High EPSS Vulnerabilities with Public Exploits
Updated 56m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
3,481 results
Clear all
CVE-2014-9735
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.83
ThemePunch Slider Revolution <3.0.96 & Showbiz Pro <1.7.1 - RCE
The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin action; (2) delete arbitrary sliders via a delete_slider action; and (3) create, (4) update, (5) import, or (6) export arbitrary sliders via unspecified vectors.
CWE-264
Jun 30, 2015
CVE-2007-4440
4 PoCs
Analysis
EPSS 0.83
MercuryS SMTP <4.51 - Buffer Overflow
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961.
CWE-119
Aug 21, 2007
CVE-2006-0564
10 PoCs
Analysis
EPSS 0.83
Microsoft Html Help - Buffer Overflow
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file field.
Feb 06, 2006
CVE-2017-8636
7.5
HIGH
4 PoCs
Analysis
EPSS 0.83
Microsoft Internet Explorer - Memory Corruption
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
CWE-119
Aug 08, 2017
CVE-2016-1525
8.6
HIGH
3 PoCs
Analysis
EPSS 0.83
NETGEAR Management System NMS300 <1.5.0.11 - Path Traversal
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allows remote authenticated users to read arbitrary files via a .. (dot dot) in the realName parameter.
CWE-22
Feb 13, 2016
CVE-2014-8516
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.83
Cloudfastpath Netcharts Server - Unrestricted File Upload
Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.
CWE-434
Jan 03, 2020
CVE-2023-32707
8.8
HIGH
3 PoCs
Analysis
EPSS 0.83
Splunk Enterprise <9.0.5 - Privilege Escalation
In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests.
CWE-285
Jun 01, 2023
CVE-2010-3973
3 PoCs
Analysis
EPSS 0.83
Microsoft Wmi Administrative Tools < 1.1 - Code Injection
The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted argument to the AddContextRef method, possibly an untrusted pointer dereference, aka "Microsoft WMITools ActiveX Control Vulnerability."
CWE-94
Dec 23, 2010
CVE-2019-0841
7.8
HIGH
KEV
RANSOMWARE
9 PoCs
Analysis
EPSS 0.83
Windows AppX Deployment Service - Privilege Escalation
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.
CWE-59
Apr 09, 2019
CVE-2017-18044
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.83
Commvault < 11.0 - OS Command Injection
A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside the Commvault service does not properly validate the input of an incoming string before passing it to CreateProcess. As a result, a specially crafted message can inject commands that will be executed on the target operating system. Exploitation of this vulnerability does not require authentication and can lead to SYSTEM level privilege on any system running the cvd daemon. This is a different vulnerability than CVE-2017-3195.
CWE-78
Jan 19, 2018
CVE-2022-1903
8.1
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.83
ARMember <3.4.8 - Auth Bypass
The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username
CWE-862
Jun 27, 2022
CVE-2010-4335
3 PoCs
Analysis
EPSS 0.83
Cakefoundation Cakephp < 1.3.6 - Improper Input Validation
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.
CWE-20
Jan 14, 2011
CVE-2020-28347
9.8
CRITICAL
1 PoC
2 Writeups
Analysis
EPSS 0.83
Tp-link Ac1750 Firmware < 201029 - OS Command Injection
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this issue exists because of an incomplete fix for CVE-2020-10882 in which shell quotes are mishandled.
CWE-78
Nov 08, 2020
CVE-2019-17240
9.8
CRITICAL
12 PoCs
Analysis
EPSS 0.83
Bludit - Brute Force
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.
CWE-307
Oct 06, 2019
CVE-2018-11784
4.3
MEDIUM
3 PoCs
Analysis
NUCLEI
EPSS 0.83
Apache Tomcat < 7.0.90 - Open Redirect
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.
CWE-601
Oct 04, 2018
CVE-2014-5519
2 PoCs
Analysis
EPSS 0.83
Phpwiki - Code Injection
The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[content] parameter to index.php/HeIp. NOTE: some of these details are obtained from third party information.
CWE-94
Sep 11, 2014
CVE-2019-7214
9.8
CRITICAL
6 PoCs
Analysis
EPSS 0.83
SmarterTools SmarterMail less than build 6985 - .NET Deserialization Remote Code Execution
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
CWE-502
Apr 24, 2019
CVE-2013-3893
8.8
HIGH
KEV
4 PoCs
Analysis
EPSS 0.83
Microsoft Internet Explorer - Use After Free
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.
CWE-416
Sep 18, 2013
CVE-2014-3120
8.1
HIGH
KEV
6 PoCs
Analysis
NUCLEI
EPSS 0.83
Elasticsearch < 1.2 - Improper Access Control
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.
CWE-284
Jul 28, 2014
CVE-2021-37343
8.8
HIGH
1 PoC
Analysis
EPSS 0.83
Nagios XI Autodiscovery Webshell Upload
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.
CWE-22
Aug 13, 2021