Critical Vulnerabilities with Public Exploits
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,109 results
Clear all
CVE-2022-50919
9.8
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.02
Tdarr 2.00.15 - RCE
Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers to inject and chain arbitrary commands. Attackers can exploit the lack of input filtering by chaining commands like `--help; curl .py | python` to execute remote code without authentication.
CWE-78
Jan 13, 2026
CVE-2022-50922
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Audio Conversion Wizard v2.01 - Buffer Overflow
Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory with a specially crafted registration code. Attackers can generate a payload that overwrites the application's memory stack, potentially enabling remote code execution through a carefully constructed input buffer.
CWE-120
Jan 13, 2026
CVE-2022-25064
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
EPSS 0.63
Tp-link Tl-wr840n Firmware - OS Command Injection
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.
CWE-78
Feb 25, 2022
CVE-2022-50925
9.8
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Prowise Reflect <1.0.9 - Code Injection
Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed WebSocket on port 8082. Attackers can craft malicious web pages to inject keystrokes, opening applications and typing arbitrary text by sending specific WebSocket messages.
CWE-346
Jan 13, 2026
CVE-2022-50926
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
WAGO 750-8212 PFC200 G2 2ETH RS - Privilege Escalation
WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's 'name' and 'roles' parameters to elevate from ordinary user to administrative privileges without authentication.
CWE-565
Jan 13, 2026
CVE-2022-25060
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
EPSS 0.75
Tp-link Tl-wr840n Firmware - OS Command Injection
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
CWE-78
Feb 25, 2022
CVE-2022-25061
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.86
Tp-link Tl-wr840n Firmware - OS Command Injection
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
CWE-78
Feb 25, 2022
CVE-2022-22845
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.13
Qxip Homer Webapp < 1.4.28 - Hard-coded Credentials
QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations.
CWE-798
Jan 10, 2022
CVE-2022-25359
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.28
Iclinks Scadaflex II Firmware - Missing Authentication
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
CWE-306
Feb 26, 2022
CVE-2022-26633
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Simple Student Quarterly Result/Grade System v1.0 - SQL Injection
Simple Student Quarterly Result/Grade System v1.0 was discovered to contain a SQL injection vulnerability via /sqgs/Actions.php.
CWE-89
May 20, 2022
CVE-2022-26632
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Multi-Vendor Online Groceries Management System v1.0 - SQL Injection
Multi-Vendor Online Groceries Management System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /products/view_product.php.
CWE-89
May 20, 2022
CVE-2022-21241
9.6
CRITICAL
1 PoC
Analysis
EPSS 0.30
Csv+ < 0.8.1 - XSS
Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated attacker to inject an arbitrary script or an arbitrary OS command via a specially crafted CSV file that contains HTML a tag.
CWE-79
Feb 08, 2022
CVE-2022-25096
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Home Owners Collection Management System - SQL Injection
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php.
CWE-89
Feb 26, 2022
CVE-2022-25095
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Home Owners Collection Management System v1.0 - Info Disclosure
Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request.
Feb 26, 2022
CVE-2022-23366
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Hms - SQL Injection
HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.
CWE-89
Jan 21, 2022
CVE-2022-40877
9.8
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Exam Reviewer Management System 1.0 - SQL Injection
Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.
CWE-89
Sep 27, 2022
CVE-2022-24223
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.45
AtomCMS v2.0 - SQL Injection
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
CWE-89
Feb 01, 2022
CVE-2022-24263
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Hospital Management System v4.0 - SQL Injection
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
CWE-89
Jan 31, 2022
CVE-2022-50935
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Flame II HSPA USB Modem - Privilege Escalation
Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.
CWE-428
Jan 13, 2026
CVE-2022-22832
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.20
Servisnet Tessa - IDOR
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request.
CWE-639
Feb 06, 2022