Critical Vulnerabilities with Public Exploits

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,482 CVEs tracked 53,635 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,335 vendors 43,883 researchers
4,103 results Clear all
CVE-2023-25725 9.1 CRITICAL 1 PoC Analysis EPSS 0.20
Haproxy < 2.0.31 - HTTP Request Smuggling
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.
CWE-444 Feb 14, 2023
CVE-2023-31069 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
TSplus Remote Access <16.0.2.14 - Info Disclosure
An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page.
CWE-312 Sep 11, 2023
CVE-2023-31068 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
TSplus Remote Access <16.0.2.14 - Info Disclosure
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes.
CWE-276 Sep 11, 2023
CVE-2023-31067 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
TSplus Remote Access <16.0.2.14 - Info Disclosure
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www.
CWE-276 Sep 11, 2023
CVE-2023-37759 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Trendylogics Crypto Currency Tracker < 9.5 - Improper Access Control
Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request.
CWE-284 Sep 08, 2023
CVE-2023-33242 9.6 CRITICAL 1 PoC Analysis EPSS 0.05
Crypto wallets - Info Disclosure
Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by exfiltrating a single bit in every signature attempt (256 in total) because of not adhering to the paper's security proof's assumption regarding handling aborts after a failed signature.
CWE-74 Aug 09, 2023
CVE-2023-37068 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Sherlock Gym Management System - SQL Injection
Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username and password fields, enabling SQL Injection attacks.
CWE-89 Aug 09, 2023
CVE-2023-39526 9.1 CRITICAL 1 PoC Analysis EPSS 0.11
Prestashop < 1.7.8.10 - SQL Injection
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.
CWE-89 Aug 07, 2023
CVE-2023-39115 9.8 CRITICAL 3 PoCs Analysis EPSS 0.02
Campcodes Online Matrimonial Website System Script <3.3 - XSS
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.
CWE-434 Aug 16, 2023
CVE-2023-38632 9.8 CRITICAL 1 PoC Analysis EPSS 0.27
async-sockets-cpp <0.3.1 - Buffer Overflow
async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in tcpsocket.hpp when processing malformed TCP packets.
CWE-787 Jul 21, 2023
CVE-2023-43131 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
General Device Manager 2.5.2.2 - Buffer Overflow
General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow.
CWE-120 Sep 25, 2023
CVE-2023-34635 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Wifi-soft Unibox Administration - SQL Injection
Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page.
CWE-89 Jul 31, 2023
CVE-2023-37771 9.8 CRITICAL 1 PoC Analysis EPSS 0.05
Phpgurukul Art Gallery Management System - SQL Injection
Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.
CWE-89 Jul 31, 2023
CVE-2023-53895 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
PimpMyLog 1.7.14 - XSS
PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization through the configuration endpoint. Attackers can exploit the unsanitized username field to inject malicious JavaScript, create a hidden backdoor account, and potentially access sensitive server-side log information and environmental variables.
CWE-285 Dec 16, 2025
CVE-2023-53894 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
phpfm 1.7.9 - Auth Bypass
phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server.
CWE-1390 Dec 16, 2025
CVE-2023-37629 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.87
Simple Online Piggery Management System - Unrestricted File Upload
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php."
CWE-434 Jul 12, 2023
CVE-2023-32117 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.88
SoftLab Integrate Google Drive - Info Disclosure
Missing Authorization vulnerability in princeahmed Integrate Google Drive integrate-google-drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through <= 1.1.99.
CWE-862 Dec 09, 2024
CVE-2023-33592 9.8 CRITICAL 2 PoCs Analysis EPSS 0.02
Lost and Found Information System v1.0 - SQL Injection
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.
CWE-89 Jun 28, 2023
CVE-2023-31704 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Oretnom23 Online Computer And Laptop Store - Incorrect Authorization
Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role.
CWE-863 Jul 13, 2023
CVE-2023-35803 9.8 CRITICAL 1 PoC Analysis EPSS 0.05
Extremenetworks IQ Engine < 10.6r2 - Buffer Overflow
IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow.
CWE-120 Oct 04, 2023