Vulnerabilities Exploited in the Wild with Public PoC

Updated 50m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,468 CVEs tracked 53,663 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,324 vendors 43,878 researchers
2,391 results Clear all
CVE-2021-45511 6.8 MEDIUM EXPLOITED 1 PoC Analysis EPSS 0.48
Netgear Ac2100 Firmware < 1.2.0.88 - Authentication Bypass
Certain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08-27, AC2400 before 2021-08-27, AC2600 before 2021-08-27, D7000 before 2021-08-27, R6220 before 2021-08-27, R6230 before 2021-08-27, R6260 before 2021-08-27, R6330 before 2021-08-27, R6350 before 2021-08-27, R6700v2 before 2021-08-27, R6800 before 2021-08-27, R6850 before 2021-08-27, R6900v2 before 2021-08-27, R7200 before 2021-08-27, R7350 before 2021-08-27, R7400 before 2021-08-27, and R7450 before 2021-08-27.
Dec 26, 2021
CVE-2021-1472 5.3 MEDIUM EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.91
Cisco Rv160 Firmware < 1.0.01.03 - Authentication Bypass
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
CWE-119 Apr 08, 2021
CVE-2021-30461 9.8 CRITICAL EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.93
VoIPmonitor <24.61 - RCE
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configuration.php.
CWE-94 May 29, 2021
CVE-2021-33045 9.8 CRITICAL KEV 3 PoCs Analysis NUCLEI EPSS 0.94
Dahua - Auth Bypass
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
CWE-287 Sep 15, 2021
CVE-2021-33044 9.8 CRITICAL KEV 8 PoCs Analysis NUCLEI EPSS 0.94
Dahua - Auth Bypass
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
CWE-287 Sep 15, 2021
CVE-2021-45837 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.81
TerraMaster TOS 4.2.15 or lower - RCE chain from unauthenticated to root via session crafting.
It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted input to /tos/index.php?app/del.
Apr 25, 2022
CVE-2021-44142 8.8 HIGH EXPLOITED 5 PoCs Analysis EPSS 0.37
Redhat Enterprise Linux For Scientific Computing - Out-of-Bounds Write
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.
CWE-125 Feb 21, 2022
CVE-2021-3018 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.79
ipeak Infosystems ibexwebCMS <3.5 - SQL Injection
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print.php page.
CWE-89 Jan 05, 2021
CVE-2021-25646 8.8 HIGH EXPLOITED 13 PoCs Analysis NUCLEI EPSS 0.94
Apache Druid <0.20.0 - XSS
Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.
Jan 29, 2021
CVE-2021-43936 10.0 CRITICAL EXPLOITED 2 PoCs Analysis EPSS 0.28
WebHMI - Code Injection
The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.
CWE-434 Dec 06, 2021
CVE-2021-42063 6.1 MEDIUM EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.41
SAP Knowledge Warehouse - XSS
A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component within a Web browser enables unauthorized attackers to conduct XSS attacks, which might lead to disclose sensitive data.
CWE-79 Dec 14, 2021
CVE-2021-20039 8.8 HIGH EXPLOITED 1 PoC Analysis EPSS 0.82
Sonicwall Sma 410 Firmware - OS Command Injection
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
CWE-78 Dec 08, 2021
CVE-2021-44529 9.8 CRITICAL KEV RANSOMWARE 4 PoCs Analysis NUCLEI EPSS 0.94
Ivanti Endpoint Manager Cloud Services Appliance - Code Injection
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
CWE-94 Dec 08, 2021
CVE-2021-42071 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.91
Visual-tools Dvr Vx16 Firmware - OS Command Injection
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.
CWE-78 Oct 07, 2021
CVE-2021-32849 8.8 HIGH EXPLOITED 3 PoCs Analysis EPSS 0.78
Gerapy <0.9.9 - Command Injection
Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is fixed in version 0.9.9. There are no known workarounds.
CWE-78 Jan 26, 2022
CVE-2021-32819 8.0 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.90
Squirrelly <9.0.0 - RCE
Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This issue is fixed in version 9.0.0. For complete details refer to the referenced GHSL-2021-023.
CWE-200 May 14, 2021
CVE-2021-40822 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.93
GeoServer <2.19.2 - SSRF
GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.
CWE-918 May 02, 2022
CVE-2021-46381 7.5 HIGH EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.90
D-Link DAP-1620 - Path Traversal
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].
CWE-22 Mar 04, 2022
CVE-2021-46379 6.1 MEDIUM EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.47
DLink DIR850 ET850-1.08TRb03 - Open Redirect
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.
CWE-601 Mar 04, 2022
CVE-2021-45092 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.79
Thinfinity VirtualUI <3.0 - Code Injection
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.
Dec 16, 2021