High EPSS Vulnerabilities with Public Exploits

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,361 CVEs tracked 53,621 with exploits 4,857 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,840 researchers
3,484 results Clear all
CVE-2012-4705 2 PoCs Analysis EPSS 0.70
3S CODESYS Gateway-Server <2.3.9.27 - Path Traversal
Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors involving a crafted pathname.
CWE-22 Feb 24, 2013
CVE-2021-26690 7.5 HIGH 3 PoCs Analysis EPSS 0.70
Apache HTTP Server < 2.4.46 - NULL Pointer Dereference
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service
CWE-476 Jun 10, 2021
CVE-2014-8741 9.8 CRITICAL 2 PoCs Analysis EPSS 0.70
Lexmark MarkVision Enterprise <2.1 - Path Traversal
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors.
CWE-22 Jan 27, 2020
CVE-2017-2370 7.8 HIGH 5 PoCs Analysis EPSS 0.70
Apple <10.2.1, <10.12.3, <10.1.1, <3.1.3 - RCE/DoS
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (buffer overflow) via a crafted app.
CWE-119 Feb 20, 2017
CVE-2011-3011 2 PoCs Analysis EPSS 0.70
CA Arcserve D2d - Information Disclosure
BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently execute arbitrary commands, via unspecified vectors.
CWE-200 Aug 15, 2011
CVE-2020-27387 8.8 HIGH EXPLOITED 1 PoC Analysis EPSS 0.70
HorizontCMS <1.0.0-beta - Code Injection
An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP code by uploading a PHP payload, and then using the FileManager's rename function to provide the payload (which will receive a random name on the server) with the PHP extension, and finally executing the PHP file via an HTTP GET request to /storage/<php_file_name>. NOTE: the vendor has patched this while leaving the version number at 1.0.0-beta.
CWE-434 Nov 05, 2020
CVE-2023-28769 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.70
Zyxel DX5401-B0 - Buffer Overflow
The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device.
CWE-120 Apr 27, 2023
CVE-2016-6603 9.8 CRITICAL 1 PoC Analysis EPSS 0.70
ZOHO WebNMS Framework 5.2-5.2 SP1 - Auth Bypass
ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.
CWE-20 Jan 23, 2017
CVE-2016-2569 7.5 HIGH 2 PoCs Analysis EPSS 0.70
Squid - Improper Input Validation
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.
CWE-20 Feb 27, 2016
CVE-2017-7442 8.8 HIGH 2 PoCs Analysis EPSS 0.70
Nitro Pro 11.0.3.173 - RCE
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.
CWE-22 Aug 03, 2017
CVE-2023-30256 6.1 MEDIUM 2 PoCs Analysis NUCLEI EPSS 0.70
Webkul Qloapps - XSS
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.
CWE-79 May 11, 2023
CVE-2024-12986 7.3 HIGH 1 PoC Analysis EPSS 0.70
Draytek Vigor300b Firmware < 1.5.1.5 - Command Injection
A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown processing of the file /cgi-bin/mainfunction.cgi/apmcfgupptim of the component Web Management Interface. The manipulation of the argument session leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.
CWE-78 Dec 27, 2024
CVE-2008-2908 2 PoCs Analysis EPSS 0.70
Novell Iprint Client < 4.35 - Memory Corruption
Multiple stack-based buffer overflows in a certain ActiveX control in ienipp.ocx in Novell iPrint Client for Windows before 4.36 allow remote attackers to execute arbitrary code via a long value of the (1) operation, (2) printer-url, or (3) target-frame parameter. NOTE: some of these details are obtained from third party information.
CWE-119 Jun 30, 2008
CVE-2015-9538 6.5 MEDIUM 1 PoC Analysis EPSS 0.70
Imagely Nextgen Gallery < 2.1.15 - Path Traversal
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
CWE-22 Nov 26, 2019
CVE-2011-5124 2 PoCs Analysis EPSS 0.70
Bluecoat Proxyone - Memory Corruption
Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 and ProxyOne, allows remote attackers to execute arbitrary code via a large packet to the synchronization port (16102/tcp).
CWE-119 Aug 26, 2012
CVE-2001-0803 3 PoCs Analysis EPSS 0.70
Open Group Cde Common Desktop Environment - Memory Corruption
Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.
CWE-119 Dec 06, 2001
CVE-2018-4404 8.8 HIGH EXPLOITED 2 PoCs Analysis EPSS 0.70
Safari Proxy Object Type Confusion
In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improved memory handling.
CWE-119 Jan 11, 2019
CVE-2022-36267 9.8 CRITICAL EXPLOITED 2 PoCs Analysis EPSS 0.70
Airspan AirSpot 5410 <0.3.4.1-4 - Command Injection
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a specific request and interact remotely with the device.
Aug 08, 2022
CVE-2008-6829 2 PoCs Analysis EPSS 0.70
Vicftps - Improper Input Validation
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (forward slash, backward slash, forward slash). NOTE: this might be the same issue as CVE-2008-2031.
CWE-20 Jun 08, 2009
CVE-2023-30854 8.8 HIGH 1 PoC Analysis EPSS 0.70
Wwbn Avideo < 12.4 - OS Command Injection
AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite/cloneClient.json.php` allows attackers to achieve Remote Code Execution. This issue is fixed in version 12.4.
CWE-78 Apr 28, 2023