Critical Vulnerabilities with Public Exploits

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,649 CVEs tracked 53,649 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,377 vendors 43,908 researchers
4,109 results Clear all
CVE-2022-31181 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.78
PrestaShop <1.7.8.7 - SQL Injection
PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call PHP's Eval function on attacker input. The problem is fixed in version 1.7.8.7. Users are advised to upgrade. Users unable to upgrade may delete the MySQL Smarty cache feature.
CWE-74 Aug 01, 2022
CVE-2022-2466 9.8 CRITICAL 1 PoC Analysis EPSS 0.13
Quarkus < 2.10.4 - HTTP Request Smuggling
It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.
CWE-444 Aug 31, 2022
CVE-2022-35131 9.0 CRITICAL 1 PoC Analysis EPSS 0.15
Joplin < 2.9.1 - XSS
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
CWE-79 Jul 25, 2022
CVE-2022-24562 9.8 CRITICAL 1 PoC Analysis EPSS 0.49
IOBit IOTransfer 4.3.1.1561 - RCE
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.
CWE-306 Jun 16, 2022
CVE-2022-25262 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Jetbrains Hub < 2022.1.14434 - Data Authenticity Bypass
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
CWE-345 Feb 25, 2022
CVE-2022-30887 9.8 CRITICAL 1 PoC Analysis EPSS 0.05
Pharmacy Management System v1.0 - RCE
Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
CWE-434 May 20, 2022
CVE-2022-20130 9.8 CRITICAL 1 PoC Analysis EPSS 0.16
Android -10,11,12,12L - Buffer Overflow
In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-224314979
CWE-754 Jun 15, 2022
CVE-2022-31885 9.8 CRITICAL 1 PoC Analysis EPSS 0.36
Marvalglobal Marval Msm - OS Command Injection
Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.
CWE-78 Jun 28, 2022
CVE-2022-31296 9.8 CRITICAL 1 PoC Analysis EPSS 0.06
Online Discussion Forum Site 1 - SQL Injection
Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.
CWE-89 Jun 17, 2022
CVE-2022-29303 9.8 CRITICAL KEV SSVC ACTIVE 3 PoCs Analysis NUCLEI EPSS 0.94
SolarView Compact 6.00 - Command Injection
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
CWE-78 May 12, 2022
CVE-2022-30511 9.8 CRITICAL 1 PoC Analysis EPSS 0.24
School Dormitory Management System - SQL Injection
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4.
CWE-89 Jun 02, 2022
CVE-2022-30510 9.8 CRITICAL 1 PoC Analysis EPSS 0.24
School Dormitory Management System - SQL Injection
School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59.
CWE-89 Jun 02, 2022
CVE-2022-30512 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.72
School Dormitory Management System - SQL Injection
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31.
CWE-89 Jun 02, 2022
CVE-2022-29337 9.8 CRITICAL 1 PoC Analysis EPSS 0.30
C-DATA FD702XW-X-R430 v2.1.13_X001 - Command Injection
C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request.
CWE-78 May 24, 2022
CVE-2022-25235 9.8 CRITICAL 1 PoC Analysis EPSS 0.13
Expat <2.4.5 - Info Disclosure
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
CWE-116 Feb 16, 2022
CVE-2022-31856 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Newsletter Module - SQL Injection
Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.
CWE-89 Jul 05, 2022
CVE-2022-29009 9.8 CRITICAL 2 PoCs Analysis NUCLEI EPSS 0.75
Cyber Cafe Management System Project v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.
CWE-89 May 11, 2022
CVE-2022-29007 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.93
Dairy Farm Shop Management System v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.
CWE-89 May 11, 2022
CVE-2022-29006 9.8 CRITICAL 2 PoCs Analysis NUCLEI EPSS 0.87
Directory Management System v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
CWE-89 May 11, 2022
CVE-2022-29383 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.75
NETGEAR ProSafe SSL VPN - SQL Injection
NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.
CWE-89 May 13, 2022