High EPSS Vulnerabilities with Public Exploits
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
3,483 results
Clear all
CVE-2021-26828
8.8
HIGH
KEV
4 PoCs
Analysis
EPSS 0.80
Scadabr < 0.9.1 - Unrestricted File Upload
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
CWE-434
Jun 11, 2021
CVE-2018-8631
7.5
HIGH
1 PoC
Analysis
EPSS 0.80
Internet Explorer < - Memory Corruption
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
CWE-787
Dec 12, 2018
CVE-2008-0105
1 PoC
Analysis
EPSS 0.80
Microsoft Office - Improper Input Validation
Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."
CWE-20
Feb 12, 2008
CVE-2017-6360
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
EPSS 0.80
Qnap Qts < 4.2.4 - OS Command Injection
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
CWE-78
Mar 23, 2017
CVE-2018-19458
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.80
PHP Proxy 3.0.3 - Info Disclosure
In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability than CVE-2018-19246.
CWE-287
Nov 22, 2018
CVE-2016-2107
5.9
MEDIUM
3 PoCs
Analysis
EPSS 0.80
Redhat Enterprise Linux Desktop < 1.0.1s - Information Disclosure
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.
CWE-310
May 05, 2016
CVE-2010-1552
2 PoCs
Analysis
EPSS 0.80
HP OpenView Network Node Manager <7.53 - Buffer Overflow
Stack-based buffer overflow in the doLoad function in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via the act and app parameters.
CWE-119
May 13, 2010
CVE-2023-28324
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.80
Ivanti Endpoint Manager < 2022 - Improper Input Validation
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.
CWE-20
Jul 01, 2023
CVE-2005-2733
3 PoCs
Analysis
EPSS 0.80
Simple PHP Blog - RCE
upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code.
Aug 30, 2005
CVE-2018-8279
7.5
HIGH
1 PoC
Analysis
EPSS 0.80
Microsoft Edge - Memory Corruption
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8125, CVE-2018-8262, CVE-2018-8274, CVE-2018-8275, CVE-2018-8301.
CWE-843
Jul 11, 2018
CVE-2018-8229
7.5
HIGH
1 PoC
Analysis
EPSS 0.80
Microsoft Edge - Memory Corruption
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8227.
CWE-843
Jun 14, 2018
CVE-2020-5377
9.1
CRITICAL
3 PoCs
Analysis
EPSS 0.80
Dell Emc Openmanage Server Administrator < 9.4 - Path Traversal
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated remote attacker could potentially exploit these vulnerabilities by sending a crafted Web API request containing directory traversal character sequences to gain file system access on the compromised management station.
CWE-22
Jul 28, 2020
CVE-2005-0043
3 PoCs
Analysis
EPSS 0.80
Apple Itunes - Buffer Overflow
Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.
May 02, 2005
CVE-2006-7196
1 PoC
Analysis
EPSS 0.80
Apache Tomcat < 4.1.31 - XSS
Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.
CWE-79
May 10, 2007
CVE-2022-32429
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.80
Megatech Msnswitch Firmware - Authentication Bypass
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.
CWE-287
Aug 10, 2022
CVE-2013-3591
8.8
HIGH
2 PoCs
Analysis
EPSS 0.80
Vtiger Crm - Unrestricted File Upload
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
CWE-434
Feb 07, 2020
CVE-2012-6096
3 PoCs
Analysis
EPSS 0.80
Nagios < 3.4.3 - Memory Corruption
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow remote attackers to execute arbitrary code via a long (1) host_name variable (host parameter) or (2) svc_description variable.
CWE-119
Jan 22, 2013
CVE-2016-0170
8.8
HIGH
1 PoC
Analysis
EPSS 0.80
Microsoft Windows 10 - Improper Access Control
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document, aka "Windows Graphics Component RCE Vulnerability."
CWE-284
May 11, 2016
CVE-2008-3558
3 PoCs
Analysis
EPSS 0.80
Cisco WebEx Meeting Manager <20.2008.2606.4919 - Buffer Overflow
Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before 20.2008.2606.4919 allows remote attackers to execute arbitrary code via a long argument to the NewObject method.
CWE-119
Aug 08, 2008
CVE-2006-2407
5 PoCs
Analysis
EPSS 0.80
Freeftpd - Memory Corruption
Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, allows remote attackers to execute arbitrary code via a long key exchange algorithm string.
CWE-119
May 16, 2006