Critical Vulnerabilities with Public Exploits

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,482 CVEs tracked 53,635 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,335 vendors 43,883 researchers
4,103 results Clear all
CVE-2023-33668 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
DigiExam <14.0.2 - Info Disclosure
DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.
CWE-354 Jul 12, 2023
CVE-2023-53899 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
PodcastGenerator 3.2.9 - SSRF
PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.
CWE-918 Dec 16, 2025
CVE-2023-36355 9.9 CRITICAL 1 PoC Analysis EPSS 0.34
TP-Link TL-WR940N V4 - Buffer Overflow
TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
CWE-120 Jun 22, 2023
CVE-2023-25610 9.8 CRITICAL 1 PoC Analysis EPSS 0.16
Fortinet FortiOS <7.2.3 - RCE
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
CWE-124 Mar 24, 2025
CVE-2023-33404 9.8 CRITICAL 1 PoC Analysis EPSS 0.82
BlogEngine.Net <3.3.8.0 - RCE
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
CWE-434 Jun 26, 2023
CVE-2023-33476 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
ReadyMedia (MiniDLNA) <1.3.2 - Buffer Overflow
ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by incorrect validation logic when handling HTTP requests using chunked transport encoding. This results in other code later using attacker-controlled chunk values that exceed the length of the allocated buffer, resulting in out-of-bounds read/write.
CWE-787 Jun 02, 2023
CVE-2023-20126 9.8 CRITICAL 1 PoC Analysis EPSS 0.74
Cisco SPA112 - RCE
A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade function. An attacker could exploit this vulnerability by upgrading an affected device to a crafted version of firmware. A successful exploit could allow the attacker to execute arbitrary code on the affected device with full privileges. Cisco has not released firmware updates to address this vulnerability.
CWE-306 May 04, 2023
CVE-2023-34852 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Publiccms < 4.0.202302 - Incorrect Permission Assignment
PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.
CWE-732 Jun 15, 2023
CVE-2023-37152 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Online Art Gallery - Unrestricted File Upload
Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.
CWE-434 Jul 10, 2023
CVE-2023-36217 9.0 CRITICAL 1 PoC Analysis EPSS 0.04
Xoops CMS <2.5.10 - XSS
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.
CWE-79 Aug 03, 2023
CVE-2023-31541 9.8 CRITICAL 1 PoC Analysis EPSS 0.06
CKEditor v1.2.3 - File Upload
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.
CWE-434 Jun 13, 2023
CVE-2023-36213 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
MotoCMS <3.4.3 - SQL Injection
SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function.
CWE-89 Aug 03, 2023
CVE-2023-33584 9.8 CRITICAL 1 PoC Analysis EPSS 0.31
Sourcecodester Enrollment System Project V1.0 - SQL Injection
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields during the login process, enabling an attacker to inject malicious SQL code.
CWE-89 Jun 21, 2023
CVE-2023-36210 9.8 CRITICAL 1 PoC Analysis EPSS 0.10
MotoCMS 3.4.3 - SSTI
MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.
CWE-74 Aug 01, 2023
CVE-2023-33730 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Escanav Escan Management Console - Cleartext Transmission
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format.
CWE-319 May 31, 2023
CVE-2023-30145 9.8 CRITICAL 2 PoCs Analysis EPSS 0.53
Tuzitio Camaleon Cms < 2.7.0 - Code Injection
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.
CWE-94 May 26, 2023
CVE-2023-53914 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
UliCMS 2023.1 - Auth Bypass
UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpoint with specific parameters to generate an administrative account with full system access.
CWE-639 Dec 17, 2025
CVE-2023-34581 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Oretnom23 Service Provider Management System - SQL Injection
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2
CWE-89 Jun 12, 2023
CVE-2023-53968 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Screen SFT DAB 600/C Firmware 1.9.3 - Auth Bypass
Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to remove user accounts without proper authentication.
CWE-306 Dec 22, 2025
CVE-2023-53922 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
TinyWebGallery v2.5 - RCE
TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers can upload .phar files with embedded system commands to execute arbitrary code on the server by accessing the uploaded file's URL.
CWE-434 Dec 17, 2025