron CMS <8.02 SP5 - RCE
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data.
CWE-19 Oct 30, 2017
CVE-2012-5076 9.8 CRITICAL KEV RANSOMWARE 4 PoCs Analysis EPSS 0.92
Java Applet AverageRangeStatisticImpl Remote Code Execution
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.
CWE-284 Oct 16, 2012
CVE-2012-4681 9.8 CRITICAL KEV RANSOMWARE 4 PoCs Analysis EPSS 0.94
Java 7 Applet Remote Code Execution
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
CWE-284 Aug 28, 2012