Critical Vulnerabilities with Public Exploits

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,482 CVEs tracked 53,635 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,335 vendors 43,883 researchers
4,103 results Clear all
CVE-2023-53921 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
SitemagicCMS 4.4.3 - RCE
SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar file with system command execution payload to compromise the web application and execute arbitrary system commands.
CWE-434 Dec 17, 2025
CVE-2023-53740 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Screen SFT DAB 1.9.3 - Auth Bypass
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account.
CWE-862 Dec 10, 2025
CVE-2023-37165 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Millhouse-project - SQL Injection
Millhouse-Project v1.414 was discovered to contain a remote code execution (RCE) vulnerability via the component /add_post_sql.php.
CWE-89 Jul 20, 2023
CVE-2023-31703 9.0 CRITICAL 2 PoCs Analysis EPSS 0.02
Microworld Technologies eScan <14.0.1400.2281 - XSS
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter.
CWE-79 May 17, 2023
CVE-2023-27823 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Optoma 1080pstx - Authentication Bypass
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.
CWE-295 May 12, 2023
CVE-2023-1934 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
PnPSCADA - SQL Injection
The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Present within the hitlogcsv.jsp endpoint, this security flaw permits unauthenticated attackers to engage with the underlying database seamlessly and passively. Consequently, malicious actors could gain access to vital information, such as Industrial Control System (ICS) and OT data, alongside other sensitive records like SMS and SMS Logs. The unauthorized database access exposes compromised systems to potential manipulation or breach of essential infrastructure data, highlighting the severity of this vulnerability.
CWE-89 May 12, 2023
CVE-2023-29919 9.1 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.92
Contec Solarview Compact Firmware - Incorrect Default Permissions
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.
CWE-276 May 23, 2023
CVE-2023-27742 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Idurar - SQL Injection
IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.
CWE-89 May 16, 2023
CVE-2023-30092 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Online Pizza Ordering System - SQL Injection
SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.
CWE-89 May 08, 2023
CVE-2023-30185 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Crmeb < 4.6.0 - Unrestricted File Upload
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.
CWE-434 May 08, 2023
CVE-2023-53941 9.8 CRITICAL 1 PoC Analysis EPSS 0.71
EasyPHP Webserver 14.1 - Command Injection
EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by injecting malicious payloads through the app_service_control parameter. Attackers can send POST requests to /index.php?zone=settings with crafted app_service_control values to execute commands with administrative privileges.
CWE-78 Dec 18, 2025
CVE-2023-53923 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
UliCMS 2023.1 - Privilege Escalation
UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php with specific parameters to generate a new admin user with full system access.
CWE-862 Dec 17, 2025
CVE-2023-29809 9.8 CRITICAL 2 PoCs Analysis EPSS 0.03
Companymaps - SQL Injection
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbitrary code via a crafted script in the request.
CWE-89 May 12, 2023
CVE-2023-25261 9.8 CRITICAL 1 PoC Analysis EPSS 0.11
Stimulsoft Designer - Code Injection
Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the local file system is not prohibited in any way. Therefore, an attacker may include source code which reads or writes local directories and files. It is also possible for the attacker to prepare a report which has a variable that holds the gathered data and render it in the report.
CWE-94 Mar 27, 2023
CVE-2023-53926 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
PHPJabbers Simple CMS 5.0 - SQL Injection
PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. Attackers can inject crafted SQL payloads through the 'column' parameter in the index.php endpoint to potentially extract or modify database information.
CWE-89 Dec 17, 2025
CVE-2023-30330 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Softexpert Excellence Suite < 2.1.3 - Untrusted Search Path
SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php.
CWE-426 May 12, 2023
CVE-2023-20025 9.0 CRITICAL 1 PoC Analysis EPSS 0.00
Cisco Small Business RV016-082 - Auth Bypass
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to bypass authentication and gain root access on the underlying operating system.
CWE-290 Jan 20, 2023
CVE-2023-30839 9.9 CRITICAL 1 PoC Analysis EPSS 0.09
Prestashop < 1.7.8.9 - SQL Injection
PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can write, update, and delete in the database, even without having specific rights. PrestaShop 8.0.4 and 1.7.8.9 contain a patch for this issue. There are no known workarounds.
CWE-89 Apr 25, 2023
CVE-2023-25234 9.8 CRITICAL 1 PoC Analysis EPSS 0.34
Tenda Ac500 Firmware - Out-of-Bounds Write
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface.
CWE-787 Feb 27, 2023
CVE-2023-53948 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Lilac-Reloaded for Nagios 2.0.8 - RCE
Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows attackers to inject arbitrary commands. Attackers can exploit the lack of input filtering in the nmap_binary parameter to execute a reverse shell by sending a crafted POST request to the autodiscovery endpoint.
CWE-78 Dec 19, 2025