Critical Vulnerabilities with Public Exploits
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,109 results
Clear all
CVE-2022-31181
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.78
PrestaShop <1.7.8.7 - SQL Injection
PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call PHP's Eval function on attacker input. The problem is fixed in version 1.7.8.7. Users are advised to upgrade. Users unable to upgrade may delete the MySQL Smarty cache feature.
CWE-74
Aug 01, 2022
CVE-2022-2466
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.13
Quarkus < 2.10.4 - HTTP Request Smuggling
It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.
CWE-444
Aug 31, 2022
CVE-2022-35131
9.0
CRITICAL
1 PoC
Analysis
EPSS 0.15
Joplin < 2.9.1 - XSS
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
CWE-79
Jul 25, 2022
CVE-2022-24562
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.49
IOBit IOTransfer 4.3.1.1561 - RCE
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.
CWE-306
Jun 16, 2022
CVE-2022-25262
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Jetbrains Hub < 2022.1.14434 - Data Authenticity Bypass
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
CWE-345
Feb 25, 2022
CVE-2022-30887
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.05
Pharmacy Management System v1.0 - RCE
Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
CWE-434
May 20, 2022
CVE-2022-20130
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.16
Android -10,11,12,12L - Buffer Overflow
In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-224314979
CWE-754
Jun 15, 2022
CVE-2022-31885
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.36
Marvalglobal Marval Msm - OS Command Injection
Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.
CWE-78
Jun 28, 2022
CVE-2022-31296
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.06
Online Discussion Forum Site 1 - SQL Injection
Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.
CWE-89
Jun 17, 2022
CVE-2022-29303
9.8
CRITICAL
KEV
SSVC ACTIVE
3 PoCs
Analysis
NUCLEI
EPSS 0.94
SolarView Compact 6.00 - Command Injection
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
CWE-78
May 12, 2022
CVE-2022-30511
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.24
School Dormitory Management System - SQL Injection
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4.
CWE-89
Jun 02, 2022
CVE-2022-30510
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.24
School Dormitory Management System - SQL Injection
School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59.
CWE-89
Jun 02, 2022
CVE-2022-30512
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.72
School Dormitory Management System - SQL Injection
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31.
CWE-89
Jun 02, 2022
CVE-2022-29337
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.30
C-DATA FD702XW-X-R430 v2.1.13_X001 - Command Injection
C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request.
CWE-78
May 24, 2022
CVE-2022-25235
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.13
Expat <2.4.5 - Info Disclosure
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
CWE-116
Feb 16, 2022
CVE-2022-31856
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Newsletter Module - SQL Injection
Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.
CWE-89
Jul 05, 2022
CVE-2022-29009
9.8
CRITICAL
2 PoCs
Analysis
NUCLEI
EPSS 0.75
Cyber Cafe Management System Project v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.
CWE-89
May 11, 2022
CVE-2022-29007
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.93
Dairy Farm Shop Management System v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.
CWE-89
May 11, 2022
CVE-2022-29006
9.8
CRITICAL
2 PoCs
Analysis
NUCLEI
EPSS 0.87
Directory Management System v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
CWE-89
May 11, 2022
CVE-2022-29383
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.75
NETGEAR ProSafe SSL VPN - SQL Injection
NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.
CWE-89
May 13, 2022