High EPSS Vulnerabilities with Public Exploits
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
3,484 results
Clear all
CVE-2004-0176
2 PoCs
Analysis
EPSS 0.71
Ethereal - Buffer Overflow
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.
May 04, 2004
CVE-2015-5574
1 PoC
Analysis
EPSS 0.71
Adobe Flash Player <18.0.0.241, 19.x <19.0.0.185 - RCE
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5581, CVE-2015-5584, and CVE-2015-6682.
Sep 22, 2015
CVE-2007-2280
2 PoCs
Analysis
EPSS 0.71
HP Openview Storage Data Protector - Memory Corruption
Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via an MSG_PROTOCOL command with long arguments, a different vulnerability than CVE-2009-3844.
CWE-119
Dec 18, 2009
CVE-2014-3789
2 PoCs
Analysis
EPSS 0.71
Cogentdatahub Cogent Datahub < 7.3.4 - Code Injection
GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary commands via unspecified vectors.
CWE-94
May 22, 2014
CVE-2024-7399
8.8
HIGH
KEV
2 PoCs
Analysis
NUCLEI
EPSS 0.71
Samsung MagicINFO 9 Server Remote Code Execution (CVE-2024-7399)
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
CWE-22
Aug 12, 2024
CVE-2018-6328
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.71
Kaseya Unitrends Backup < 10.1 - Authentication Bypass
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.
CWE-287
Mar 14, 2018
CVE-2016-0638
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.71
Oracle WebLogic Server - Info Disclosure
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.
Apr 21, 2016
CVE-2022-37122
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.71
Carel Pcoweb Card Firmware < b.2.1.0 - Path Traversal
Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.
CWE-22
Aug 31, 2022
CVE-2022-39227
9.1
CRITICAL
2 PoCs
Analysis
EPSS 0.71
Python-jwt < 3.3.4 - Authentication Bypass by Spoofing
python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.
CWE-290
Sep 23, 2022
CVE-2016-0709
7.2
HIGH
1 PoC
Analysis
EPSS 0.71
Apache Jetspeed <2.3.1 - Path Traversal
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot dot) in a ZIP archive entry, as demonstrated by "../../webapps/x.jsp."
CWE-22
Apr 11, 2016
CVE-2017-8225
9.8
CRITICAL
EXPLOITED
4 PoCs
Analysis
EPSS 0.71
Wificam Wireless IP Camera (p2p) Firm... - Insufficiently Protected Credentials
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas parameter in the URI.
CWE-522
Apr 25, 2017
CVE-2013-1349
2 PoCs
Analysis
EPSS 0.71
Os4ed Opensis - Code Injection
Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP code via the modname parameter.
CWE-94
Dec 09, 2013
CVE-2003-0780
2 PoCs
Analysis
EPSS 0.71
MySQL <4.0.14 & <3.23.x - RCE
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field.
Sep 22, 2003
CVE-2013-6414
1 PoC
Analysis
EPSS 0.71
Rails < 4.0.1 - Improper Input Validation
actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.
CWE-20
Dec 07, 2013
CVE-2019-20372
5.3
MEDIUM
3 PoCs
Analysis
EPSS 0.71
F5 Nginx < 1.17.7 - HTTP Request Smuggling
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
CWE-444
Jan 09, 2020
CVE-2018-18852
8.8
HIGH
EXPLOITED
2 PoCs
Analysis
EPSS 0.71
Cerio Dt-300n Firmware < 1.1.12 - OS Command Injection
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018.
CWE-78
Jun 18, 2019
CVE-2017-16082
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.71
Node-postgres PG < 2.11.2 - Code Injection
A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.
CWE-94
Jun 07, 2018
CVE-2011-2750
1 PoC
Analysis
EPSS 0.71
Novell File Reporter < 1.0.4.2 - Resource Management Error
NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5 request to /FSF/CMD.
CWE-399
Jul 17, 2011
CVE-2024-0200
7.2
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.71
Github Enterprise Server < 3.8.13 - Remote Code Execution
An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-controlled methods and remote code execution. To exploit this bug, an actor would need to be logged into an account on the GHES instance with the organization owner role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.8.13, 3.9.8, 3.10.5, and 3.11.3. This vulnerability was reported via the GitHub Bug Bounty program.
CWE-470
Jan 16, 2024
CVE-1999-0532
4 PoCs
Analysis
EPSS 0.71
DNS Server - SSRF
A DNS server allows zone transfers.
Jul 01, 1997