Critical Vulnerabilities with Public Exploits
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2024-54820
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
XOne Web Monitor <1.0.4.9 - SQL Injection
XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.
CWE-89
Feb 24, 2025
CVE-2024-1651
10.0
CRITICAL
4 PoCs
Analysis
EPSS 0.81
Torrentpier - Insecure Deserialization
Torrentpier version 2.4.1 allows executing arbitrary commands on the server.
This is possible because the application is vulnerable to insecure deserialization.
CWE-502
Feb 20, 2024
CVE-2024-13159
9.8
CRITICAL
KEV
1 PoC
Analysis
NUCLEI
EPSS 0.94
Ivanti EPM - Path Traversal
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
CWE-36
Jan 14, 2025
CVE-2024-8381
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.12
Firefox < 130 - Type Confusion
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
CWE-843
Sep 03, 2024
CVE-2024-55215
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.05
Jrohy Trojan < 2.15.3 - Incorrect Default Permissions
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.
CWE-276
Feb 07, 2025
CVE-2024-6624
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.43
JSON API User <3.9.3 - Privilege Escalation
The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin to also be installed.
CWE-269
Jul 11, 2024
CVE-2024-57430
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Phpjabbers Cinema Booking System - SQL Injection
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.
CWE-89
Feb 06, 2025
CVE-2024-57428
9.3
CRITICAL
1 PoC
Analysis
EPSS 0.02
Phpjabbers Cinema Booking System - XSS
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection, and session hijacking.
CWE-79
Feb 06, 2025
CVE-2024-44756
9.8
CRITICAL
1 PoC
1 Writeup
Analysis
EPSS 0.00
NUS-M9 ERP Mgmt SW v3.0.0 - SQL Injection
NUS-M9 ERP Management Software v3.0.0 was discovered to contain a SQL injection vulnerability via the usercode parameter at /UserWH/checkLogin.
CWE-89
Nov 18, 2024
CVE-2024-44758
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
NUS-M9 ERP Management Software <3.0.0 - Code Injection
An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to execute arbitrary code via uploading crafted files.
CWE-94
Nov 15, 2024
CVE-2024-44761
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
EQ Enterprise Management System <2.0.0 - Path Traversal
An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.
CWE-22
Aug 28, 2024
CVE-2024-30802
9.8
CRITICAL
1 PoC
1 Writeup
Analysis
EPSS 0.00
Vehicle Management System <7.31.0.3 - Privilege Escalation
An issue in Vehicle Management System 7.31.0.3_20230412 allows an attacker to escalate privileges via the login.html component.
CWE-1393
May 14, 2024
CVE-2024-54880
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.06
SeaCMS V13.1 - Privilege Escalation
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
CWE-281
Jan 06, 2025
CVE-2024-54239
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
dugudlabs Eyewear <4.0.18 - Privilege Escalation
Missing Authorization vulnerability in dugudlabs Eyewear prescription form eyewear-prescription-form allows Privilege Escalation.This issue affects Eyewear prescription form: from n/a through <= 4.0.18.
CWE-862
Dec 13, 2024
CVE-2024-54879
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.04
SeaCMS V13.1 - Privilege Escalation
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.
CWE-281
Jan 06, 2025
CVE-2024-38821
9.1
CRITICAL
2 PoCs
Analysis
EPSS 0.13
Org.springframework.security Spring-s... - Resource Allocation Without Limits
Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances.
For this to impact an application, all of the following must be true:
* It must be a WebFlux application
* It must be using Spring's static resources support
* It must have a non-permitAll authorization rule applied to the static resources support
CWE-770
Oct 28, 2024
CVE-2024-43468
9.8
CRITICAL
KEV
3 PoCs
Analysis
EPSS 0.83
Microsoft Configuration Manager 2403 - SQL Injection
Microsoft Configuration Manager Remote Code Execution Vulnerability
CWE-89
Oct 08, 2024
CVE-2024-36404
9.8
CRITICAL
1 PoC
1 Writeup
Analysis
NUCLEI
EPSS 0.91
GeoTools <31.2-30.4-29.6 - RCE
GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) is possible if an application uses certain GeoTools functionality to evaluate XPath expressions supplied by user input. Versions 31.2, 30.4, and 29.6 contain a fix for this issue. As a workaround, GeoTools can operate with reduced functionality by removing the `gt-complex` jar from one's application. As an example of the impact, application schema `datastore` would not function without the ability to use XPath expressions to query complex content. Alternatively, one may utilize a drop-in replacement GeoTools jar from SourceForge for versions 31.1, 30.3, 30.2, 29.2, 28.2, 27.5, 27.4, 26.7, 26.4, 25.2, and 24.0. These jars are for download only and are not available from maven central, intended to quickly provide a fix to affected applications.
CWE-95
Jul 02, 2024
CVE-2024-56059
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.27
Mighty Digital Partners <0.2.0 - Code Injection
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Partners partners allows Object Injection.This issue affects Partners: from n/a through <= 0.2.0.
CWE-1321
Dec 18, 2024
CVE-2024-56058
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.37
Gueststream VRPConnector <2.0.1 - Code Injection
Deserialization of Untrusted Data vulnerability in denniskravetstns VRPConnector vrpconnector allows Object Injection.This issue affects VRPConnector: from n/a through <= 2.0.1.
CWE-502
Dec 18, 2024