Critical Vulnerabilities with Public Exploits
Updated 54m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,104 results
Clear all
CVE-2022-42889
9.8
CRITICAL
EXPLOITED
62 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache Commons Text < 1.10.0 - Code Injection
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.
CWE-94
Oct 13, 2022
CVE-2022-22965
9.8
CRITICAL
KEV
RANSOMWARE
119 PoCs
Analysis
NUCLEI
EPSS 0.94
Vmware Spring Framework < 5.2.20 - Code Injection
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
CWE-94
Apr 01, 2022
CVE-2022-0543
10.0
CRITICAL
KEV
9 PoCs
Analysis
NUCLEI
EPSS 0.94
Redis Lua Sandbox Escape
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
CWE-862
Feb 18, 2022
CVE-2022-31706
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.90
Vmware Vrealize Log Insight < 4.8 - Path Traversal
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
CWE-22
Jan 26, 2023
CVE-2022-31704
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.90
Vmware Vrealize Log Insight < 4.8 - Improper Access Control
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.
CWE-284
Jan 26, 2023
CVE-2022-48114
9.8
CRITICAL
1 PoC
EPSS 0.00
Ruoyi < 4.7.5 - SQL Injection
RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.
CWE-89
Feb 02, 2023
CVE-2022-44089
9.8
CRITICAL
1 PoC
EPSS 0.03
ESPCMS P8.21120101 - RCE
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
CWE-94
Nov 10, 2022
CVE-2022-44088
9.8
CRITICAL
1 PoC
EPSS 0.04
ESPCMS <P8.21120101 - RCE
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.
CWE-94
Nov 10, 2022
CVE-2022-44087
9.8
CRITICAL
1 PoC
EPSS 0.03
ESPCMS <P8.21120101 - RCE
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.
CWE-94
Nov 10, 2022
CVE-2022-35150
9.8
CRITICAL
1 PoC
1 Writeup
Analysis
EPSS 0.00
Baijiacms - Unrestricted File Upload
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.
CWE-434
Aug 22, 2022
CVE-2022-36599
9.8
CRITICAL
1 PoC
EPSS 0.01
Mingsoft MCMS 5.2.8 - SQL Injection
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.
CWE-89
Aug 16, 2022
CVE-2022-30506
9.8
CRITICAL
1 PoC
EPSS 0.03
Mingsoft Mcms - Unrestricted File Upload
An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file.
CWE-434
Jun 02, 2022
CVE-2022-28930
9.8
CRITICAL
1 PoC
EPSS 0.00
ERP-Pro <3.7.5 - SQL Injection
ERP-Pro v3.7.5 was discovered to contain a SQL injection vulnerability via the component /base/SysEveMenuAuthPointMapper.xml..
CWE-89
May 15, 2022
CVE-2022-30048
9.8
CRITICAL
1 PoC
EPSS 0.00
Mingsoft Mcms - SQL Injection
Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.
CWE-89
May 11, 2022
CVE-2022-30047
9.8
CRITICAL
1 PoC
EPSS 0.00
Mingsoft Mcms - SQL Injection
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.
CWE-89
May 11, 2022
CVE-2022-28114
9.1
CRITICAL
1 PoC
EPSS 0.00
DSCMS v3.0 - Path Traversal
DSCMS v3.0 was discovered to contain an arbitrary file deletion vulnerability via /controller/Adv.php.
Apr 28, 2022
CVE-2022-26585
9.8
CRITICAL
1 PoC
NUCLEI
EPSS 0.48
Mingsoft MCMS <5.2.7 - SQL Injection
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.
CWE-89
Apr 05, 2022
CVE-2022-26249
9.8
CRITICAL
1 PoC
EPSS 0.01
Survey King v0.3.0 - Code Injection
Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack.
CWE-1236
Mar 24, 2022
CVE-2022-25125
9.8
CRITICAL
1 PoC
NUCLEI
EPSS 0.79
Mingsoft Mcms - SQL Injection
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
CWE-89
Mar 03, 2022
CVE-2022-23329
9.8
CRITICAL
1 PoC
EPSS 0.01
Ujcms Jspxcms - Unrestricted File Upload
A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.
CWE-434
Feb 04, 2022