Critical Vulnerabilities with Public Exploits
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,103 results
Clear all
CVE-2023-33668
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
DigiExam <14.0.2 - Info Disclosure
DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.
CWE-354
Jul 12, 2023
CVE-2023-53899
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
PodcastGenerator 3.2.9 - SSRF
PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.
CWE-918
Dec 16, 2025
CVE-2023-36355
9.9
CRITICAL
1 PoC
Analysis
EPSS 0.34
TP-Link TL-WR940N V4 - Buffer Overflow
TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
CWE-120
Jun 22, 2023
CVE-2023-25610
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.16
Fortinet FortiOS <7.2.3 - RCE
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
CWE-124
Mar 24, 2025
CVE-2023-33404
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.82
BlogEngine.Net <3.3.8.0 - RCE
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
CWE-434
Jun 26, 2023
CVE-2023-33476
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
ReadyMedia (MiniDLNA) <1.3.2 - Buffer Overflow
ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by incorrect validation logic when handling HTTP requests using chunked transport encoding. This results in other code later using attacker-controlled chunk values that exceed the length of the allocated buffer, resulting in out-of-bounds read/write.
CWE-787
Jun 02, 2023
CVE-2023-20126
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.74
Cisco SPA112 - RCE
A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade function. An attacker could exploit this vulnerability by upgrading an affected device to a crafted version of firmware. A successful exploit could allow the attacker to execute arbitrary code on the affected device with full privileges. Cisco has not released firmware updates to address this vulnerability.
CWE-306
May 04, 2023
CVE-2023-34852
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Publiccms < 4.0.202302 - Incorrect Permission Assignment
PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.
CWE-732
Jun 15, 2023
CVE-2023-37152
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Online Art Gallery - Unrestricted File Upload
Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.
CWE-434
Jul 10, 2023
CVE-2023-36217
9.0
CRITICAL
1 PoC
Analysis
EPSS 0.04
Xoops CMS <2.5.10 - XSS
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.
CWE-79
Aug 03, 2023
CVE-2023-31541
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.06
CKEditor v1.2.3 - File Upload
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.
CWE-434
Jun 13, 2023
CVE-2023-36213
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
MotoCMS <3.4.3 - SQL Injection
SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function.
CWE-89
Aug 03, 2023
CVE-2023-33584
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.31
Sourcecodester Enrollment System Project V1.0 - SQL Injection
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields during the login process, enabling an attacker to inject malicious SQL code.
CWE-89
Jun 21, 2023
CVE-2023-36210
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.10
MotoCMS 3.4.3 - SSTI
MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.
CWE-74
Aug 01, 2023
CVE-2023-33730
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Escanav Escan Management Console - Cleartext Transmission
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format.
CWE-319
May 31, 2023
CVE-2023-30145
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.53
Tuzitio Camaleon Cms < 2.7.0 - Code Injection
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.
CWE-94
May 26, 2023
CVE-2023-53914
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
UliCMS 2023.1 - Auth Bypass
UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpoint with specific parameters to generate an administrative account with full system access.
CWE-639
Dec 17, 2025
CVE-2023-34581
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Oretnom23 Service Provider Management System - SQL Injection
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2
CWE-89
Jun 12, 2023
CVE-2023-53968
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Screen SFT DAB 600/C Firmware 1.9.3 - Auth Bypass
Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to remove user accounts without proper authentication.
CWE-306
Dec 22, 2025
CVE-2023-53922
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
TinyWebGallery v2.5 - RCE
TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers can upload .phar files with embedded system commands to execute arbitrary code on the server by accessing the uploaded file's URL.
CWE-434
Dec 17, 2025