Critical Vulnerabilities with Public Exploits
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,103 results
Clear all
CVE-2023-6567
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.82
LearnPress <4.2.5.7 - SQL Injection
The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CWE-89
Jan 11, 2024
CVE-2023-31446
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.93
Cassia Gateway firmware - Code Injection
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.
CWE-77
Jan 10, 2024
CVE-2023-51126
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.16
FLIR AX8 <1.49.16 - Command Injection
Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.
CWE-77
Jan 10, 2024
CVE-2023-50254
9.3
CRITICAL
1 PoC
Analysis
EPSS 0.09
Deepin Reader < 6.0.7 - Path Traversal
Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw that leads to remote command execution via crafted docx document. This is a file overwrite vulnerability. Remote code execution (RCE) can be achieved by overwriting files like .bash_rc, .bash_login, etc. RCE will be triggered when the user opens the terminal. Version 6.0.7 contains a patch for the issue.
CWE-22
Dec 22, 2023
CVE-2023-22524
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.35
Atlassian Companion < 2.0.0 - Remote Code Execution
Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.
Dec 06, 2023
CVE-2023-49989
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Pratham-jaiswal Hotel Booking Management System - SQL Injection
Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php.
CWE-89
Mar 07, 2024
CVE-2023-49970
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Oretnom23 Customer Support System - SQL Injection
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket.
CWE-89
Mar 05, 2024
CVE-2023-49547
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.08
Oretnom23 Customer Support System - SQL Injection
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login.
CWE-89
Mar 05, 2024
CVE-2023-49543
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Book Store Management System - Improper Access Control
Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions without authenticating.
CWE-284
Mar 01, 2024
CVE-2023-49954
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
3cx < 18.0.9.23 - SQL Injection
The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address.
CWE-89
Dec 25, 2023
CVE-2023-31546
9.6
CRITICAL
1 PoC
Analysis
EPSS 0.21
DedeBIZ v6.0.3 - XSS
Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.
CWE-79
Dec 14, 2023
CVE-2023-34034
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.48
Spring Security - SSRF
Using "**" as a pattern in Spring Security configuration
for WebFlux creates a mismatch in pattern matching between Spring
Security and Spring WebFlux, and the potential for a security bypass.
CWE-281
Jul 19, 2023
CVE-2023-49105
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.90
ownCloud <10.13.1 - Info Disclosure
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
CWE-287
Nov 21, 2023
CVE-2023-48849
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Ruijie EG Series Routers <EG_3.0(1)B11P216 - RCE
Ruijie EG Series Routers version EG_3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitrary code due to incorrect filtering.
Dec 06, 2023
CVE-2023-48842
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.27
D-Link Go-RT-AC750 - Command Injection
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.
CWE-78
Dec 01, 2023
CVE-2023-47840
9.9
CRITICAL
1 PoC
Analysis
EPSS 0.21
Qodeinteractive Qode Essential Addons < 1.5.2 - Code Injection
Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential Addons: from n/a through 1.5.2.
CWE-94
Dec 29, 2023
CVE-2023-49313
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.04
XMachOViewer 0.04 - Code Injection
A dylib injection vulnerability in XMachOViewer 0.04 allows attackers to compromise integrity. By exploiting this, unauthorized code can be injected into the product's processes, potentially leading to remote control and unauthorized access to sensitive user data.
CWE-94
Nov 28, 2023
CVE-2023-2982
9.8
CRITICAL
EXPLOITED
4 PoCs
Analysis
NUCLEI
EPSS 0.70
Miniorange Wordpress Social Login And... - Authentication Bypass
The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they know the email address associated with that user. This was partially patched in version 7.6.4 and fully patched in version 7.6.5.
CWE-288
Jun 29, 2023
CVE-2023-4699
10.0
CRITICAL
1 PoC
Analysis
EPSS 0.01
Mitsubishielectric Fx3u-32mt/es Firmware - Missing Authentication
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU modules, MELSEC iQ-F Series, MELSEC iQ-R series CPU modules, MELSEC iQ-R series, MELSEC iQ-L series, MELSEC Q series, MELSEC-L series, Mitsubishi Electric CNC M800V/M80V series, Mitsubishi Electric CNC M800/M80/E80 series and Mitsubishi Electric CNC M700V/M70V/E70 series allows a remote unauthenticated attacker to execute arbitrary commands by sending specific packets to the affected products. This could lead to disclose or tamper with information by reading or writing control programs, or cause a denial-of-service (DoS) condition on the products by resetting the memory contents of the products to factory settings or resetting the products remotely.
CWE-345
Nov 06, 2023
CVE-2023-42471
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Wave < 1.0.35 - Code Injection
The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to display web content and doesn't adequately validate or sanitize the URI or any extra data passed in the intent by a third party application (with no permissions).
CWE-94
Sep 11, 2023