Critical Vulnerabilities with Public Exploits
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2012-1723
9.8
CRITICAL
KEV
RANSOMWARE
3 PoCs
Analysis
EPSS 0.94
Java Applet Field Bytecode Verifier Cache Remote Code Execution
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
CWE-284
Jun 16, 2012
CVE-2012-0507
9.8
CRITICAL
KEV
RANSOMWARE
2 PoCs
Analysis
EPSS 0.94
Java AtomicReferenceArray Type Violation Vulnerability
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
CWE-843
Jun 07, 2012
CVE-2012-10060
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.69
Sysax Multi Server <5.55 - Buffer Overflow
Sysax Multi Server versions prior to 5.55 contains a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username during authentication, the server copies the input to a fixed-size stack buffer without proper bounds checking. This allows remote code execution under the context of the service.
CWE-121
Aug 13, 2025
CVE-2012-10030
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.61
FreeFloat FTP Server - Unauthenticated RCE
FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty credentials, defaults user access to the root of the C:\ drive, and imposes no restrictions on file type or destination path. These conditions enable attackers to upload executable payloads and .mof files to locations such as system32 and wbem\mof, where Windows Management Instrumentation (WMI) automatically processes and executes them. This results in remote code execution with SYSTEM-level privileges, without requiring user interaction.
CWE-732
Aug 05, 2025
CVE-2012-10023
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.71
FreeFloat FTP Server 1.0.0 - Buffer Overflow
A stack-based buffer overflow vulnerability exists in FreeFloat FTP Server version 1.0.0. The server fails to properly validate input passed to the USER command, allowing remote attackers to overwrite memory and potentially execute arbitrary code. The flaw is triggered by sending an overly long username string, which overflows the buffer allocated for user authentication.
CWE-121
Aug 05, 2025
CVE-2012-10021
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.59
D-Link DIR-605L Wireless N300 Cloud Router <1.13 - Buffer Overflow
A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode() function. The flaw arises from unsafe usage of sprintf() when processing user-supplied CAPTCHA data via the FILECODE parameter in /goform/formLogin. A remote unauthenticated attacker can exploit this to execute arbitrary code with root privileges on the device.
CWE-121
Jul 31, 2025
CVE-2012-1495
9.8
CRITICAL
4 PoCs
Analysis
EPSS 0.89
Webcalendar < 1.2.5 - Injection
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.
CWE-74
Jan 27, 2020
CVE-2012-4284
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.51
Sparklabs Viscosity - Privilege Escalation
A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary code
Jan 10, 2020
CVE-2012-6611
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Polycom Hdx System Software < 3.0.5 - Hard-coded Credentials
An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and can be successfully used without setting this password.
CWE-798
Feb 10, 2020
CVE-2012-3152
9.1
CRITICAL
KEV
2 PoCs
Analysis
EPSS 0.94
Oracle Reports Developer - Info Disclosure
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the URLPARAMETER functionality allows remote attackers to read and upload arbitrary files to reports/rwservlet, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3153 to execute arbitrary code by uploading a .jsp file.
Oct 16, 2012
CVE-2012-5190
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Prizm Content Connect 5.1 - Code Injection
Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability
CWE-434
Jan 21, 2020
CVE-2012-5878
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Bulbsecurity Smartphone Pentest Framework - OS Command Injection
Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl.
CWE-78
Jan 03, 2020
CVE-2012-5686
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.14
ZPanel 10.0.1 - Info Disclosure
ZPanel 10.0.1 has insufficient entropy for its password reset process.
CWE-640
Feb 04, 2020
CVE-2012-4750
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.28
EzServer 7.0 - RCE
A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, which could let a remote malicious user execute arbitrary code or cause a Denial of Service
CWE-119
Jan 13, 2020
CVE-2012-3363
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.55
Zend Framework < 1.11.12 - XXE
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.
CWE-611
Feb 13, 2013
CVE-2012-6649
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.45
Devfarm WP Gpx Maps - Unrestricted File Upload
WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.
CWE-434
Jan 23, 2020
CVE-2012-2576
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.41
SolarWinds <5.1.2 - SQL Injection
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.
CWE-89
Dec 20, 2017
CVE-2012-1259
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.14
Plixer Scrutinizer Netflow & Sflow Analyzer - SQL Injection
Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands via the (1) addip parameter to cgi-bin/scrut_fa_exclusions.cgi, (2) getPermissionsAndPreferences parameter to cgi-bin/login.cgi, or (3) possibly certain parameters to d4d/alarms.php as demonstrated by the search_str parameter.
CWE-89
Jan 09, 2020
CVE-2012-2226
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.13
Invisioncommunity Invision Power Board - Unrestricted File Upload
Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.
CWE-434
Jan 09, 2020
CVE-2012-1124
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.04
phxEventManager 2.0 beta 5 - SQL Injection
SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.
CWE-89
Feb 11, 2020