High EPSS Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,363 CVEs tracked 53,626 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,844 researchers
3,484 results Clear all
CVE-2008-0115 1 PoC Analysis EPSS 0.72
Microsoft Excel - Code Injection
Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via malformed formulas, aka "Excel Formula Parsing Vulnerability."
CWE-94 Mar 11, 2008
CVE-2013-6829 2 PoCs Analysis EPSS 0.72
Pineapp Mail-secure - Code Injection
admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pinghost parameter during a ping operation.
CWE-94 Nov 20, 2013
CVE-2018-10583 7.5 HIGH 5 PoCs Analysis EPSS 0.72
LibreOffice 6.0.3 - Apache OpenOffice Writer 4.1.5 - Info Disclosure
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.
CWE-200 May 01, 2018
CVE-2008-4385 2 PoCs Analysis EPSS 0.72
Systemrequirementslab System Requirements Lab - Code Injection
Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the download and execution of arbitrary programs via by specifiying a malicious website argument to the Init method in (1) a certain ActiveX control (sysreqlab2.cab, sysreqlab.dll, sysreqlabsli.dll, or sysreqlab2.dll) and (2) a certain Java applet in RLApplet.class in sysreqlab2.jar or sysreqlab.jar.
CWE-94 Oct 14, 2008
CVE-2021-3110 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.72
Prestashop - SQL Injection
The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.
CWE-89 Jan 20, 2021
CVE-2020-4450 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.72
IBM Websphere Application Server < 8.5.5.18 - Insecure Deserialization
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.
CWE-502 Jun 05, 2020
CVE-2008-2549 1 PoC Analysis EPSS 0.72
Adobe Acrobat Reader < 8.1.2 - Denial of Service
Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed PDF document, as demonstrated by 2008-HI2.pdf.
Jun 04, 2008
CVE-2010-4566 3 PoCs Analysis EPSS 0.72
Citrix Access Gateway <5.0 - Command Injection
The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.
Jan 14, 2011
CVE-2008-0871 3 PoCs Analysis EPSS 0.72
NOW Sms Mms Gateway < 2007.06.27 - Memory Corruption
Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute arbitrary code via a (1) long password in an Authorization header to the HTTP service or a (2) large packet to the SMPP service.
CWE-119 Feb 21, 2008
CVE-2020-13965 6.1 MEDIUM KEV 1 PoC Analysis EPSS 0.72
Roundcube Webmail < 1.3.12 - Basic XSS
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
CWE-80 Jun 09, 2020
CVE-2005-0684 2 PoCs Analysis EPSS 0.72
Mysql Maxdb - Buffer Overflow
Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent ("%") sign or (2) a long Lock-Token string to the WebDAV functionality, which is not properly handled by the getLockTokenHeader function in WDVHandler_CommonUtils.c.
Apr 25, 2005
CVE-2019-8985 9.8 CRITICAL 1 PoC Analysis EPSS 0.72
Netis-systems Wf2411 Firmware - Out-of-Bounds Write
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability can be triggered by a GET request with a long HTTP "Authorization: Basic" header that is mishandled by user_auth->user_ok in /bin/boa.
CWE-306 Feb 21, 2019
CVE-2022-30512 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.72
School Dormitory Management System - SQL Injection
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31.
CWE-89 Jun 02, 2022
CVE-2009-4498 3 PoCs Analysis EPSS 0.72
Zabbix Server <1.8 - Command Injection
The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request.
CWE-78 Dec 31, 2009
CVE-2015-2468 1 PoC Analysis EPSS 0.72
Microsoft Office - Memory Corruption
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office for Mac 2011, Office for Mac 2016, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Word Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
CWE-119 Aug 15, 2015
CVE-2005-2551 3 PoCs Analysis EPSS 0.72
Novell Edirectory - Buffer Overflow
Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors.
Aug 12, 2005
CVE-2005-1018 2 PoCs Analysis EPSS 0.72
CA BrightStor ARCserve Backup - Buffer Overflow
Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows remote authenticated users to cause a denial of service or execute arbitrary code via an agent request to TCP port 6050 with a large argument before the option field.
May 02, 2005
CVE-2012-5965 1 PoC Analysis EPSS 0.72
Portable SDK For Upnp - Memory Corruption
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) 1.3.1 allows remote attackers to execute arbitrary code via a long DeviceType (aka urn device) field in a UDP packet.
CWE-119 Jan 31, 2013
CVE-2019-8953 6.1 MEDIUM 1 PoC Analysis EPSS 0.72
Netgate Haproxy < 0.59_16 - XSS
The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and haproxy_listeners_edit.php.
CWE-79 Feb 20, 2019
CVE-2013-10069 9.8 CRITICAL 2 PoCs Analysis EPSS 0.72
D-Link DIR-600 DIR-300 - Command Injection
The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in command.php, which improperly handles the cmd POST parameter. A remote attacker can exploit this flaw without authentication to spawn a Telnet service on a specified port, enabling persistent interactive shell access as root.
CWE-78 Aug 05, 2025