Critical Vulnerabilities with Public Exploits

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,482 CVEs tracked 53,635 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,335 vendors 43,883 researchers
4,103 results Clear all
CVE-2023-46954 9.8 CRITICAL 1 PoC Analysis EPSS 0.04
RelativityOne <12.1.537.3 - SQL Injection
SQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacker to execute arbitrary code via the name parameter.
CWE-89 Nov 03, 2023
CVE-2023-43955 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
TV Bro <2.0.0 - RCE
The com.phlox.tvwebbrowser TV Bro application through 2.0.0 for Android mishandles external intents through WebView. This allows attackers to execute arbitrary code, create arbitrary files. and perform arbitrary downloads via JavaScript that uses takeBlobDownloadData.
CWE-94 Dec 27, 2023
CVE-2023-37903 9.8 CRITICAL 1 PoC Analysis EPSS 0.36
Vm2 < 3.9.19 - OS Command Injection
vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to escape the sandbox and run arbitrary code. This may result in Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox. There are no patches and no known workarounds. Users are advised to find an alternative software.
CWE-78 Jul 21, 2023
CVE-2023-46980 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
Best Courier Management System <1.0 - RCE
An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.
CWE-94 Nov 03, 2023
CVE-2023-46501 9.1 CRITICAL 1 PoC Analysis EPSS 0.11
BoltWire <6.03 - Info Disclosure
An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function.
CWE-284 Nov 07, 2023
CVE-2023-42283 9.8 CRITICAL 1 PoC Analysis EPSS 0.11
Tyk - SQL Injection
Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.
CWE-89 Nov 07, 2023
CVE-2023-42284 9.8 CRITICAL 1 PoC Analysis EPSS 0.09
Tyk - SQL Injection
Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.
CWE-89 Nov 07, 2023
CVE-2023-46404 9.9 CRITICAL 1 PoC Analysis EPSS 0.34
PCRS <3.11 - RCE
PCRS <= 3.11 (d0de1e) “Questions” page and “Code editor” page are vulnerable to remote code execution (RCE) by escaping Python sandboxing.
CWE-94 Nov 03, 2023
CVE-2023-34051 9.8 CRITICAL 1 PoC Analysis EPSS 0.58
VMware Aria Operations for Logs - RCE
VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
CWE-863 Oct 20, 2023
CVE-2023-45657 9.8 CRITICAL 1 PoC Analysis EPSS 0.12
Posimyth Nexter < 2.0.4 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSIMYTH Nexter allows SQL Injection.This issue affects Nexter: from n/a through 2.0.3.
CWE-89 Nov 06, 2023
CVE-2023-36076 9.8 CRITICAL 1 PoC Analysis EPSS 0.44
smanga <3.1.9 - SQL Injection
SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive information via mediaId, mangaId, and userId parameters in php/history/add.php.
CWE-89 Sep 01, 2023
CVE-2023-45992 9.6 CRITICAL 1 PoC Analysis EPSS 0.01
RUCKUS Cloudpath <5.12.5538 - XSS/CSRF
A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.
CWE-352 Oct 19, 2023
CVE-2023-43144 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Assets-management-system-in-php 1.0 - SQL Injection
Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.
CWE-89 Sep 22, 2023
CVE-2023-22855 9.8 CRITICAL 2 PoCs Analysis EPSS 0.62
Kardex Control Center - Code Injection
Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path is handed to a path-concatenation method (Path.Combine from .NET) without proper sanitisation. This yields the possibility of including local files, as well as remote files on SMB shares. If one provides a file with the extension .t4, it is rendered with the .NET templating engine mono/t4, which can execute code.
CWE-94 Feb 15, 2023
CVE-2023-5521 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Kernelsu < 0.6.9 - Incorrect Authorization
Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.
CWE-863 Oct 11, 2023
CVE-2023-54327 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Tinycontrol Lan Controller Firmware < 1.58a - Missing Authorization
Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.
CWE-862 Dec 30, 2025
CVE-2023-24538 9.8 CRITICAL 2 PoCs Analysis EPSS 0.01
Go Templates - Code Injection via JavaScript Template Literals
Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. "var a = {{.}}"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template.Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmpllitinterp=1, with the caveat that backticks will now be escaped. This should be used with caution.
CWE-94 Apr 06, 2023
CVE-2023-20918 9.8 CRITICAL 2 PoCs Analysis EPSS 0.01
Google Android - XXE
In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused deputy with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-611 Jul 13, 2023
CVE-2023-43154 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Macros CMS 1.1.4f - Auth Bypass
In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account.
CWE-843 Sep 27, 2023
CVE-2023-40989 9.8 CRITICAL 1 PoC Analysis EPSS 0.43
Jeecg-boot <3.5.3 - SQL Injection
SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component.
CWE-89 Sep 22, 2023