High EPSS Vulnerabilities with Public Exploits
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
3,484 results
Clear all
CVE-2019-6447
8.1
HIGH
16 PoCs
Analysis
EPSS 0.71
Estrongs ES File Explorer File Manager - Missing Authentication
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.
CWE-306
Jan 16, 2019
CVE-2005-0581
7 PoCs
Analysis
EPSS 0.71
Broadcom License Software - Buffer Overflow
Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execute arbitrary code via (1) certain long fields in the Checksum item in a GCR request, (2) a long IP address, hostname, or netmask values in a GCR request, (3) a long last parameter in a GETCONFIG packet, or (4) long values in a request with an invalid format.
May 02, 2005
CVE-2020-35576
8.8
HIGH
1 PoC
Analysis
EPSS 0.71
Tp-link Tl-wr841n Firmware < 201216 - OS Command Injection
A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different vulnerability than CVE-2018-12577.
CWE-78
Jan 26, 2021
CVE-2009-2484
3 PoCs
Analysis
EPSS 0.71
VLC media player <0.9.9 - Buffer Overflow
Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.9, when running on Microsoft Windows, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long smb URI in a playlist file.
CWE-119
Jul 16, 2009
CVE-2015-0064
1 PoC
Analysis
EPSS 0.71
Microsoft Web Applications - Resource Management Error
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applications 2010 SP2, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Office Remote Code Execution Vulnerability."
CWE-399
Feb 11, 2015
CVE-2015-10138
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.71
The Work The Flow File Upload plugin - Path Traversal
The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
CWE-434
Jul 19, 2025
CVE-2015-2856
7.5
HIGH
1 PoC
Analysis
EPSS 0.71
Accellion File Transfer Appliance < fta_9_11_200 - Path Traversal
Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices before FTA_9_11_210 allows remote attackers to read arbitrary files via a .. (dot dot) in the statecode cookie.
CWE-22
Oct 10, 2017
CVE-2022-28079
8.8
HIGH
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.71
College Management System - SQL Injection
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.
CWE-89
May 05, 2022
CVE-2014-3996
2 PoCs
Analysis
EPSS 0.71
ManageEngine <9-0.90043 - SQL Injection
SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to LinkViewFetchServlet.dat.
CWE-89
Dec 05, 2014
CVE-2015-0273
1 PoC
Analysis
EPSS 0.71
Php < 5.4.37 - Use After Free
Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allow remote attackers to execute arbitrary code via crafted serialized input containing a (1) R or (2) r type specifier in (a) DateTimeZone data handled by the php_date_timezone_initialize_from_hash function or (b) DateTime data handled by the php_date_initialize_from_hash function.
Mar 30, 2015
CVE-2024-53375
8.0
HIGH
EXPLOITED
1 PoC
Analysis
EPSS 0.71
TP-Link Archer - Authenticated RCE
An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exists in the "tmp_get_sites" function of the HomeShield functionality provided by TP-Link. This vulnerability is still exploitable without the activation of the HomeShield functionality.
CWE-78
Dec 02, 2024
CVE-2016-8610
7.5
HIGH
2 PoCs
Analysis
EPSS 0.71
OpenSSL <1.1.0 - DoS
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
CWE-400
Nov 13, 2017
CVE-2018-14417
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.71
SoftNAS Cloud <4.0.3 - Command Injection
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.
CWE-78
Aug 04, 2018
CVE-2005-4832
5 PoCs
Analysis
EPSS 0.71
Oracle Database Server 10g - SQL Injection
SQL injection vulnerability in the Oracle Database Server 10g allows remote authenticated users to execute arbitrary SQL commands with elevated privileges via the SUBSCRIPTION_NAME parameter in the (1) SYS.DBMS_CDC_SUBSCRIBE and (2) SYS.DBMS_CDC_ISUBSCRIBE packages, a different vector than CVE-2005-1197.
Dec 31, 2005
CVE-2018-7665
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.71
Clip-bucket Clipbucket < 4.0.0 - Unrestricted File Upload
An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter to actions/beats_uploader.php or actions/photo_uploader.php, or the coverPhoto parameter to edit_account.php.
CWE-434
Mar 05, 2018
CVE-2011-0517
3 PoCs
Analysis
EPSS 0.71
Sielcosistemi Winlog Pro < 2.07.00 - Memory Corruption
Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted 0x02 opcode to TCP port 46823.
CWE-119
Jan 20, 2011
CVE-2014-1510
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
EPSS 0.71
Mozilla Firefox < 28.0 - Improper Privilege Management
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment to trigger a window.open call.
CWE-269
Mar 19, 2014
CVE-2019-8449
5.3
MEDIUM
3 PoCs
Analysis
NUCLEI
EPSS 0.71
Atlassian Jira < 8.4.0 - Missing Authentication
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
CWE-306
Sep 11, 2019
CVE-2024-42845
8.0
HIGH
2 PoCs
Analysis
EPSS 0.71
InVesalius <3.1.99998 - Code Injection
An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to execute arbitrary code via loading a crafted DICOM file.
CWE-94
Aug 23, 2024
CVE-2014-1764
1 PoC
Analysis
EPSS 0.71
Microsoft Internet Explorer <11 - RCE
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism by leveraging "object confusion" in a broker process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
CWE-264
Apr 27, 2014