High EPSS Vulnerabilities with Public Exploits

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,361 CVEs tracked 53,621 with exploits 4,857 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,840 researchers
3,484 results Clear all
CVE-2025-52367 5.4 MEDIUM 2 PoCs Analysis EPSS 0.70
Pivotx - XSS
Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the subtitle field.
CWE-79 Sep 22, 2025
CVE-2018-16158 9.8 CRITICAL 1 PoC Analysis EPSS 0.70
Eaton Power Xpert Meter 4000 Firmware - Hard-coded Credentials
Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the PubkeyAuthentication option.
CWE-798 Aug 30, 2018
CVE-2023-2877 8.8 HIGH EXPLOITED 1 PoC Analysis EPSS 0.70
Formidable Forms <6.3.1 - RCE
The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.
Jun 27, 2023
CVE-2018-1418 8.8 HIGH 2 PoCs Analysis EPSS 0.70
IBM Security QRadar SIEM <7.4 - Auth Bypass
IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824.
CWE-287 Apr 26, 2018