Critical Vulnerabilities with Public Exploits
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2011-2523
9.8
CRITICAL
44 PoCs
Analysis
NUCLEI
EPSS 0.94
Vsftpd - OS Command Injection
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
CWE-78
Nov 27, 2019
CVE-2011-0657
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.47
Microsoft Windows 2003 Server - Improper Input Validation
DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process DNS queries, which allows remote attackers to execute arbitrary code via (1) a crafted LLMNR broadcast query or (2) a crafted application, aka "DNS Query Vulnerability."
CWE-20
Apr 13, 2011
CVE-2011-4908
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.62
Tinybrowser < 1.5.13 - Unrestricted File Upload
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
CWE-434
Feb 12, 2020
CVE-2011-10026
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.65
Spree < 0.50.1 - OS Command Injection
Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instance_eval] parameter, which is dynamically invoked using Ruby’s send method. This flaw enables unauthenticated attackers to execute commands on the server.
CWE-78
Aug 20, 2025
CVE-2011-10019
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.69
Spree < 0.60.2 - Code Injection
Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell commands on the server without authentication.
CWE-94
Aug 13, 2025
CVE-2011-10018
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.53
myBB 1.6.4 - Code Injection
myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitrary PHP code by injecting payloads into a specially crafted collapsed cookie. This vulnerability was introduced during packaging and was not part of the intended application logic. Exploitation requires no authentication and results in full compromise of the web server under the context of the web application.
CWE-912
Aug 13, 2025
CVE-2011-3923
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.91
Apache Struts <2.3.1.2 - Command Injection
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
CWE-732
Nov 01, 2019
CVE-2011-3544
9.8
CRITICAL
KEV
2 PoCs
Analysis
EPSS 0.93
Java Applet Rhino Script Engine Remote Code Execution
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.
CWE-284
Oct 19, 2011
CVE-2011-2462
9.8
CRITICAL
KEV
2 PoCs
Analysis
EPSS 0.92
Adobe Acrobat < 10.1.1 - Out-of-Bounds Write
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.
CWE-787
Dec 07, 2011
CVE-2011-2921
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.73
ktsuss suid Privilege Escalation
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.
CWE-273
Nov 19, 2019
CVE-2011-5331
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.05
Distributed Ruby <1.8 - Code Injection
Distributed Ruby (aka DRuby) 1.8 mishandles instance_eval.
Nov 18, 2019
CVE-2011-2013
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.43
Microsoft Windows - Buffer Overflow
Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code by sending a sequence of crafted UDP packets to a closed port, aka "Reference Counter Overflow Vulnerability."
CWE-190
Nov 08, 2011
CVE-2011-4094
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.07
Jara 1.6 - SQL Injection
Jara 1.6 has a SQL injection vulnerability.
CWE-89
Jan 21, 2020
CVE-2011-3642
9.6
CRITICAL
1 PoC
Analysis
EPSS 0.08
Flowplayer Flash <3.2.16 - XSS
Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.
CWE-79
Feb 08, 2020
CVE-2011-1939
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.06
Zend Framework <1.10.9, <1.11.6 - SQL Injection
SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.
CWE-89
Nov 26, 2019
CVE-2011-1930
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.29
klibc 1.5.20-1.5.21 - RCE
In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.
Nov 14, 2019
CVE-2011-5330
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Distributed Ruby <1.8 - Buffer Overflow
Distributed Ruby (aka DRuby) 1.8 mishandles the sending of syscalls.
Nov 18, 2019
CVE-2011-4906
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.36
Tinybrowser < 1.5.13 - Unrestricted File Upload
Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.
CWE-434
Feb 12, 2020
CVE-2010-4344
9.8
CRITICAL
KEV
2 PoCs
Analysis
EPSS 0.53
Exim < 4.70 - Out-of-Bounds Write
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
CWE-787
Dec 14, 2010
CVE-2010-2861
9.8
CRITICAL
KEV
RANSOMWARE
4 PoCs
Analysis
NUCLEI
EPSS 0.94
Adobe ColdFusion <9.0.1 - Path Traversal
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.
CWE-22
Aug 11, 2010