High EPSS Vulnerabilities with Public Exploits
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
3,484 results
Clear all
CVE-2013-1600
5.3
MEDIUM
1 PoC
Analysis
EPSS 0.73
Dlink Dcs-2102 Firmware - Authentication Bypass
An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-2121 1.06_FR, 1.06, and 1.05_RU, DCS-2102 1.06_FR. 1.06, and 1.05_RU, which could let a malicious user obtain sensitive information.
CWE-287
Jan 28, 2020
CVE-2023-0099
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.73
Simple URLs WP <115 - XSS
The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Feb 13, 2023
CVE-2013-1080
2 PoCs
Analysis
EPSS 0.73
Novell Zenworks Configuration Management - Authentication Bypass
The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory traversal attacks, and consequently upload and execute arbitrary programs, via a request to TCP port 443.
CWE-287
Mar 29, 2013
CVE-2021-21809
9.1
CRITICAL
2 PoCs
Analysis
EPSS 0.73
Moodle Authenticated Spelling Binary RCE
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.
CWE-78
Jun 23, 2021
CVE-2012-1775
2 PoCs
Analysis
EPSS 0.73
Videolan Vlc Media Player < 2.0.0 - Memory Corruption
Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code via a crafted MMS:// stream.
CWE-119
Mar 19, 2012
CVE-2020-13699
8.8
HIGH
2 PoCs
Analysis
EPSS 0.73
TeamViewer Unquoted URI Handler SMB Redirect
TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. An attacker could force a victim to send an NTLM authentication request and either relay the request or capture the hash for offline password cracking. This affects teamviewer10, teamviewer8, teamviewerapi, tvchat1, tvcontrol1, tvfiletransfer1, tvjoinv8, tvpresent1, tvsendfile1, tvsqcustomer1, tvsqsupport1, tvvideocall1, and tvvpn1. The issue is fixed in 8.0.258861, 9.0.258860, 10.0.258873, 11.0.258870, 12.0.258869, 13.2.36220, 14.2.56676, 14.7.48350, and 15.8.3.
CWE-88
Jul 29, 2020
CVE-2024-0507
6.5
MEDIUM
1 PoC
Analysis
EPSS 0.73
GitHub Enterprise Server - Privilege Escalation
An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3, 3.10.5, 3.9.8, and 3.8.13 This vulnerability was reported via the GitHub Bug Bounty program.
CWE-20
Jan 16, 2024
CVE-2005-0560
1 PoC
Analysis
EPSS 0.73
Microsoft Exchange Server - Out-of-Bounds Write
Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.
CWE-787
May 02, 2005
CVE-2018-8544
8.8
HIGH
1 PoC
Analysis
EPSS 0.73
Windows VBScript Engine - RCE
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
CWE-416
Nov 14, 2018
CVE-2023-49606
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
EPSS 0.73
Tinyproxy - Use After Free
A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability.
CWE-416
May 01, 2024
CVE-2025-2611
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.73
ICTBroadcast - Command Injection
The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling.
Versions 7.4 and below are known to be vulnerable.
CWE-78
Aug 05, 2025
CVE-2015-7603
2 PoCs
Analysis
EPSS 0.73
Konica Minolta FTP Utility 1.0 - Path Traversal
Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in a RETR command.
CWE-22
Sep 29, 2015
CVE-2017-18371
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.73
Billion 5200w-t Firmware - Hard-coded Credentials
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username supervisor and password zyad1234. These accounts can be used to login to the web interface, exploit authenticated command injections, and change router settings for malicious purposes.
CWE-798
May 02, 2019
CVE-2017-8386
8.8
HIGH
1 PoC
Analysis
EPSS 0.73
git <2.4.12-2.12.3 - Privilege Escalation
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.
Jun 01, 2017
CVE-2007-3798
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.73
tcpdump <3.9.6 - RCE
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
CWE-252
Jul 16, 2007
CVE-2007-0348
2 PoCs
Analysis
EPSS 0.73
Interactual Technologies Interactual Player - Memory Corruption
Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property.
CWE-119
Mar 21, 2007
CVE-2023-46474
7.2
HIGH
1 PoC
Analysis
EPSS 0.73
PMB 7.4.8 - RCE
File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php file.
CWE-434
Jan 11, 2024
CVE-2004-0363
2 PoCs
Analysis
EPSS 0.73
Norton AntiSpam 2004 - Buffer Overflow
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.
Apr 15, 2004
CVE-2025-13486
9.8
CRITICAL
EXPLOITED
9 PoCs
Analysis
NUCLEI
EPSS 0.73
Advanced Custom Fields: Extended <0.9.1.1 - RCE
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.
CWE-94
Dec 03, 2025
CVE-2018-6317
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.73
Claymore Dual Miner < 10.5 - Format String Vulnerability
The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allowing remote attackers to read memory or cause a denial of service.
CWE-134
Feb 02, 2018