Vulnerabilities Exploited in the Wild with Public PoC
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
2,390 results
Clear all
CVE-2015-2067
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.76
Magmi - Path Traversal
Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
CWE-22
Feb 24, 2015
CVE-2015-9406
7.5
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.87
Mtheme-unus < 2.3 - Path Traversal
Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a .. (dot dot) in the files parameter to css/css.php.
CWE-22
Sep 20, 2019
CVE-2015-5468
7.5
HIGH
EXPLOITED
1 PoC
Analysis
EPSS 0.51
WP e-Commerce Shop Styling <2.6 - Path Traversal
Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to includes/download.php.
CWE-22
May 23, 2017
CVE-2015-8562
EXPLOITED
13 PoCs
Analysis
NUCLEI
EPSS 0.93
Joomla! <3.4.6 - Code Injection
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.
CWE-20
Dec 16, 2015
CVE-2015-5374
EXPLOITED
3 PoCs
Analysis
EPSS 0.84
Siemens SIPROTEC 4 and SIPROTEC Compact EN100 Ethernet Module - Denial of Service
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02. Specially crafted packets sent to port 50000/UDP could cause a denial-of-service of the affected device. A manual reboot may be required to recover the service of the device.
CWE-19
Jul 18, 2015
CVE-2015-1805
EXPLOITED
6 PoCs
Analysis
EPSS 0.15
Google Android < 3.15.10 - Denial of Service
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun."
CWE-17
Aug 08, 2015
CVE-2015-7501
9.8
CRITICAL
EXPLOITED
3 PoCs
Analysis
EPSS 0.71
Red Hat - RCE
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
CWE-502
Nov 09, 2017
CVE-2015-1397
EXPLOITED
5 PoCs
Analysis
EPSS 0.72
Magento CE/EE 1.9.1.0-1.14.1.0 - SQL Injection
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary SQL commands via the popularity[field_expr] parameter when the popularity[from] or popularity[to] parameter is set.
CWE-89
Apr 29, 2015
CVE-2015-3090
EXPLOITED
3 PoCs
Analysis
EPSS 0.90
Adobe Flash Player ShaderJob Buffer Overflow
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3078, CVE-2015-3089, and CVE-2015-3093.
CWE-119
May 13, 2015
CVE-2015-0359
EXPLOITED
2 PoCs
Analysis
EPSS 0.89
Adobe Flash Player domainMemory ByteArray Use After Free
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0346.
Apr 14, 2015
CVE-2015-0003
EXPLOITED
2 PoCs
Analysis
EPSS 0.14
Microsoft Windows 7 - NULL Pointer Dereference
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
CWE-476
Feb 11, 2015
CVE-2015-7858
EXPLOITED
3 PoCs
Analysis
EPSS 0.69
Joomla! <3.4.4 - SQL Injection
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7297.
CWE-89
Oct 29, 2015
CVE-2015-5065
EXPLOITED
1 PoC
Analysis
EPSS 0.35
Intelligent-it Paypal Currency Conver... - Path Traversal
Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin before 1.4 for WordPress allows remote attackers to read arbitrary files via a full pathname in the requrl parameter.
CWE-22
Jun 24, 2015
CVE-2015-9415
7.5
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.18
Angrycreative BJ Lazy Load < 1.0 - Improper Input Validation
The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion.
CWE-20
Sep 26, 2019
CVE-2015-5477
EXPLOITED
11 PoCs
Analysis
EPSS 0.93
ISC BIND 9.x <9.9.7-P2, 9.10.x <9.10.2-P3 - DoS
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.
CWE-19
Jul 29, 2015
CVE-2015-3105
EXPLOITED
RANSOMWARE
2 PoCs
Analysis
EPSS 0.90
Adobe Flash Player Drawing Fill Shader Memory Corruption
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
CWE-119
Jun 10, 2015
CVE-2015-9480
7.5
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.62
Robot-cpa Robotcpa - Path Traversal
The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.
CWE-22
Oct 10, 2019
CVE-2015-0336
EXPLOITED
2 PoCs
Analysis
EPSS 0.89
Adobe Flash Player NetConnection Type Confusion
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0334.
Mar 13, 2015
CVE-2015-0072
EXPLOITED
2 PoCs
Analysis
EPSS 0.89
Microsoft Internet Explorer - XSS
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy and inject arbitrary web script or HTML via vectors involving an IFRAME element that triggers a redirect, a second IFRAME element that does not trigger a redirect, and an eval of a WindowProxy object, aka "Universal XSS (UXSS)."
CWE-79
Feb 07, 2015
CVE-2015-9499
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.68
Themepunch Showbiz Pro < 1.7.1 - Unrestricted File Upload
The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.
CWE-434
Oct 22, 2019