Latest Vulnerabilities with Public Exploits
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
53,708 results
Clear all
CVE-2024-57774
4.8
MEDIUM
SSVC PoC
1 PoC
EPSS 0.00
Jfinaloa < 2025.01.01 - XSS
A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CWE-79
Jan 16, 2025
CVE-2024-57773
4.8
MEDIUM
SSVC PoC
1 PoC
EPSS 0.00
Jfinaloa < 2025.01.01 - XSS
A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CWE-79
Jan 16, 2025
CVE-2024-57772
4.8
MEDIUM
SSVC PoC
1 PoC
EPSS 0.00
Jfinaloa < 2025.01.01 - XSS
A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CWE-79
Jan 16, 2025
CVE-2024-57771
4.8
MEDIUM
SSVC PoC
1 PoC
EPSS 0.00
Jfinaloa < 2025.01.01 - XSS
A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CWE-79
Jan 16, 2025
CVE-2024-57770
8.8
HIGH
SSVC PoC
1 PoC
EPSS 0.00
Jfinaloa < 2025-01-01 - SQL Injection
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.
CWE-89
Jan 16, 2025
CVE-2024-57769
8.8
HIGH
SSVC PoC
1 PoC
EPSS 0.00
Jfinaloa < 2025-01-01 - SQL Injection
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.
CWE-89
Jan 16, 2025
CVE-2024-57768
9.8
CRITICAL
SSVC PoC
1 PoC
EPSS 0.00
Jfinaloa < 2025-01-01 - SQL Injection
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.
CWE-89
Jan 16, 2025
CVE-2024-57767
8.6
HIGH
SSVC PoC
1 PoC
EPSS 0.00
Wangl1989 Mysiteforme < 2025-01-01 - SSRF
MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download.
CWE-918
Jan 15, 2025
CVE-2024-57766
9.1
CRITICAL
1 PoC
EPSS 0.00
Wangl1989 Mysiteforme < 2025-01-01 - Insecure Deserialization
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField.
CWE-502
Jan 15, 2025
CVE-2024-57765
7.5
HIGH
SSVC PoC
1 PoC
EPSS 0.00
Wangl1989 Mysiteforme < 2025-01-01 - SQL Injection
MSFM before 2025.01.01 was discovered to contain a SQL injection vulnerability via the s_name parameter at table/list.
CWE-89
Jan 15, 2025
CVE-2024-57764
9.1
CRITICAL
SSVC PoC
1 PoC
EPSS 0.00
Wangl1989 Mysiteforme < 2025-01-01 - Insecure Deserialization
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/add.
CWE-502
Jan 15, 2025
CVE-2024-57763
9.1
CRITICAL
SSVC PoC
1 PoC
EPSS 0.00
Wangl1989 Mysiteforme < 2025-01-01 - Insecure Deserialization
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/addField.
CWE-502
Jan 15, 2025
CVE-2024-57762
7.5
HIGH
SSVC PoC
1 PoC
EPSS 0.00
Wangl1989 Mysiteforme < 2025-01-01 - Insecure Deserialization
MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.
CWE-502
Jan 15, 2025
CVE-2024-51229
8.8
HIGH
SSVC PoC
1 PoC
EPSS 0.02
Pb-cms - XSS
Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.
CWE-79
Jan 09, 2025
CVE-2024-55461
9.8
CRITICAL
SSVC PoC
1 PoC
EPSS 0.01
Seacms < 13.0 - Command Injection
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().
CWE-77
Dec 18, 2024
CVE-2024-48236
6.5
MEDIUM
SSVC PoC
1 PoC
EPSS 0.00
Ofcms - Code Injection
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file
CWE-94
Oct 25, 2024
CVE-2024-48235
6.5
MEDIUM
SSVC PoC
1 PoC
EPSS 0.00
Ofcms - Code Injection
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.
CWE-94
Oct 25, 2024
CVE-2024-46535
9.8
CRITICAL
SSVC PoC
1 PoC
EPSS 0.01
Ketr Jepaas - SQL Injection
Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUserMsg.
CWE-89
Oct 14, 2024
CVE-2024-48813
8.8
HIGH
SSVC PoC
1 PoC
EPSS 0.02
taskmatic 1.0 - SQL Injection
SQL injection vulnerability in employee-management-system-php-and-mysql-free-download.html taskmatic 1.0 allows a remote attacker to execute arbitrary code via the admin_id parameter of the /update-employee.php component.
CWE-89
Oct 11, 2024
CVE-2024-9411
3.5
LOW
SSVC PoC
1 PoC
EPSS 0.00
Ofcms - XSS
A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-79
Oct 01, 2024