Critical Vulnerabilities with Public Exploits

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,417 CVEs tracked 53,633 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,306 vendors 43,872 researchers
4,101 results Clear all
CVE-2024-50526 10.0 CRITICAL 1 PoC Analysis EPSS 0.01
Lindeni Multi Purpose Mail Form < 1.0.2 - Unrestricted File Upload
Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose-mail-form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through <= 1.0.2.
CWE-434 Nov 04, 2024
CVE-2024-51791 10.0 CRITICAL 1 PoC Analysis EPSS 0.01
Made I.T. Forms <2.8.0 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms forms-by-made-it allows Upload a Web Shell to a Web Server.This issue affects Forms: from n/a through <= 2.8.0.
CWE-434 Nov 11, 2024
CVE-2024-51793 10.0 CRITICAL 5 PoCs Analysis EPSS 0.52
Webful Creations Computer Repair Shop <3.8115 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Upload a Web Shell to a Web Server.This issue affects RepairBuddy: from n/a through <= 3.8115.
CWE-434 Nov 11, 2024
CVE-2024-38476 9.8 CRITICAL 2 PoCs Analysis EPSS 0.05
Apache HTTP Server <2.4.60 - Info Disclosure/SSRF
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
CWE-829 Jul 01, 2024
CVE-2024-43400 9.0 CRITICAL 2 PoCs Analysis EPSS 0.06
XWiki Platform - XSS
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engineer to trick a user to follow the URL. This has been patched in XWiki 14.10.21, 15.5.5, 15.10.6 and 16.0.0.
CWE-79 Aug 19, 2024
CVE-2024-8465 9.8 CRITICAL 2 PoCs Analysis EPSS 0.00
SQL Injection - Info Disclosure
SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in it.
CWE-89 Sep 05, 2024
CVE-2024-11635 9.8 CRITICAL 1 PoC Analysis EPSS 0.24
WordPress File Upload <4.24.12 - RCE
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.
CWE-94 Jan 08, 2025
CVE-2024-24401 9.8 CRITICAL 2 PoCs Analysis EPSS 0.58
Nagios XI - SQL Injection
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.
CWE-89 Feb 26, 2024
CVE-2024-36412 10.0 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.94
SuiteCRM <7.14.4-8.6.1 - SQL Injection
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
CWE-89 Jun 10, 2024
CVE-2024-43202 9.8 CRITICAL 1 PoC Analysis EPSS 0.04
Apache DolphinScheduler <3.2.2 - RCE
Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue.
CWE-94 Aug 20, 2024
CVE-2024-48910 9.1 CRITICAL 2 PoCs Analysis EPSS 0.03
Cure53 Dompurify < 2.4.2 - Prototype Pollution
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.
CWE-1321 Oct 31, 2024
CVE-2024-40110 9.8 CRITICAL 3 PoCs Analysis EPSS 0.32
Sourcecodester Poultry Farm Management System v1.0 - RCE
Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability via the productimage parameter at /farm/product.php.
CWE-77 Jul 12, 2024
CVE-2024-39205 9.8 CRITICAL 2 PoCs Analysis EPSS 0.84
pyload-ng <0.5.0b3.dev85 - RCE
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.
Oct 28, 2024
CVE-2024-38077 9.8 CRITICAL 14 PoCs Analysis EPSS 0.90
Windows Remote Desktop < - RCE
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CWE-122 Jul 09, 2024
CVE-2024-30804 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
ASUS Fan_Xpert <v.10013 - RCE
An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via crafted IOCTL requests.
CWE-782 Apr 26, 2024
CVE-2024-22120 9.1 CRITICAL EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.92
Zabbix Server - Command Injection
Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.
CWE-20 May 17, 2024
CVE-2024-12252 9.8 CRITICAL 3 PoCs Analysis EPSS 0.68
SEO LAT Auto Post <2.2.1 - RCE
The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remote_update AJAX action in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to overwrite the seo-beginner-auto-post.php file which can be leveraged to achieve remote code execution.
CWE-94 Jan 07, 2025
CVE-2024-56249 9.1 CRITICAL 2 PoCs Analysis EPSS 0.42
Webdeclic WPMasterToolKit <1.13.1 - Code Injection
Unrestricted Upload of File with Dangerous Type vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Upload a Web Shell to a Web Server.This issue affects WPMasterToolKit: from n/a through <= 1.13.1.
CWE-434 Jan 02, 2025
CVE-2024-56071 9.8 CRITICAL 2 PoCs Analysis EPSS 0.00
Mike Leembruggen Simple Dashboard <2.0 - Privilege Escalation
Incorrect Privilege Assignment vulnerability in mikeleembruggen Simple Dashboard simple-dashboard allows Privilege Escalation.This issue affects Simple Dashboard: from n/a through <= 2.0.
CWE-266 Dec 31, 2024
CVE-2024-54369 9.1 CRITICAL 3 PoCs Analysis EPSS 0.19
ThemeHunk Zita Site Builder <1.0.2 - Info Disclosure
Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Zita Site Builder: from n/a through <= 1.0.2.
CWE-862 Dec 16, 2024