Critical Vulnerabilities with Public Exploits
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,098 results
Clear all
CVE-2004-2061
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.16
Risearch - SSRF
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.
CWE-918
Jul 27, 2004
CVE-2004-0285
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.30
AllMyVisitors/Links/Guests - RCE
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.
CWE-829
Nov 23, 2004
CVE-2004-0030
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.05
PHPGEDVIEW 2.61 - RCE
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.
CWE-829
Jan 20, 2004
CVE-2003-0899
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.20
Acme Thttpd < 2.23 - Buffer Overflow
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and ">" sequences.
CWE-131
Nov 03, 2003
CVE-2003-0466
9.8
CRITICAL
5 PoCs
Analysis
EPSS 0.91
wu-ftpd <2.6.2 - RCE
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.
CWE-193
Aug 27, 2003
CVE-2002-1816
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Redshift Atphttpd < 0.4b - Buffer Overflow
Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
CWE-193
Dec 31, 2002
CVE-2002-1798
9.1
CRITICAL
2 PoCs
Analysis
EPSS 0.05
MidiCart PHP - RCE
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php.
CWE-425
Dec 31, 2002
CVE-2002-1484
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.07
DB4Web - SSRF
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.
CWE-918
Apr 22, 2003
CVE-2002-0083
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
OpenSSH <3.0.2 - Privilege Escalation
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
CWE-193
Mar 15, 2002
CVE-2001-1291
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.07
3Com PS40 SuperStack II - Info Disclosure
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing.
CWE-307
Jul 12, 2001
CVE-2001-0766
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Apache on MacOS X Client 10.0.3 - Auth Bypass
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
CWE-178
Oct 18, 2001
CVE-2001-1339
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.24
IPC@CHIP - DoS
Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.
CWE-307
May 24, 2001
CVE-2001-0609
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.10
Infodrom cfingerd <1.4.3 - Privilege Escalation
Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.
CWE-193
Aug 02, 2001
CVE-2000-0944
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
CGI Script Center News Update 1.1 - Info Disclosure
CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password.
CWE-522
Dec 19, 2000
CVE-1999-0426
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.08
Suse Linux - Incorrect Default Permissions
The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.
CWE-276
Mar 01, 1999
CVE-1999-0006
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.08
Qualcomm Qpopper - Out-of-Bounds Read
Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.
CWE-125
Jul 14, 1998
CVE-1999-1588
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.18
SUN Solaris - Memory Corruption
Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.
CWE-119
Dec 31, 1999
CVE-1999-0066
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.22
AnyForm CGI - RCE
AnyForm CGI remote execution.
Jul 31, 1995