High EPSS Vulnerabilities with Public Exploits

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,361 CVEs tracked 53,621 with exploits 4,857 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,840 researchers
3,484 results Clear all
CVE-2004-0176 2 PoCs Analysis EPSS 0.71
Ethereal - Buffer Overflow
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.
May 04, 2004
CVE-2015-5574 1 PoC Analysis EPSS 0.71
Adobe Flash Player <18.0.0.241, 19.x <19.0.0.185 - RCE
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5581, CVE-2015-5584, and CVE-2015-6682.
Sep 22, 2015
CVE-2007-2280 2 PoCs Analysis EPSS 0.71
HP Openview Storage Data Protector - Memory Corruption
Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via an MSG_PROTOCOL command with long arguments, a different vulnerability than CVE-2009-3844.
CWE-119 Dec 18, 2009
CVE-2014-3789 2 PoCs Analysis EPSS 0.71
Cogentdatahub Cogent Datahub < 7.3.4 - Code Injection
GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary commands via unspecified vectors.
CWE-94 May 22, 2014
CVE-2024-7399 8.8 HIGH KEV 2 PoCs Analysis NUCLEI EPSS 0.71
Samsung MagicINFO 9 Server Remote Code Execution (CVE-2024-7399)
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
CWE-22 Aug 12, 2024
CVE-2018-6328 9.8 CRITICAL 3 PoCs Analysis EPSS 0.71
Kaseya Unitrends Backup < 10.1 - Authentication Bypass
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.
CWE-287 Mar 14, 2018
CVE-2016-0638 9.8 CRITICAL 3 PoCs Analysis EPSS 0.71
Oracle WebLogic Server - Info Disclosure
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.
Apr 21, 2016
CVE-2022-37122 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.71
Carel Pcoweb Card Firmware < b.2.1.0 - Path Traversal
Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.
CWE-22 Aug 31, 2022
CVE-2022-39227 9.1 CRITICAL 2 PoCs Analysis EPSS 0.71
Python-jwt < 3.3.4 - Authentication Bypass by Spoofing
python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.
CWE-290 Sep 23, 2022
CVE-2016-0709 7.2 HIGH 1 PoC Analysis EPSS 0.71
Apache Jetspeed <2.3.1 - Path Traversal
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot dot) in a ZIP archive entry, as demonstrated by "../../webapps/x.jsp."
CWE-22 Apr 11, 2016
CVE-2017-8225 9.8 CRITICAL EXPLOITED 4 PoCs Analysis EPSS 0.71
Wificam Wireless IP Camera (p2p) Firm... - Insufficiently Protected Credentials
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas parameter in the URI.
CWE-522 Apr 25, 2017
CVE-2013-1349 2 PoCs Analysis EPSS 0.71
Os4ed Opensis - Code Injection
Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP code via the modname parameter.
CWE-94 Dec 09, 2013
CVE-2003-0780 2 PoCs Analysis EPSS 0.71
MySQL <4.0.14 & <3.23.x - RCE
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field.
Sep 22, 2003
CVE-2013-6414 1 PoC Analysis EPSS 0.71
Rails < 4.0.1 - Improper Input Validation
actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.
CWE-20 Dec 07, 2013
CVE-2019-20372 5.3 MEDIUM 3 PoCs Analysis EPSS 0.71
F5 Nginx < 1.17.7 - HTTP Request Smuggling
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
CWE-444 Jan 09, 2020
CVE-2018-18852 8.8 HIGH EXPLOITED 2 PoCs Analysis EPSS 0.71
Cerio Dt-300n Firmware < 1.1.12 - OS Command Injection
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018.
CWE-78 Jun 18, 2019
CVE-2017-16082 9.8 CRITICAL 1 PoC Analysis EPSS 0.71
Node-postgres PG < 2.11.2 - Code Injection
A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.
CWE-94 Jun 07, 2018
CVE-2011-2750 1 PoC Analysis EPSS 0.71
Novell File Reporter < 1.0.4.2 - Resource Management Error
NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5 request to /FSF/CMD.
CWE-399 Jul 17, 2011
CVE-2024-0200 7.2 HIGH 1 PoC Analysis NUCLEI EPSS 0.71
Github Enterprise Server < 3.8.13 - Remote Code Execution
An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-controlled methods and remote code execution. To exploit this bug, an actor would need to be logged into an account on the GHES instance with the organization owner role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.8.13, 3.9.8, 3.10.5, and 3.11.3. This vulnerability was reported via the GitHub Bug Bounty program.
CWE-470 Jan 16, 2024
CVE-1999-0532 4 PoCs Analysis EPSS 0.71
DNS Server - SSRF
A DNS server allows zone transfers.
Jul 01, 1997