Critical Vulnerabilities with Public Exploits

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,361 CVEs tracked 53,621 with exploits 4,857 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,840 researchers
4,098 results Clear all
CVE-2004-2061 9.8 CRITICAL 2 PoCs Analysis EPSS 0.16
Risearch - SSRF
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.
CWE-918 Jul 27, 2004
CVE-2004-0285 9.8 CRITICAL 3 PoCs Analysis EPSS 0.30
AllMyVisitors/Links/Guests - RCE
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.
CWE-829 Nov 23, 2004
CVE-2004-0030 9.8 CRITICAL 1 PoC Analysis EPSS 0.05
PHPGEDVIEW 2.61 - RCE
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.
CWE-829 Jan 20, 2004
CVE-2003-0899 9.8 CRITICAL 2 PoCs Analysis EPSS 0.20
Acme Thttpd < 2.23 - Buffer Overflow
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;" sequences.
CWE-131 Nov 03, 2003
CVE-2003-0466 9.8 CRITICAL 5 PoCs Analysis EPSS 0.91
wu-ftpd <2.6.2 - RCE
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.
CWE-193 Aug 27, 2003
CVE-2002-1816 9.8 CRITICAL 1 PoC Analysis EPSS 0.11
Redshift Atphttpd < 0.4b - Buffer Overflow
Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
CWE-193 Dec 31, 2002
CVE-2002-1798 9.1 CRITICAL 2 PoCs Analysis EPSS 0.05
MidiCart PHP - RCE
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php.
CWE-425 Dec 31, 2002
CVE-2002-1484 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
DB4Web - SSRF
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.
CWE-918 Apr 22, 2003
CVE-2002-0083 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
OpenSSH <3.0.2 - Privilege Escalation
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
CWE-193 Mar 15, 2002
CVE-2001-1291 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
3Com PS40 SuperStack II - Info Disclosure
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing.
CWE-307 Jul 12, 2001
CVE-2001-0766 9.8 CRITICAL 1 PoC Analysis EPSS 0.11
Apache on MacOS X Client 10.0.3 - Auth Bypass
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
CWE-178 Oct 18, 2001
CVE-2001-1339 9.8 CRITICAL 1 PoC Analysis EPSS 0.24
IPC@CHIP - DoS
Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.
CWE-307 May 24, 2001
CVE-2001-0609 9.8 CRITICAL 2 PoCs Analysis EPSS 0.10
Infodrom cfingerd <1.4.3 - Privilege Escalation
Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.
CWE-193 Aug 02, 2001
CVE-2000-0944 9.8 CRITICAL 1 PoC Analysis EPSS 0.11
CGI Script Center News Update 1.1 - Info Disclosure
CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password.
CWE-522 Dec 19, 2000
CVE-1999-0426 9.8 CRITICAL 1 PoC Analysis EPSS 0.08
Suse Linux - Incorrect Default Permissions
The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.
CWE-276 Mar 01, 1999
CVE-1999-0006 9.8 CRITICAL 2 PoCs Analysis EPSS 0.08
Qualcomm Qpopper - Out-of-Bounds Read
Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.
CWE-125 Jul 14, 1998
CVE-1999-1588 9.8 CRITICAL 1 PoC Analysis EPSS 0.18
SUN Solaris - Memory Corruption
Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.
CWE-119 Dec 31, 1999
CVE-1999-0066 9.8 CRITICAL 1 PoC Analysis EPSS 0.22
AnyForm CGI - RCE
AnyForm CGI remote execution.
Jul 31, 1995