High EPSS Vulnerabilities with Public Exploits

Updated 33m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,378 CVEs tracked 53,627 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,849 researchers
3,484 results Clear all
CVE-2022-22960 7.8 HIGH KEV 1 PoC Analysis EPSS 0.73
VMware Workspace ONE Access CVE-2022-22960
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.
CWE-732 Apr 13, 2022
CVE-1999-0526 EXPLOITED 3 PoCs Analysis EPSS 0.73
X Server - Info Disclosure
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
Jul 01, 1997
CVE-2004-0798 3 PoCs Analysis EPSS 0.73
Ipswitch WhatsUp Gold <8.03.1 - RCE
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary code via a long instancename parameter.
Oct 20, 2004
CVE-2021-43267 9.8 CRITICAL 3 PoCs Analysis EPSS 0.73
Linux Kernel <5.14.16 - RCE
An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.
CWE-1284 Nov 02, 2021
CVE-2009-3693 3 PoCs Analysis EPSS 0.73
Persits Xupload - Path Traversal
Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows remote attackers to create arbitrary files via \.. (backwards slash dot dot) sequences in the third argument to the MakeHttpRequest method.
CWE-22 Oct 13, 2009
CVE-2006-5559 EXPLOITED 1 PoC Analysis EPSS 0.73
Microsoft Data Access Components - Improper Input Validation
The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
CWE-20 Oct 27, 2006
CVE-2018-3714 6.5 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.73
Node-srv < 2.1.1 - Path Traversal
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.
CWE-22 Jun 07, 2018
CVE-2015-0081 1 PoC Analysis EPSS 0.73
Microsoft Windows 7 - Remote Code Execution
Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "WTS Remote Code Execution Vulnerability."
CWE-19 Mar 11, 2015
CVE-2006-0143 1 PoC Analysis EPSS 0.73
Microsoft Windows 2000 - Resource Management Error
Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.
CWE-399 Jan 09, 2006
CVE-2019-14271 9.8 CRITICAL 1 PoC Analysis EPSS 0.73
Docker 19.03.x <19.03.1 - Code Injection
In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.
CWE-665 Jul 29, 2019
CVE-2009-3033 2 PoCs Analysis EPSS 0.73
Symantec Altiris Deployment Solution - Memory Corruption
Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Symantec Altiris Deployment Solution 6.9.x, Altiris Notification Server 6.0.x, and Management Platform 7.0.x allows remote attackers to execute arbitrary code via a long string in the second argument.
CWE-119 Nov 25, 2009
CVE-2021-44026 9.8 CRITICAL KEV 2 PoCs Analysis EPSS 0.73
Roundcube Webmail < 1.3.17 - SQL Injection
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
CWE-89 Nov 19, 2021
CVE-2016-6267 8.8 HIGH 1 PoC Analysis EPSS 0.73
Trend Micro Smart Protection Server <3.0.1330 - Command Injection
SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) spare_Community, (2) spare_AllowGroupIP, or (3) spare_AllowGroupNetmask parameter to admin_notification.php.
CWE-20 Jan 30, 2017
CVE-2006-5792 4 PoCs Analysis EPSS 0.73
XLink Omni-NFS Enterprise - RCE
Unspecified vulnerability in XLink Omni-NFS Enterprise allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by vd_xlink2.pm, an "Omni-NFS Enterprise remote exploit." NOTE: this is probably a different vulnerability than CVE-2006-5780. As of 20061107, this disclosure has no actionable information. However, since it is from a reliable researcher, it is being assigned a CVE identifier for tracking purposes.
Nov 07, 2006
CVE-2022-24715 8.5 HIGH 5 PoCs Analysis EPSS 0.73
Icinga Web 2 <2.8.6-2.10 - Authenticated RCE
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 configuration.
CWE-22 Mar 08, 2022
CVE-2006-3440 1 PoC Analysis EPSS 0.72
Microsoft Windows 2000 - Buffer Overflow
Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka "Winsock Hostname Vulnerability."
Aug 09, 2006
CVE-2014-9034 3 PoCs Analysis EPSS 0.72
WordPress Long Password DoS
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.
CWE-19 Nov 25, 2014
CVE-2024-47533 9.8 CRITICAL 5 PoCs Analysis NUCLEI EPSS 0.72
Cobbler <3.2.3, <3.3.7 - Auth Bypass
Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.
CWE-287 Nov 18, 2024
CVE-2007-4515 3 PoCs Analysis EPSS 0.72
Yahoo! services suite - Buffer Overflow
Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execute arbitrary code via unspecified vectors involving arguments to the (1) fvCom and (2) info methods. NOTE: some of these details are obtained from third party information.
CWE-119 Aug 31, 2007
CVE-2018-8735 8.8 HIGH 4 PoCs Analysis EPSS 0.72
Nagios XI <5.4.13 - RCE
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection.
CWE-78 Apr 18, 2018