Latest Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,876 CVEs tracked 53,708 with exploits 4,860 exploited in wild 1,585 CISA KEV 4,078 Nuclei templates 53,663 vendors 43,954 researchers
53,708 results Clear all
CVE-2024-57774 4.8 MEDIUM SSVC PoC 1 PoC EPSS 0.00
Jfinaloa < 2025.01.01 - XSS
A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CWE-79 Jan 16, 2025
CVE-2024-57773 4.8 MEDIUM SSVC PoC 1 PoC EPSS 0.00
Jfinaloa < 2025.01.01 - XSS
A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CWE-79 Jan 16, 2025
CVE-2024-57772 4.8 MEDIUM SSVC PoC 1 PoC EPSS 0.00
Jfinaloa < 2025.01.01 - XSS
A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CWE-79 Jan 16, 2025
CVE-2024-57771 4.8 MEDIUM SSVC PoC 1 PoC EPSS 0.00
Jfinaloa < 2025.01.01 - XSS
A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CWE-79 Jan 16, 2025
CVE-2024-57770 8.8 HIGH SSVC PoC 1 PoC EPSS 0.00
Jfinaloa < 2025-01-01 - SQL Injection
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.
CWE-89 Jan 16, 2025
CVE-2024-57769 8.8 HIGH SSVC PoC 1 PoC EPSS 0.00
Jfinaloa < 2025-01-01 - SQL Injection
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.
CWE-89 Jan 16, 2025
CVE-2024-57768 9.8 CRITICAL SSVC PoC 1 PoC EPSS 0.00
Jfinaloa < 2025-01-01 - SQL Injection
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.
CWE-89 Jan 16, 2025
CVE-2024-57767 8.6 HIGH SSVC PoC 1 PoC EPSS 0.00
Wangl1989 Mysiteforme < 2025-01-01 - SSRF
MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download.
CWE-918 Jan 15, 2025
CVE-2024-57766 9.1 CRITICAL 1 PoC EPSS 0.00
Wangl1989 Mysiteforme < 2025-01-01 - Insecure Deserialization
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField.
CWE-502 Jan 15, 2025
CVE-2024-57765 7.5 HIGH SSVC PoC 1 PoC EPSS 0.00
Wangl1989 Mysiteforme < 2025-01-01 - SQL Injection
MSFM before 2025.01.01 was discovered to contain a SQL injection vulnerability via the s_name parameter at table/list.
CWE-89 Jan 15, 2025
CVE-2024-57764 9.1 CRITICAL SSVC PoC 1 PoC EPSS 0.00
Wangl1989 Mysiteforme < 2025-01-01 - Insecure Deserialization
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/add.
CWE-502 Jan 15, 2025
CVE-2024-57763 9.1 CRITICAL SSVC PoC 1 PoC EPSS 0.00
Wangl1989 Mysiteforme < 2025-01-01 - Insecure Deserialization
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/addField.
CWE-502 Jan 15, 2025
CVE-2024-57762 7.5 HIGH SSVC PoC 1 PoC EPSS 0.00
Wangl1989 Mysiteforme < 2025-01-01 - Insecure Deserialization
MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.
CWE-502 Jan 15, 2025
CVE-2024-51229 8.8 HIGH SSVC PoC 1 PoC EPSS 0.02
Pb-cms - XSS
Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.
CWE-79 Jan 09, 2025
CVE-2024-55461 9.8 CRITICAL SSVC PoC 1 PoC EPSS 0.01
Seacms < 13.0 - Command Injection
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().
CWE-77 Dec 18, 2024
CVE-2024-48236 6.5 MEDIUM SSVC PoC 1 PoC EPSS 0.00
Ofcms - Code Injection
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file
CWE-94 Oct 25, 2024
CVE-2024-48235 6.5 MEDIUM SSVC PoC 1 PoC EPSS 0.00
Ofcms - Code Injection
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.
CWE-94 Oct 25, 2024
CVE-2024-46535 9.8 CRITICAL SSVC PoC 1 PoC EPSS 0.01
Ketr Jepaas - SQL Injection
Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUserMsg.
CWE-89 Oct 14, 2024
CVE-2024-48813 8.8 HIGH SSVC PoC 1 PoC EPSS 0.02
taskmatic 1.0 - SQL Injection
SQL injection vulnerability in employee-management-system-php-and-mysql-free-download.html taskmatic 1.0 allows a remote attacker to execute arbitrary code via the admin_id parameter of the /update-employee.php component.
CWE-89 Oct 11, 2024
CVE-2024-9411 3.5 LOW SSVC PoC 1 PoC EPSS 0.00
Ofcms - XSS
A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-79 Oct 01, 2024