Critical Vulnerabilities with Public Exploits

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,432 CVEs tracked 53,633 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,306 vendors 43,872 researchers
4,101 results Clear all
CVE-2024-10508 9.8 CRITICAL 2 PoCs Analysis EPSS 0.15
Metagauss Registrationmagic < 6.0.2.7 - Privilege Escalation
The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0.2.6. This is due to the plugin not properly validating the password reset token prior to updating a user's password. This makes it possible for unauthenticated attackers to reset the password of arbitrary users, including administrators, and gain access to these accounts.
CWE-230 Nov 09, 2024
CVE-2024-52316 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Apache Tomcat - Unchecked Error Condition
Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fix the issue.
CWE-754 Nov 18, 2024
CVE-2024-1698 9.8 CRITICAL EXPLOITED 3 PoCs Analysis NUCLEI EPSS 0.94
Wpdeveloper Notificationx < 2.8.3 - SQL Injection
The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CWE-89 Feb 27, 2024
CVE-2024-10245 9.8 CRITICAL 1 PoC Analysis EPSS 0.36
Relais 2FA plugin <1.0 - Auth Bypass
The Relais 2FA plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0. This is due to incorrect authentication and capability checking in the 'rl_do_ajax' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
CWE-288 Nov 12, 2024
CVE-2024-32640 9.8 CRITICAL EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.94
MASA CMS <7.4.5-7.2.7 - SQL Injection
MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.
CWE-89 Aug 11, 2025
CVE-2024-51747 9.1 CRITICAL 1 PoC Analysis EPSS 0.01
Kanboard - Path Traversal
Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delete arbitrary files from the server. File attachments, that are viewable or downloadable in Kanboard are resolved through its `path` entry in the `project_has_files` SQLite db. Thus, an attacker who can upload a modified sqlite.db through the dedicated feature, can set arbitrary file links, by abusing path traversals. Once the modified db is uploaded and the project page is accessed, a file download can be triggered and all files, readable in the context of the Kanboard application permissions, can be downloaded. This issue has been addressed in version 1.2.42 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
CWE-22 Nov 11, 2024
CVE-2024-54756 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
ZDoom Team GZDoom <4.13.1 - RCE
A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted PK3 file containing a malicious ZScript source file.
CWE-94 Feb 20, 2025
CVE-2024-25292 9.6 CRITICAL 1 PoC Analysis EPSS 0.12
RenderTune 1.1.4 - XSS
Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Upload Title parameter.
CWE-79 Feb 29, 2024
CVE-2024-49368 9.8 CRITICAL 1 PoC Analysis EPSS 0.58
Nginxui Nginx UI < 1.9.9-4 - Improper Input Validation
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 fixes this issue.
CWE-20 Oct 21, 2024
CVE-2024-50493 10.0 CRITICAL 1 PoC Analysis EPSS 0.56
masterhomepage <1.0.4 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation automatic-translation allows Upload a Web Shell to a Web Server.This issue affects Automatic Translation: from n/a through <= 1.0.4.
CWE-434 Oct 29, 2024
CVE-2024-49607 10.0 CRITICAL 1 PoC Analysis EPSS 0.23
Redwan Hilali WP Dropbox Dropins - Unrestricted Upload
Unrestricted Upload of File with Dangerous Type vulnerability in redhopit WP Dropbox Dropins wp-dropbox-dropins allows Upload a Web Shell to a Web Server.This issue affects WP Dropbox Dropins: from n/a through <= 1.0.
CWE-434 Oct 20, 2024
CVE-2024-49681 9.3 CRITICAL 1 PoC Analysis EPSS 0.51
SWIT WP Sessions Time Monitoring Full Automatic <1.0.9 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.0.9.
CWE-89 Oct 24, 2024
CVE-2024-51132 9.8 CRITICAL 1 PoC Analysis EPSS 0.08
Ca.uhn.hapi.fhir Org.hl7.fhir.convertors < 6.4.0 - XXE
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
CWE-611 Nov 05, 2024
CVE-2024-50473 10.0 CRITICAL 1 PoC Analysis EPSS 0.62
Ajar in5 Embed <3.1.3 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through <= 3.1.3.
CWE-434 Oct 29, 2024
CVE-2024-50427 9.9 CRITICAL 1 PoC Analysis EPSS 0.70
SurveyJS: Drag & Drop WordPress Form Builder <= 1.9.136 - Unrestricted File Upload
Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects SurveyJS: from n/a through <= 1.9.136.
CWE-434 Oct 29, 2024
CVE-2024-38124 9.0 CRITICAL 1 PoC Analysis EPSS 0.00
Windows Netlogon < - Privilege Escalation
Windows Netlogon Elevation of Privilege Vulnerability
CWE-287 Oct 08, 2024
CVE-2024-50478 9.8 CRITICAL 1 PoC Analysis EPSS 0.29
Swoopnow 1-click Login - Authentication Bypass
Authentication Bypass by Primary Weakness vulnerability in swoopbrandon 1-Click Login: Passwordless Authentication swoop-password-free-authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: from n/a through 1.4.5.
CWE-287 Oct 28, 2024
CVE-2024-50483 9.8 CRITICAL 1 PoC Analysis EPSS 0.54
Tareqhasan Meetup < 0.1 - IDOR
Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: from n/a through <= 0.1.
CWE-639 Oct 28, 2024
CVE-2024-50482 10.0 CRITICAL 1 PoC Analysis EPSS 0.56
Chetan Khandla Woocommerce Product Design <1.0.0 - Code Injection
Unrestricted Upload of File with Dangerous Type vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Upload a Web Shell to a Web Server.This issue affects Woocommerce Product Design: from n/a through <= 1.0.0.
CWE-434 Oct 29, 2024
CVE-2024-50485 9.8 CRITICAL 1 PoC Analysis EPSS 0.22
Udit Rawat Exam Matrix <1.5 - Privilege Escalation
Incorrect Privilege Assignment vulnerability in Udit Rawat Exam Matrix exam-matrix allows Privilege Escalation.This issue affects Exam Matrix: from n/a through <= 1.5.
CWE-266 Oct 29, 2024