Critical Vulnerabilities with Public Exploits
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2024-50526
10.0
CRITICAL
1 PoC
Analysis
EPSS 0.01
Lindeni Multi Purpose Mail Form < 1.0.2 - Unrestricted File Upload
Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose-mail-form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through <= 1.0.2.
CWE-434
Nov 04, 2024
CVE-2024-51791
10.0
CRITICAL
1 PoC
Analysis
EPSS 0.01
Made I.T. Forms <2.8.0 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms forms-by-made-it allows Upload a Web Shell to a Web Server.This issue affects Forms: from n/a through <= 2.8.0.
CWE-434
Nov 11, 2024
CVE-2024-51793
10.0
CRITICAL
5 PoCs
Analysis
EPSS 0.52
Webful Creations Computer Repair Shop <3.8115 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Upload a Web Shell to a Web Server.This issue affects RepairBuddy: from n/a through <= 3.8115.
CWE-434
Nov 11, 2024
CVE-2024-38476
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.05
Apache HTTP Server <2.4.60 - Info Disclosure/SSRF
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
CWE-829
Jul 01, 2024
CVE-2024-43400
9.0
CRITICAL
2 PoCs
Analysis
EPSS 0.06
XWiki Platform - XSS
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engineer to trick a user to follow the URL. This has been patched in XWiki 14.10.21, 15.5.5, 15.10.6 and 16.0.0.
CWE-79
Aug 19, 2024
CVE-2024-8465
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.00
SQL Injection - Info Disclosure
SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in it.
CWE-89
Sep 05, 2024
CVE-2024-11635
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.24
WordPress File Upload <4.24.12 - RCE
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.
CWE-94
Jan 08, 2025
CVE-2024-24401
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.58
Nagios XI - SQL Injection
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.
CWE-89
Feb 26, 2024
CVE-2024-36412
10.0
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.94
SuiteCRM <7.14.4-8.6.1 - SQL Injection
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
CWE-89
Jun 10, 2024
CVE-2024-43202
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.04
Apache DolphinScheduler <3.2.2 - RCE
Exposure of Remote Code Execution in Apache Dolphinscheduler.
This issue affects Apache DolphinScheduler: before 3.2.2.
We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue.
CWE-94
Aug 20, 2024
CVE-2024-48910
9.1
CRITICAL
2 PoCs
Analysis
EPSS 0.03
Cure53 Dompurify < 2.4.2 - Prototype Pollution
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.
CWE-1321
Oct 31, 2024
CVE-2024-40110
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.32
Sourcecodester Poultry Farm Management System v1.0 - RCE
Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability via the productimage parameter at /farm/product.php.
CWE-77
Jul 12, 2024
CVE-2024-39205
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.84
pyload-ng <0.5.0b3.dev85 - RCE
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.
Oct 28, 2024
CVE-2024-38077
9.8
CRITICAL
14 PoCs
Analysis
EPSS 0.90
Windows Remote Desktop < - RCE
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CWE-122
Jul 09, 2024
CVE-2024-30804
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
ASUS Fan_Xpert <v.10013 - RCE
An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via crafted IOCTL requests.
CWE-782
Apr 26, 2024
CVE-2024-22120
9.1
CRITICAL
EXPLOITED
4 PoCs
Analysis
NUCLEI
EPSS 0.92
Zabbix Server - Command Injection
Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.
CWE-20
May 17, 2024
CVE-2024-12252
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.68
SEO LAT Auto Post <2.2.1 - RCE
The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remote_update AJAX action in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to overwrite the seo-beginner-auto-post.php file which can be leveraged to achieve remote code execution.
CWE-94
Jan 07, 2025
CVE-2024-56249
9.1
CRITICAL
2 PoCs
Analysis
EPSS 0.42
Webdeclic WPMasterToolKit <1.13.1 - Code Injection
Unrestricted Upload of File with Dangerous Type vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Upload a Web Shell to a Web Server.This issue affects WPMasterToolKit: from n/a through <= 1.13.1.
CWE-434
Jan 02, 2025
CVE-2024-56071
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.00
Mike Leembruggen Simple Dashboard <2.0 - Privilege Escalation
Incorrect Privilege Assignment vulnerability in mikeleembruggen Simple Dashboard simple-dashboard allows Privilege Escalation.This issue affects Simple Dashboard: from n/a through <= 2.0.
CWE-266
Dec 31, 2024
CVE-2024-54369
9.1
CRITICAL
3 PoCs
Analysis
EPSS 0.19
ThemeHunk Zita Site Builder <1.0.2 - Info Disclosure
Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Zita Site Builder: from n/a through <= 1.0.2.
CWE-862
Dec 16, 2024