Vulnerabilities Exploited in the Wild with Public PoC

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,432 CVEs tracked 53,633 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,306 vendors 43,872 researchers
2,391 results Clear all
CVE-2022-22242 6.1 MEDIUM EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.62
Juniper Networks Junos OS <19.1R3-S9-20.2 - XSS
A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker to run malicious scripts reflected off of J-Web to the victim's browser in the context of their session within J-Web. This issue affects Juniper Networks Junos OS all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S8; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R2; 22.1 versions prior to 22.1R2.
CWE-79 Oct 18, 2022
CVE-2022-0482 9.1 CRITICAL EXPLOITED 3 PoCs Analysis NUCLEI EPSS 0.91
GitHub alextselegidis/easyappointments <1.4.3 - Info Disclosure
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
CWE-359 Mar 09, 2022
CVE-2022-2414 7.5 HIGH EXPLOITED 5 PoCs Analysis NUCLEI EPSS 0.91
Dogtagpki - XXE
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.
CWE-611 Jul 29, 2022
CVE-2022-0591 9.1 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.88
FormCraft WP <3.8.28 - SSRF
The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users
CWE-918 Mar 21, 2022
CVE-2022-39986 9.8 CRITICAL EXPLOITED 3 PoCs Analysis NUCLEI EPSS 0.93
Raspap < 2.8.7 - Command Injection
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.
CWE-77 Aug 01, 2023
CVE-2022-40022 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.91
Symmetricom SyncServer Unauthenticated Remote Command Execution
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
CWE-77 Feb 13, 2023
CVE-2022-4063 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.88
InPost Gallery <2.1.4.1 - Code Injection
The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.
CWE-22 Dec 19, 2022
CVE-2022-41840 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.79
Welcart eCommerce <2.7.7 - Path Traversal
Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress.
CWE-22 Nov 18, 2022
CVE-2022-36642 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.71
Telosalliance Omnia Mpx Node Firmware < 1.5.0 - Missing Authorization
A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be unlatched by exploiting the LFD vulnerability.
CWE-862 Sep 02, 2022
CVE-2022-31793 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.94
Inglorion Muhttpd < 1.1.7 - Path Traversal
do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.
CWE-22 Aug 04, 2022
CVE-2022-34753 8.8 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.94
Schneider-electric Spacelogic C-bus H... - OS Command Injection
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised. Affected Products: SpaceLogic C-Bus Home Controller (5200WHC2), formerly known as C-Bus Wiser Homer Controller MK2 (V1.31.460 and prior)
CWE-78 Jul 13, 2022
CVE-2022-31126 10.0 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.90
Roxy-wi <6.1.1.0 - RCE
Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.
CWE-74 Jul 06, 2022
CVE-2022-29014 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.66
Razer Sila Gaming Router <2.0.441_api-2.0.418 - Info Disclosure
A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files.
Jun 09, 2022
CVE-2022-29383 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.75
NETGEAR ProSafe SSL VPN - SQL Injection
NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.
CWE-89 May 13, 2022
CVE-2022-29007 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.93
Dairy Farm Shop Management System v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.
CWE-89 May 11, 2022
CVE-2022-28079 8.8 HIGH EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.71
College Management System - SQL Injection
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.
CWE-89 May 05, 2022
CVE-2022-28219 9.8 CRITICAL EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.94
ManageEngine ADAudit Plus CVE-2022-28219
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
CWE-611 Apr 05, 2022
CVE-2022-34305 6.1 MEDIUM EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.17
Apache Tomcat < 8.5.81 - XSS
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
CWE-79 Jun 23, 2022
CVE-2022-29303 9.8 CRITICAL KEV 3 PoCs Analysis NUCLEI EPSS 0.94
SolarView Compact 6.00 - Command Injection
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
CWE-78 May 12, 2022
CVE-2022-31199 9.8 CRITICAL KEV RANSOMWARE 1 PoC Analysis EPSS 0.06
Netwrix Auditor - RCE
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.
CWE-502 Nov 08, 2022