High EPSS Vulnerabilities with Public Exploits
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
3,485 results
Clear all
CVE-2012-10054
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.76
Umbraco CMS <4.7.1 - RCE
Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the fileName parameter, attackers can write malicious ASPX scripts directly into the web-accessible /umbraco/ directory and execute them remotely.
CWE-22
Aug 13, 2025
CVE-2024-27983
8.2
HIGH
1 PoC
Analysis
EPSS 0.76
Node.js HTTP/2 - DoS
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is abruptly closed by the client triggering the Http2Session destructor while header frames are still being processed (and stored in memory) causing a race condition.
CWE-362
Apr 09, 2024
CVE-2006-6707
3 PoCs
Analysis
EPSS 0.76
NeoTrace Express <3.25 - RCE
Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Express 3.25 and NeoTrace Pro (aka McAfee Visual Trace) 3.25 allows remote attackers to execute arbitrary code via a long argument string to the TraceTarget method. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Dec 23, 2006
CVE-2011-0978
1 PoC
Analysis
EPSS 0.76
Microsoft Excel - Memory Corruption
Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via vectors related to an axis properties record, and improper incrementing of an array index, aka "Excel Array Indexing Vulnerability."
CWE-119
Feb 10, 2011
CVE-2017-6527
7.5
HIGH
2 PoCs
Analysis
EPSS 0.76
Dnatools Dnalims - Path Traversal
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal attack allowing an unauthenticated attacker to access system files readable by the web server user (by using the viewAppletFsa.cgi seqID parameter).
CWE-22
Mar 09, 2017
CVE-2019-12169
8.8
HIGH
3 PoCs
Analysis
EPSS 0.76
ATutor 2.2.4 - RCE
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/languages/language_import.php (aka Import New Language) or mods/_standard/patcher/index_admin.php (aka Patcher) component.
CWE-22
Jun 03, 2019
CVE-2020-8260
7.2
HIGH
KEV
RANSOMWARE
1 PoC
Analysis
EPSS 0.76
Pulse Connect Secure <9.1R9 - Authenticated RCE
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.
CWE-434
Oct 28, 2020
CVE-2021-44967
8.8
HIGH
4 PoCs
Analysis
EPSS 0.76
Limesurvey - Unrestricted File Upload
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding.
CWE-434
Feb 24, 2022
CVE-2000-0248
EXPLOITED
3 PoCs
Analysis
EPSS 0.76
Red Hat Linux Piranha - Command Injection
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.
Apr 24, 2000
CVE-2023-34992
10.0
CRITICAL
2 PoCs
Analysis
EPSS 0.76
Fortinet Fortisiem < 6.6.3 - OS Command Injection
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.
CWE-78
Oct 10, 2023
CVE-2011-3658
2 PoCs
Analysis
EPSS 0.76
Mozilla Firefox <8.0, Thunderbird <8.0, SeaMonkey <2.5 - DoS
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via vectors involving removal of SVG elements.
CWE-399
Dec 21, 2011
CVE-2012-6066
5 PoCs
Analysis
EPSS 0.76
Freesshd < 1.2.6 - Authentication Bypass
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c.
CWE-287
Dec 04, 2012
CVE-2008-5444
2 PoCs
Analysis
EPSS 0.76
Oracle Secure Backup <10.2.0.2 - Info Disclosure
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2008-5448 and CVE-2008-5449.
Jan 14, 2009
CVE-2011-2882
2 PoCs
Analysis
EPSS 0.76
Citrix Access Gateway - Memory Corruption
Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 allows remote attackers to execute arbitrary code via crafted HTTP header data.
CWE-119
Jul 21, 2011
CVE-2012-6710
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.76
Extplorer < 2.1.2 - Authentication Bypass
ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php.
CWE-287
Oct 07, 2018
CVE-2006-1314
1 PoC
Analysis
EPSS 0.76
Microsoft Windows - Buffer Overflow
Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.
Jul 11, 2006
CVE-2025-21293
8.8
HIGH
2 PoCs
Analysis
EPSS 0.76
Microsoft Windows 10 1507 < 10.0.10240.20890 - Improper Access Control
Active Directory Domain Services Elevation of Privilege Vulnerability
CWE-284
Jan 14, 2025
CVE-2009-4484
2 PoCs
Analysis
EPSS 0.76
yaSSL <1.9.9 - Buffer Overflow
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.
CWE-787
Dec 30, 2009
CVE-2013-10051
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.76
InstantCMS <1.6 - RCE
A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() within the search view handler. Specifically, user-supplied input passed via the look parameter is concatenated into a PHP expression and executed without proper sanitation. A remote attacker can exploit this flaw by sending a crafted HTTP GET request with a base64-encoded payload in the Cmd header, resulting in arbitrary PHP code execution within the context of the web server.
CWE-95
Aug 01, 2025
CVE-2007-4620
2 PoCs
Analysis
EPSS 0.76
CA Alert Notification Service <8.1.586.0 - RCE
Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used in multiple CA products including Anti-Virus for the Enterprise 7.1 through r11.1 and Threat Manager for the Enterprise 8.1 and r8, allow remote authenticated users to execute arbitrary code via crafted RPC requests.
CWE-119
Apr 07, 2008