High EPSS Vulnerabilities with Public Exploits

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,402 CVEs tracked 53,629 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,301 vendors 43,863 researchers
3,485 results Clear all
CVE-2006-2447 3 PoCs Analysis EPSS 0.76
SpamAssassin <3.1.3 - RCE
SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.
Jun 06, 2006
CVE-2007-5603 3 PoCs Analysis EPSS 0.76
Sonicwall SSL VPN < 2.1 - Memory Corruption
Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remote attackers to execute arbitrary code via a long string in the second argument to the AddRouteEntry method.
CWE-119 Nov 05, 2007
CVE-2003-0558 3 PoCs Analysis EPSS 0.76
LeapFTP 2.7.3.600 - Buffer Overflow
Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request.
Aug 18, 2003
CVE-2017-13089 8.8 HIGH 2 PoCs Analysis EPSS 0.76
GNU Wget < 1.19.1 - Memory Corruption
The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects. When the response is sent chunked in wget before 1.19.2, the chunk parser uses strtol() to read each chunk's length, but doesn't check that the chunk length is a non-negative number. The code then tries to skip the chunk in pieces of 512 bytes by using the MIN() macro, but ends up passing the negative chunk length to connect.c:fd_read(). As fd_read() takes an int argument, the high 32 bits of the chunk length are discarded, leaving fd_read() with a completely attacker controlled length argument.
CWE-119 Oct 27, 2017
CVE-2007-0217 1 PoC Analysis EPSS 0.76
Microsoft Internet Explorer <6 - RCE
The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.
Feb 13, 2007
CVE-2009-1025 1 PoC Analysis EPSS 0.76
Beerwin Phplinkadmin - Code Injection
PHP remote file inclusion vulnerability in linkadmin.php in Beerwin PHPLinkAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
CWE-94 Mar 20, 2009
CVE-2005-3757 3 PoCs Analysis EPSS 0.76
Google Mini Search Appliance - RCE
The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to obtain sensitive information and execute arbitrary code via dangerous Java class methods in select attribute of xsl:value-of tags in XSLT style sheets, such as (1) system-property, (2) sys:getProperty, and (3) run:exec.
Nov 22, 2005
CVE-2024-46981 7.0 HIGH 2 PoCs Analysis EPSS 0.76
Redis < 6.2.17 - Use After Free
Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the garbage collector and potentially lead to remote code execution. The problem is fixed in 7.4.2, 7.2.7, and 6.2.17. An additional workaround to mitigate the problem without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands.
CWE-416 Jan 06, 2025
CVE-2005-2120 3 PoCs Analysis EPSS 0.76
Microsoft Windows 2000 - Buffer Overflow
Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.
Oct 13, 2005
CVE-2014-2850 1 PoC Analysis EPSS 0.76
Sophos Web Appliance Firmware < 3.8.1.1 - OS Command Injection
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter.
CWE-78 Apr 11, 2014
CVE-2023-2114 7.2 HIGH 1 PoC Analysis EPSS 0.76
NEX-Forms WP <8.4 - SQL Injection
The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query.
CWE-89 May 08, 2023
CVE-2007-0325 2 PoCs Analysis EPSS 0.76
Trend Micro Client-server-messaging Security - Memory Corruption
Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow remote attackers to execute arbitrary code via a crafted HTML document.
CWE-119 Feb 20, 2007
CVE-2011-5003 2 PoCs Analysis EPSS 0.76
Avid Media Composer < 5.5.3 - Memory Corruption
Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier allows remote attackers to execute arbitrary code via a long request to TCP port 4659.
CWE-119 Dec 25, 2011
CVE-2006-6665 3 PoCs Analysis EPSS 0.76
Astonsoft DeepBurner Pro & Free <1.8.0 - RCE
Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name tag in a dbr file.
Dec 20, 2006
CVE-2018-0780 5.3 MEDIUM 1 PoC Analysis EPSS 0.76
Microsoft Edge < 1.7.6 - Out-of-Bounds Read
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0767 and CVE-2018-0800.
CWE-125 Jan 04, 2018
CVE-2018-0767 5.3 MEDIUM 1 PoC Analysis EPSS 0.76
Microsoft Chakracore < 1.7.6 - Out-of-Bounds Read
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0780 and CVE-2018-0800.
CWE-125 Jan 04, 2018
CVE-2019-19368 6.1 MEDIUM 2 PoCs Analysis NUCLEI EPSS 0.76
Rumpus FTP Web File Manager 8.2.9.1 - XSS
A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker can exploit it by sending a crafted link to end users and can execute arbitrary Javascripts
CWE-79 Dec 16, 2019
CVE-2013-4837 2 PoCs Analysis EPSS 0.76
HP LoadRunner <11.52 - RCE
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1832.
Nov 04, 2013
CVE-2013-2343 2 PoCs Analysis EPSS 0.76
HP LeftHand Virtual SAN Appliance <10.0 - RCE
Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1510.
Jul 02, 2013
CVE-2012-2019 2 PoCs Analysis EPSS 0.76
HP Operations Agent <11.03.12 - RCE
Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1325.
Jul 11, 2012