Critical Vulnerabilities with Public Exploits

Updated 54m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,544 CVEs tracked 53,640 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,344 vendors 43,890 researchers
4,104 results Clear all
CVE-2022-42889 9.8 CRITICAL EXPLOITED 62 PoCs Analysis NUCLEI EPSS 0.94
Apache Commons Text < 1.10.0 - Code Injection
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.
CWE-94 Oct 13, 2022
CVE-2022-22965 9.8 CRITICAL KEV RANSOMWARE 119 PoCs Analysis NUCLEI EPSS 0.94
Vmware Spring Framework < 5.2.20 - Code Injection
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
CWE-94 Apr 01, 2022
CVE-2022-0543 10.0 CRITICAL KEV 9 PoCs Analysis NUCLEI EPSS 0.94
Redis Lua Sandbox Escape
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
CWE-862 Feb 18, 2022
CVE-2022-31706 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.90
Vmware Vrealize Log Insight < 4.8 - Path Traversal
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
CWE-22 Jan 26, 2023
CVE-2022-31704 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.90
Vmware Vrealize Log Insight < 4.8 - Improper Access Control
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.
CWE-284 Jan 26, 2023
CVE-2022-48114 9.8 CRITICAL 1 PoC EPSS 0.00
Ruoyi < 4.7.5 - SQL Injection
RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.
CWE-89 Feb 02, 2023
CVE-2022-44089 9.8 CRITICAL 1 PoC EPSS 0.03
ESPCMS P8.21120101 - RCE
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
CWE-94 Nov 10, 2022
CVE-2022-44088 9.8 CRITICAL 1 PoC EPSS 0.04
ESPCMS <P8.21120101 - RCE
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.
CWE-94 Nov 10, 2022
CVE-2022-44087 9.8 CRITICAL 1 PoC EPSS 0.03
ESPCMS <P8.21120101 - RCE
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.
CWE-94 Nov 10, 2022
CVE-2022-35150 9.8 CRITICAL 1 PoC 1 Writeup Analysis EPSS 0.00
Baijiacms - Unrestricted File Upload
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.
CWE-434 Aug 22, 2022
CVE-2022-36599 9.8 CRITICAL 1 PoC EPSS 0.01
Mingsoft MCMS 5.2.8 - SQL Injection
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.
CWE-89 Aug 16, 2022
CVE-2022-30506 9.8 CRITICAL 1 PoC EPSS 0.03
Mingsoft Mcms - Unrestricted File Upload
An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file.
CWE-434 Jun 02, 2022
CVE-2022-28930 9.8 CRITICAL 1 PoC EPSS 0.00
ERP-Pro <3.7.5 - SQL Injection
ERP-Pro v3.7.5 was discovered to contain a SQL injection vulnerability via the component /base/SysEveMenuAuthPointMapper.xml..
CWE-89 May 15, 2022
CVE-2022-30048 9.8 CRITICAL 1 PoC EPSS 0.00
Mingsoft Mcms - SQL Injection
Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.
CWE-89 May 11, 2022
CVE-2022-30047 9.8 CRITICAL 1 PoC EPSS 0.00
Mingsoft Mcms - SQL Injection
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.
CWE-89 May 11, 2022
CVE-2022-28114 9.1 CRITICAL 1 PoC EPSS 0.00
DSCMS v3.0 - Path Traversal
DSCMS v3.0 was discovered to contain an arbitrary file deletion vulnerability via /controller/Adv.php.
Apr 28, 2022
CVE-2022-26585 9.8 CRITICAL 1 PoC NUCLEI EPSS 0.48
Mingsoft MCMS <5.2.7 - SQL Injection
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.
CWE-89 Apr 05, 2022
CVE-2022-26249 9.8 CRITICAL 1 PoC EPSS 0.01
Survey King v0.3.0 - Code Injection
Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack.
CWE-1236 Mar 24, 2022
CVE-2022-25125 9.8 CRITICAL 1 PoC NUCLEI EPSS 0.79
Mingsoft Mcms - SQL Injection
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
CWE-89 Mar 03, 2022
CVE-2022-23329 9.8 CRITICAL 1 PoC EPSS 0.01
Ujcms Jspxcms - Unrestricted File Upload
A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.
CWE-434 Feb 04, 2022