Critical Vulnerabilities with Public Exploits
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,103 results
Clear all
CVE-2023-25725
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.20
Haproxy < 2.0.31 - HTTP Request Smuggling
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.
CWE-444
Feb 14, 2023
CVE-2023-31069
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
TSplus Remote Access <16.0.2.14 - Info Disclosure
An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page.
CWE-312
Sep 11, 2023
CVE-2023-31068
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
TSplus Remote Access <16.0.2.14 - Info Disclosure
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes.
CWE-276
Sep 11, 2023
CVE-2023-31067
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
TSplus Remote Access <16.0.2.14 - Info Disclosure
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www.
CWE-276
Sep 11, 2023
CVE-2023-37759
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Trendylogics Crypto Currency Tracker < 9.5 - Improper Access Control
Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request.
CWE-284
Sep 08, 2023
CVE-2023-33242
9.6
CRITICAL
1 PoC
Analysis
EPSS 0.05
Crypto wallets - Info Disclosure
Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by exfiltrating a single bit in every signature attempt (256 in total) because of not adhering to the paper's security proof's assumption regarding handling aborts after a failed signature.
CWE-74
Aug 09, 2023
CVE-2023-37068
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Sherlock Gym Management System - SQL Injection
Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username and password fields, enabling SQL Injection attacks.
CWE-89
Aug 09, 2023
CVE-2023-39526
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.11
Prestashop < 1.7.8.10 - SQL Injection
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.
CWE-89
Aug 07, 2023
CVE-2023-39115
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.02
Campcodes Online Matrimonial Website System Script <3.3 - XSS
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.
CWE-434
Aug 16, 2023
CVE-2023-38632
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.27
async-sockets-cpp <0.3.1 - Buffer Overflow
async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in tcpsocket.hpp when processing malformed TCP packets.
CWE-787
Jul 21, 2023
CVE-2023-43131
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
General Device Manager 2.5.2.2 - Buffer Overflow
General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow.
CWE-120
Sep 25, 2023
CVE-2023-34635
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Wifi-soft Unibox Administration - SQL Injection
Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page.
CWE-89
Jul 31, 2023
CVE-2023-37771
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.05
Phpgurukul Art Gallery Management System - SQL Injection
Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.
CWE-89
Jul 31, 2023
CVE-2023-53895
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
PimpMyLog 1.7.14 - XSS
PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization through the configuration endpoint. Attackers can exploit the unsanitized username field to inject malicious JavaScript, create a hidden backdoor account, and potentially access sensitive server-side log information and environmental variables.
CWE-285
Dec 16, 2025
CVE-2023-53894
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
phpfm 1.7.9 - Auth Bypass
phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server.
CWE-1390
Dec 16, 2025
CVE-2023-37629
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.87
Simple Online Piggery Management System - Unrestricted File Upload
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php."
CWE-434
Jul 12, 2023
CVE-2023-32117
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.88
SoftLab Integrate Google Drive - Info Disclosure
Missing Authorization vulnerability in princeahmed Integrate Google Drive integrate-google-drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through <= 1.1.99.
CWE-862
Dec 09, 2024
CVE-2023-33592
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.02
Lost and Found Information System v1.0 - SQL Injection
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.
CWE-89
Jun 28, 2023
CVE-2023-31704
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Oretnom23 Online Computer And Laptop Store - Incorrect Authorization
Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role.
CWE-863
Jul 13, 2023
CVE-2023-35803
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.05
Extremenetworks IQ Engine < 10.6r2 - Buffer Overflow
IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow.
CWE-120
Oct 04, 2023