Critical Vulnerabilities with Public Exploits

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,361 CVEs tracked 53,621 with exploits 4,857 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,840 researchers
4,098 results Clear all
CVE-2008-1160 9.8 CRITICAL 1 PoC Analysis EPSS 0.16
ZyXEL ZyWALL 1050 - Privilege Escalation
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.
CWE-798 Mar 25, 2008
CVE-2007-4559 9.8 CRITICAL 7 PoCs Analysis EPSS 0.90
Python - Path Traversal
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
CWE-22 Aug 28, 2007
CVE-2007-5775 9.8 CRITICAL 1 PoC Analysis EPSS 0.08
Bitdefender Antivirus - Code Injection
Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
CWE-94 Nov 01, 2007
CVE-2007-3010 9.8 CRITICAL KEV 4 PoCs Analysis NUCLEI EPSS 0.94
Al-enterprise Omnipcx Enterprise Comm... - Command Injection
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
CWE-77 Sep 18, 2007
CVE-2007-1399 9.8 CRITICAL 1 PoC Analysis EPSS 0.39
Php < 1.8.4 - Buffer Overflow
Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback.
Mar 10, 2007
CVE-2007-3798 9.8 CRITICAL 1 PoC Analysis EPSS 0.73
tcpdump <3.9.6 - RCE
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
CWE-252 Jul 16, 2007
CVE-2007-1383 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Php - Integer Overflow
Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this counter, which causes the same variable to be destroyed twice, a related issue to CVE-2007-1286.
CWE-189 Mar 10, 2007
CVE-2007-0681 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
ExtCalendar <2 - Auth Bypass
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.
CWE-522 Feb 03, 2007
CVE-2006-6863 9.8 CRITICAL 1 PoC Analysis EPSS 0.06
Enigma2 < - RCE
PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote attackers to execute arbitrary PHP code via a URL in the boarddir parameter. NOTE: CVE disputes this issue, since $boarddir is set to a fixed value
Dec 31, 2006
CVE-2006-5603 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Snitz Communications Snitz Forums 2000 - SQL Injection
SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
CWE-89 Oct 30, 2006
CVE-2006-7079 9.8 CRITICAL 1 PoC Analysis EPSS 0.15
Exv2 Content Management System < 2.0.4.3 - Path Traversal
Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute arbitrary code by modifying the $xoopsOption['pagetype'] variable.
CWE-22 Mar 02, 2007
CVE-2006-5021 9.8 CRITICAL 4 PoCs Analysis EPSS 0.02
Redgun RedBLoG 0.5 - RCE
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the root parameter in imgen.php, and the root_path parameter in (2) admin/config.php, (3) common.php, and (4) admin/index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
CWE-94 Sep 27, 2006
CVE-2006-4428 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
Jupiter CMS 1.1.5 - RCE
PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary PHP code via a URL in the template parameter. NOTE: CVE disputes this claim, since the $template variable is defined as a static value before it is referenced in an include statement
Aug 29, 2006
CVE-2005-2773 9.8 CRITICAL KEV 3 PoCs Analysis EPSS 0.90
HP OpenView Network Node Manager <7.50 - RCE
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.
CWE-77 Sep 02, 2005
CVE-2005-3120 9.8 CRITICAL 2 PoCs Analysis EPSS 0.30
Lynx <2.8.6 - Buffer Overflow
Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.
CWE-131 Oct 17, 2005
CVE-2005-2103 9.8 CRITICAL 1 PoC Analysis EPSS 0.26
Gaim < 1.5.0 - Buffer Overflow
Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.
CWE-131 Aug 16, 2005
CVE-2005-4891 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Simple Machine Forum <1.0.4 - SQL Injection
Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.
CWE-89 Jan 15, 2020
CVE-2005-0199 9.8 CRITICAL 1 PoC Analysis EPSS 0.20
Barton Ngircd < 0.8.2 - Integer Underflow
Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length calculation, which leads to a buffer overflow.
CWE-191 May 02, 2005
CVE-2005-0408 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
CitrusDB <0.3.6 - Auth Bypass
CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating the MD5 checksum of the user name combined with the "boogaadeeboo" string, which is hard-coded in the $hidden_hash variable.
CWE-916 Feb 14, 2005
CVE-2004-0847 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.53
Microsoft .NET - Auth Bypass
The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."
CWE-22 Nov 03, 2004