Critical Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,432 CVEs tracked 53,633 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,306 vendors 43,872 researchers
4,101 results Clear all
CVE-2024-54820 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
XOne Web Monitor <1.0.4.9 - SQL Injection
XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.
CWE-89 Feb 24, 2025
CVE-2024-1651 10.0 CRITICAL 4 PoCs Analysis EPSS 0.81
Torrentpier - Insecure Deserialization
Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.
CWE-502 Feb 20, 2024
CVE-2024-13159 9.8 CRITICAL KEV 1 PoC Analysis NUCLEI EPSS 0.94
Ivanti EPM - Path Traversal
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
CWE-36 Jan 14, 2025
CVE-2024-8381 9.8 CRITICAL 1 PoC Analysis EPSS 0.12
Firefox < 130 - Type Confusion
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
CWE-843 Sep 03, 2024
CVE-2024-55215 9.8 CRITICAL 1 PoC Analysis EPSS 0.05
Jrohy Trojan < 2.15.3 - Incorrect Default Permissions
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.
CWE-276 Feb 07, 2025
CVE-2024-6624 9.8 CRITICAL 2 PoCs Analysis EPSS 0.43
JSON API User <3.9.3 - Privilege Escalation
The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin to also be installed.
CWE-269 Jul 11, 2024
CVE-2024-57430 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Phpjabbers Cinema Booking System - SQL Injection
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.
CWE-89 Feb 06, 2025
CVE-2024-57428 9.3 CRITICAL 1 PoC Analysis EPSS 0.02
Phpjabbers Cinema Booking System - XSS
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection, and session hijacking.
CWE-79 Feb 06, 2025
CVE-2024-44756 9.8 CRITICAL 1 PoC 1 Writeup Analysis EPSS 0.00
NUS-M9 ERP Mgmt SW v3.0.0 - SQL Injection
NUS-M9 ERP Management Software v3.0.0 was discovered to contain a SQL injection vulnerability via the usercode parameter at /UserWH/checkLogin.
CWE-89 Nov 18, 2024
CVE-2024-44758 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
NUS-M9 ERP Management Software <3.0.0 - Code Injection
An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to execute arbitrary code via uploading crafted files.
CWE-94 Nov 15, 2024
CVE-2024-44761 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
EQ Enterprise Management System <2.0.0 - Path Traversal
An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.
CWE-22 Aug 28, 2024
CVE-2024-30802 9.8 CRITICAL 1 PoC 1 Writeup Analysis EPSS 0.00
Vehicle Management System <7.31.0.3 - Privilege Escalation
An issue in Vehicle Management System 7.31.0.3_20230412 allows an attacker to escalate privileges via the login.html component.
CWE-1393 May 14, 2024
CVE-2024-54880 9.1 CRITICAL 1 PoC Analysis EPSS 0.06
SeaCMS V13.1 - Privilege Escalation
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
CWE-281 Jan 06, 2025
CVE-2024-54239 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
dugudlabs Eyewear <4.0.18 - Privilege Escalation
Missing Authorization vulnerability in dugudlabs Eyewear prescription form eyewear-prescription-form allows Privilege Escalation.This issue affects Eyewear prescription form: from n/a through <= 4.0.18.
CWE-862 Dec 13, 2024
CVE-2024-54879 9.1 CRITICAL 1 PoC Analysis EPSS 0.04
SeaCMS V13.1 - Privilege Escalation
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.
CWE-281 Jan 06, 2025
CVE-2024-38821 9.1 CRITICAL 2 PoCs Analysis EPSS 0.13
Org.springframework.security Spring-s... - Resource Allocation Without Limits
Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this to impact an application, all of the following must be true: * It must be a WebFlux application * It must be using Spring's static resources support * It must have a non-permitAll authorization rule applied to the static resources support
CWE-770 Oct 28, 2024
CVE-2024-43468 9.8 CRITICAL KEV 3 PoCs Analysis EPSS 0.83
Microsoft Configuration Manager 2403 - SQL Injection
Microsoft Configuration Manager Remote Code Execution Vulnerability
CWE-89 Oct 08, 2024
CVE-2024-36404 9.8 CRITICAL 1 PoC 1 Writeup Analysis NUCLEI EPSS 0.91
GeoTools <31.2-30.4-29.6 - RCE
GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) is possible if an application uses certain GeoTools functionality to evaluate XPath expressions supplied by user input. Versions 31.2, 30.4, and 29.6 contain a fix for this issue. As a workaround, GeoTools can operate with reduced functionality by removing the `gt-complex` jar from one's application. As an example of the impact, application schema `datastore` would not function without the ability to use XPath expressions to query complex content. Alternatively, one may utilize a drop-in replacement GeoTools jar from SourceForge for versions 31.1, 30.3, 30.2, 29.2, 28.2, 27.5, 27.4, 26.7, 26.4, 25.2, and 24.0. These jars are for download only and are not available from maven central, intended to quickly provide a fix to affected applications.
CWE-95 Jul 02, 2024
CVE-2024-56059 9.8 CRITICAL 1 PoC Analysis EPSS 0.27
Mighty Digital Partners <0.2.0 - Code Injection
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Partners partners allows Object Injection.This issue affects Partners: from n/a through <= 0.2.0.
CWE-1321 Dec 18, 2024
CVE-2024-56058 9.8 CRITICAL 1 PoC Analysis EPSS 0.37
Gueststream VRPConnector <2.0.1 - Code Injection
Deserialization of Untrusted Data vulnerability in denniskravetstns VRPConnector vrpconnector allows Object Injection.This issue affects VRPConnector: from n/a through <= 2.0.1.
CWE-502 Dec 18, 2024