Critical Vulnerabilities with Public Exploits

Updated 37m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,534 CVEs tracked 53,639 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,342 vendors 43,887 researchers
4,103 results Clear all
CVE-2023-26918 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Diasoft File Replication Pro 7.5.0 - Privilege Escalation
Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access.
CWE-276 Apr 14, 2023
CVE-2023-53950 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
InnovaStudio WYSIWYG Editor 5.4 - Unrestricted File Upload
InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions through filename manipulation. Attackers can upload malicious ASP shells by using null byte techniques and alternate file extensions to circumvent upload controls in the asset manager.
CWE-434 Dec 19, 2025
CVE-2023-53951 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Ever Gauzy <0.281.9 - Auth Bypass
Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can leverage the exposed JWT token to authenticate and gain unauthorized access with administrative permissions.
CWE-347 Dec 19, 2025
CVE-2023-27290 9.1 CRITICAL 1 PoC Analysis EPSS 0.09
IBM Instana - Info Disclosure
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.
CWE-306 Mar 03, 2023
CVE-2023-53959 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
FileZilla Client 3.63.1 - Code Injection
FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the application launches.
CWE-427 Dec 19, 2025
CVE-2023-53957 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Kimai <1.30.10 - XSS
Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.
CWE-1275 Dec 19, 2025
CVE-2023-52252 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Unifiedremote Unified Remote - XXE
Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.
CWE-611 Dec 30, 2023
CVE-2023-23156 9.8 CRITICAL 1 PoC Analysis EPSS 0.04
Phpgurukul Art Gallery Management System - SQL Injection
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.
CWE-89 Feb 27, 2023
CVE-2023-0777 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.76
Modoboa < 2.0.4 - Authentication Bypass
Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.
CWE-305 Feb 10, 2023
CVE-2023-53980 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
ProjectSend r1605 - RCE
ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Attackers can upload shell scripts with disguised extensions through the upload.process.php endpoint to execute arbitrary commands on the server.
CWE-434 Dec 22, 2025
CVE-2023-53966 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
SOUND4 LinkAndShare Transmitter 1.1.2 - Memory Corruption
SOUND4 LinkAndShare Transmitter 1.1.2 contains a format string vulnerability that allows attackers to trigger memory stack overflows through maliciously crafted environment variables. Attackers can manipulate the username environment variable with format string payloads to potentially execute arbitrary code and crash the application.
CWE-134 Dec 22, 2025
CVE-2023-0744 9.8 CRITICAL 1 PoC Analysis EPSS 0.09
Answer < 1.0.4 - Improper Access Control
Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.
CWE-284 Feb 08, 2023
CVE-2023-24775 9.8 CRITICAL 1 PoC Analysis EPSS 0.31
Funadmin v3.2.0 - SQL Injection
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.
CWE-89 Mar 07, 2023
CVE-2023-23163 9.8 CRITICAL 1 PoC Analysis EPSS 0.04
Phpgurukul Art Gallery Management System - SQL Injection
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.
CWE-89 Feb 10, 2023
CVE-2023-23162 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Phpgurukul Art Gallery Management System - SQL Injection
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.
CWE-89 Feb 10, 2023
CVE-2023-26866 9.8 CRITICAL 1 PoC Analysis EPSS 0.09
GreenPacket OH736 WR-1200 Indoor Unit, OT-235 - Command Injection
GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respectively are vulnerable to remote command injection. Commands are executed using pre-login execution and executed with root privileges allowing complete takeover.
CWE-77 Apr 04, 2023
CVE-2023-53964 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - RCE
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with specific data to trigger a factory reset and bypass authentication, gaining full system control.
CWE-306 Dec 22, 2025
CVE-2023-53963 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Command Injection
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit the login.php and index.php scripts by injecting shell commands via the 'password' POST parameter to execute commands with web server privileges.
CWE-78 Dec 22, 2025
CVE-2023-53960 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
SOUND4 IMPACT/FIRST/PULSE/Eco 2.x - SQL Injection
SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL code through the 'password' POST parameter to bypass authentication and potentially gain unauthorized access to the system.
CWE-89 Dec 22, 2025
CVE-2023-53955 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Auth Bypass
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-supplied input to execute privileged functionalities without proper authentication.
CWE-639 Dec 22, 2025