Critical Vulnerabilities with Public Exploits
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,105 results
Clear all
CVE-2022-22720
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.27
Apache HTTP Server < 2.4.52 - HTTP Request Smuggling
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
CWE-444
Mar 14, 2022
CVE-2022-0592
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.70
MapSVG WP <6.2.20 - SQL Injection
The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.
CWE-89
May 09, 2022
CVE-2022-0591
9.1
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.88
FormCraft WP <3.8.28 - SSRF
The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users
CWE-918
Mar 21, 2022
CVE-2022-4060
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.89
User Post Gallery WP <2.19 - Code Injection
The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.
Jan 16, 2023
CVE-2022-4063
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.88
InPost Gallery <2.1.4.1 - Code Injection
The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.
CWE-22
Dec 19, 2022
CVE-2022-25148
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.58
Veronalabs WP Statistics < 13.1.5 - SQL Injection
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.
CWE-89
Feb 24, 2022
CVE-2022-34721
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
EPSS 0.27
Microsoft Windows 10 - Remote Code Execution
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Sep 13, 2022
CVE-2022-2185
9.9
CRITICAL
3 PoCs
Analysis
NUCLEI
EPSS 0.90
GitLab <14.10.5-15.1.1 - Authenticated RCE
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.
CWE-78
Jul 01, 2022
CVE-2022-1162
9.1
CRITICAL
4 PoCs
Analysis
NUCLEI
EPSS 0.88
Gitlab < 14.7.7 - Hard-coded Credentials
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts
CWE-798
Apr 04, 2022
CVE-2022-21849
9.8
CRITICAL
1 PoC
EPSS 0.25
Microsoft Windows 10 - Remote Code Execution
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Jan 11, 2022
CVE-2022-45808
9.9
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.84
Thimpress Learnpress < 4.1.7.3.2 - SQL Injection
SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
CWE-89
Jan 26, 2023
CVE-2022-47615
9.3
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.83
Thimpress Learnpress < 4.2.0 - Unrestricted File Upload
Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
CWE-434
Jan 26, 2023
CVE-2022-41220
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.13
md2roff 1.9 - Buffer Overflow
md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: the vendor's position is that the product is not intended for untrusted input
CWE-787
Sep 21, 2022
CVE-2022-23305
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.09
Apache Log4j < 1.2.17 - SQL Injection
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
CWE-89
Jan 18, 2022
CVE-2022-22822
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Libexpat < 2.4.3 - Integer Overflow
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CWE-190
Jan 10, 2022
CVE-2022-44118
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.10
dedecmdv6 <6.1.9 - RCE
dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.
Nov 23, 2022
CVE-2022-4297
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Netflixtech WP Autocomplete Search < 1.0.4 - SQL Injection
The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX available to unauthenticated users, leading to an unauthenticated SQL injection
Jan 02, 2023
CVE-2022-44276
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.27
Responsive Filemanager < 9.12.0 - Auth Bypass
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.
CWE-434
Jun 28, 2023
CVE-2022-35698
10.0
CRITICAL
1 PoC
Analysis
EPSS 0.03
Adobe Commerce <2.4.4-p1, <2.4.5 - XSS
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
CWE-79
Oct 14, 2022
CVE-2022-45025
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.43
Markdown Preview Enhanced - OS Command Injection
Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF file import function.
CWE-78
Dec 07, 2022