Critical Vulnerabilities with Public Exploits
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2024-21508
9.8
CRITICAL
1 PoC
1 Writeup
EPSS 0.40
NPM Mysql2 < 3.9.4 - Code Injection
Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.
CWE-94
Apr 11, 2024
CVE-2024-31345
9.1
CRITICAL
1 PoC
EPSS 0.01
Sukhchain Singh Auto Poster <1.2 - Unrestricted Upload
Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2.
CWE-434
Apr 07, 2024
CVE-2024-31286
9.9
CRITICAL
1 PoC
EPSS 0.01
J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus <8.6.03.005 - Unr...
Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.
CWE-434
Apr 07, 2024
CVE-2024-21894
9.8
CRITICAL
EXPLOITED
1 PoC
EPSS 0.09
Ivanti Connect Secure - Out-of-Bounds Write
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack. In certain conditions this may lead to execution of arbitrary code
CWE-703
Apr 04, 2024
CVE-2024-2086
10.0
CRITICAL
1 PoC
EPSS 0.01
WordPress Integrate Google Drive - Info Disclosure
The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers to modify plugin settings as well as allowing full read/write/delete access to the Google Drive associated with the plugin.
CWE-862
Mar 30, 2024
CVE-2024-21400
9.0
CRITICAL
1 PoC
EPSS 0.02
Microsoft Confidental Containers < 0.3.3 - Path Traversal
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
CWE-22
Mar 12, 2024
CVE-2024-21334
9.8
CRITICAL
1 PoC
EPSS 0.07
Microsoft Open Management Infrastructure < 1.8.1-0 - Use After Free
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CWE-416
Mar 12, 2024
CVE-2024-21899
9.8
CRITICAL
EXPLOITED
1 PoC
EPSS 0.11
Qnap Qts < 4.5.4.2627 - Authentication Bypass
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QTS 4.5.4.2627 build 20231225 and later
QuTS hero h5.1.3.2578 build 20231110 and later
QuTS hero h4.5.4.2626 build 20231225 and later
QuTScloud c5.1.5.2651 and later
CWE-287
Mar 08, 2024
CVE-2024-28222
9.8
CRITICAL
1 PoC
EPSS 0.01
Veritas Netbackup < 8.1.2 - Path Traversal
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
CWE-22
Mar 07, 2024
CVE-2024-53704
9.8
CRITICAL
KEV
RANSOMWARE
4 PoCs
Analysis
NUCLEI
EPSS 0.94
Sonicwall Sonicos < 7.1.1-7058 - Authentication Bypass
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
CWE-287
Jan 09, 2025
CVE-2024-0001
10.0
CRITICAL
1 PoC
Analysis
EPSS 0.02
FlashArray Purity - Privilege Escalation
A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.
CWE-1188
Sep 23, 2024
CVE-2024-29847
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.63
Ivanti EPM <2022 SU6-2024 September - Code Injection
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
CWE-502
Sep 12, 2024
CVE-2024-41570
9.8
CRITICAL
6 PoCs
Analysis
EPSS 0.74
Havoc - SSRF
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic originating from the team server.
CWE-918
Aug 12, 2024
CVE-2024-23739
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.36
Discord for macOS <0.0.291 - RCE
An issue in Discord for macOS version 0.0.291 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.
Jan 28, 2024
CVE-2024-23738
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.13
Postman < 10.22 - Remote Code Execution
An issue in Postman version 10.22 and before on macOS allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. NOTE: the vendor states "we dispute the report's accuracy ... the configuration does not enable remote code execution.."
Jan 28, 2024
CVE-2024-34716
9.6
CRITICAL
5 PoCs
Analysis
EPSS 0.37
Prestashop < 8.1.6 - XSS
PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the customer thread feature flag is enabled through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. The script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. This vulnerability is patched in 8.1.6. A workaround is to disable the customer-thread feature-flag.
CWE-79
May 14, 2024
CVE-2024-32651
10.0
CRITICAL
4 PoCs
Analysis
NUCLEI
EPSS 0.92
changedetection.io - RCE
changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover the server machine. This can be reduced if changedetection is behind a login page, but this isn't required by the application (not by default and not enforced).
CWE-1336
Apr 26, 2024
CVE-2024-25830
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.39
F-logic Datacube3 Firmware - Path Traversal
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password.
CWE-22
Feb 29, 2024
CVE-2024-48839
10.0
CRITICAL
2 PoCs
Analysis
EPSS 0.03
ABB Aspect-ent-2 Firmware < 3.08.03 - Code Injection
Improper Input Validation vulnerability allows Remote Code Execution.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
CWE-94
Dec 05, 2024
CVE-2024-51550
10.0
CRITICAL
1 PoC
Analysis
EPSS 0.02
ABB ASPECT Enterprise, NEXUS Series, and MATRIX Series <3.08.02 <3 - Data Validation
Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
CWE-1287
Dec 05, 2024