High EPSS Vulnerabilities with Public Exploits
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
3,484 results
Clear all
CVE-2018-11529
8.0
HIGH
2 PoCs
Analysis
EPSS 0.74
Debian Linux < 2.2.8 - Use After Free
VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result in denial of service conditions.
CWE-416
Jul 11, 2018
CVE-2007-1211
3 PoCs
Analysis
EPSS 0.74
Microsoft Windows - DoS
Unspecified kernel GDI functions in Microsoft Windows 2000 SP4; XP SP2; and Server 2003 Gold, SP1, and SP2 allows user-assisted remote attackers to cause a denial of service (possibly persistent restart) via a crafted Windows Metafile (WMF) image that causes an invalid dereference of an offset in a kernel structure, a related issue to CVE-2005-4560.
CWE-399
Apr 04, 2007
CVE-2014-8420
1 PoC
Analysis
EPSS 0.74
Sonicwall Analyzer - Improper Input Validation
The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA before 7.2 SP2 allows remote authenticated users to execute arbitrary code via unspecified vectors.
CWE-20
Nov 25, 2014
CVE-2019-9760
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.74
FTPGetter Standard <5.97.0.177 - RCE
FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-controlled machine that sends crafted responses. Long responses can also crash the FTP client with memory corruption.
CWE-787
Mar 14, 2019
CVE-2020-5844
7.2
HIGH
3 PoCs
Analysis
EPSS 0.74
Pandora FMS v7.0 NG - Authenticated RCE
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.
CWE-434
Mar 16, 2020
CVE-2007-3386
1 PoC
Analysis
EPSS 0.74
Apache Tomcat - XSS
Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.
CWE-79
Aug 14, 2007
CVE-2023-6505
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.74
Migrate WP <1.9.3 - Path Traversal
The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files.
Jan 08, 2024
CVE-2007-2708
1 PoC
Analysis
EPSS 0.74
Feindt Computerservice News <2.0 - RCE
PHP remote file inclusion vulnerability in newsadmin.php in Feindt Computerservice News (News-Script) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.
May 16, 2007
CVE-2025-49706
6.5
MEDIUM
KEV
RANSOMWARE
3 PoCs
Analysis
NUCLEI
EPSS 0.74
Microsoft Sharepoint Enterprise Server - Authentication Bypass
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CWE-287
Jul 08, 2025
CVE-2013-10066
CRITICAL
2 PoCs
Analysis
EPSS 0.74
Kordil EDMS v2.2.60rc3 - Unauthenticated RCE
An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The application exposes an upload endpoint (users_add.php) that allows attackers to upload files to the /userpictures/ directory without authentication. This flaw enables remote code execution by uploading a PHP payload and invoking it via a direct HTTP request.
CWE-434
Aug 05, 2025
CVE-2013-10054
CRITICAL
3 PoCs
Analysis
EPSS 0.74
LibrettoCMS 1.1.7 - Unauthenticated RCE
An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contains an unauthenticated arbitrary file upload vulnerability in its File Manager plugin. The upload handler located at adm/ui/js/ckeditor/plugins/pgrfilemanager/php/upload.php fails to properly validate file extensions, allowing attackers to upload files with misleading extensions and subsequently rename them to executable .php scripts. This enables remote code execution on the server without authentication.
CWE-434
Aug 04, 2025
CVE-2012-10027
CRITICAL
3 PoCs
Analysis
EPSS 0.74
WP-Property <1.35.0 - RCE
WP-Property plugin for WordPress through version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a temporary directory without authentication, leading to remote code execution.
CWE-434
Aug 05, 2025
CVE-2010-2746
1 PoC
Analysis
EPSS 0.74
Microsoft Windows XP-7 - Buffer Overflow
Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when a third-party SVG viewer is used, allows remote attackers to execute arbitrary code via a crafted HTML document that triggers unspecified messages from this viewer, aka "Comctl32 Heap Overflow Vulnerability."
CWE-119
Oct 13, 2010
CVE-2018-10094
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.74
Dolibarr <7.0.2 - SQL Injection
SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes.
CWE-89
May 22, 2018
CVE-2019-11447
8.8
HIGH
EXPLOITED
10 PoCs
Analysis
EPSS 0.74
CutePHP CuteNews 2.1.2 - Code Injection
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)
CWE-434
Apr 22, 2019
CVE-2019-25065
6.3
MEDIUM
EXPLOITED
3 PoCs
Analysis
EPSS 0.74
OpenNetAdmin 18.1.1 - Privilege Escalation
A vulnerability was found in OpenNetAdmin 18.1.1. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to privilege escalation. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-78
Jun 09, 2022
CVE-2019-12347
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.74
pfSense 2.4.4-p3 - XSS
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability occurs due to input validation errors.
CWE-79
May 29, 2019
CVE-2007-5208
2 PoCs
Analysis
EPSS 0.74
HP Linux Imaging And Printing Project - Improper Input Validation
hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a from address, which is not properly handled when invoking sendmail.
CWE-20
Oct 13, 2007
CVE-2025-34111
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.74
Tikiwiki Cms/groupware < 15.1 - Missing Authentication
An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to upload and execute malicious PHP scripts in the context of the web server. The vulnerable component does not enforce file type validation, allowing attackers to craft a POST request to upload executable PHP payloads through the ELFinder interface exposed at /vendor_extra/elfinder/.
CWE-306
Jul 15, 2025
CVE-2008-6938
2 PoCs
Analysis
EPSS 0.74
Holger Zimmermann Pi3web < 2.0.3_pl1 - Improper Input Validation
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which triggers the crash when the DLL load fails, as demonstrated using Isapi\users.txt.
CWE-20
Aug 11, 2009