Critical Vulnerabilities with Public Exploits
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2024-10571
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.87
Ays-pro Chartify < 2.9.6 - Remote File Inclusion
The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
CWE-98
Nov 14, 2024
CVE-2024-3605
10.0
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.79
Thimpress WP Hotel Booking < 2.1.0 - SQL Injection
The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CWE-89
Jun 20, 2024
CVE-2024-50491
9.3
CRITICAL
1 PoC
Analysis
EPSS 0.38
Micahblu Rsvp ME < 1.9.9 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME rsvp-me allows SQL Injection.This issue affects RSVP ME: from n/a through <= 1.9.9.
CWE-89
Oct 28, 2024
CVE-2024-36840
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.12
Boelter Blue System Management <1.3 - SQL Injection
SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter to news_details.php and location_details.php; and the section parameter to services.php.
CWE-89
Jun 12, 2024
CVE-2024-56064
10.0
CRITICAL
EXPLOITED
1 PoC
Analysis
EPSS 0.56
Azzaroco WP SuperBackup <2.3.3 - Code Injection
Unrestricted Upload of File with Dangerous Type vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Upload a Web Shell to a Web Server.This issue affects WP SuperBackup: from n/a through <= 2.3.3.
CWE-434
Dec 31, 2024
CVE-2024-11613
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.75
WordPress File Upload <4.24.15 - RCE
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of proper sanitization of the 'source' parameter and allowing a user-defined directory path. This makes it possible for unauthenticated attackers to execute code on the server.
CWE-94
Jan 08, 2025
CVE-2024-54292
9.3
CRITICAL
1 PoC
Analysis
EPSS 0.04
Appsplate <2.1.3 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsplate Appsplate appsplate allows SQL Injection.This issue affects Appsplate: from n/a through <= 2.1.3.
CWE-89
Dec 13, 2024
CVE-2024-27115
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.82
SOPlanning - Remote Code Execution
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publicly accessible folder before verifying any requirements. This leads to the possibility of execution of code on the underlying system when the file is triggered. The vulnerability has been remediated in version 1.52.02.
CWE-434
Sep 11, 2024
CVE-2024-56278
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.43
Smackcoders WP Ultimate Exporter <2.9.1 - Code Injection
Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders Inc., WP Ultimate Exporter wp-ultimate-exporter allows PHP Remote File Inclusion.This issue affects WP Ultimate Exporter: from n/a through <= 2.9.1.
CWE-94
Jan 07, 2025
CVE-2024-55976
9.3
CRITICAL
1 PoC
Analysis
EPSS 0.30
Mike Leembruggen Critical Site Intel <1.0 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mikeleembruggen Critical Site Intel critical-site-intel-stats allows SQL Injection.This issue affects Critical Site Intel: from n/a through <= 1.0.
CWE-89
Dec 16, 2024
CVE-2024-55972
9.3
CRITICAL
1 PoC
Analysis
EPSS 0.08
eTemplates <0.2.1 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chriscarvache eTemplates etemplates allows SQL Injection.This issue affects eTemplates: from n/a through <= 0.2.1.
CWE-89
Dec 16, 2024
CVE-2024-55981
9.3
CRITICAL
1 PoC
Analysis
EPSS 0.20
Nabz Image Gallery <v1.00 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nabajit Roy Nabz Image Gallery nabz-image-gallery allows SQL Injection.This issue affects Nabz Image Gallery: from n/a through <= v1.00.
CWE-89
Dec 16, 2024
CVE-2024-55982
9.3
CRITICAL
1 PoC
Analysis
EPSS 0.26
Richteam Share Buttons - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in richteam Share Buttons – Social Media rich-web-share-button allows Blind SQL Injection.This issue affects Share Buttons – Social Media: from n/a through <= 1.0.2.
CWE-89
Dec 16, 2024
CVE-2024-55988
9.3
CRITICAL
1 PoC
Analysis
EPSS 0.27
Amol Nirmala Waman Navayan CSV Export <1.0.9 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Amol Nirmala Waman Navayan CSV Export navayan-csv-export allows Blind SQL Injection.This issue affects Navayan CSV Export: from n/a through <= 1.0.9.
CWE-89
Dec 16, 2024
CVE-2024-50944
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
SimplCommerce - Buffer Overflow
Integer overflow vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f in the shopping cart functionality. The issue lies in the quantity parameter in the CartController's AddToCart method.
CWE-190
Dec 27, 2024
CVE-2024-55978
9.3
CRITICAL
1 PoC
Analysis
EPSS 0.05
WalletStation.com Code Generator Pro - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WalletStation Code Generator Pro code-generator-pro allows SQL Injection.This issue affects Code Generator Pro: from n/a through <= 1.2.
CWE-89
Dec 16, 2024
CVE-2024-55980
9.3
CRITICAL
1 PoC
Analysis
EPSS 0.05
Webriderz Wr Age Verification <2.0.0 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robindkumar Wr Age Verification wr-age-verification allows SQL Injection.This issue affects Wr Age Verification: from n/a through <= 2.0.0.
CWE-89
Dec 16, 2024
CVE-2024-54819
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.44
I, Librarian <5.11.1 - SSRF
I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation in classes/security/validation.php
CWE-918
Jan 07, 2025
CVE-2024-55557
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.17
Weasis 4.5.1 - Info Disclosure
ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials.
CWE-798
Dec 16, 2024
CVE-2024-56431
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Theora <1.0 - Buffer Overflow
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
CWE-863
Dec 25, 2024