Latest Vulnerabilities with Public Exploits

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,876 CVEs tracked 53,708 with exploits 4,860 exploited in wild 1,585 CISA KEV 4,078 Nuclei templates 53,663 vendors 43,954 researchers
53,708 results Clear all
CVE-2024-9048 3.1 LOW SSVC PoC 2 PoCs EPSS 0.00
Ruoyi < 4.7.9 - XSS
A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is the function SysUserServiceImpl of the file ruoyi-system/src/main/java/com/ruoyi/system/service/impl/SysUserServiceImpl.java of the component Backend User Import. The manipulation of the argument loginName leads to cross site scripting. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The patch is named 9b68013b2af87b9c809c4637299abd929bc73510. It is recommended to apply a patch to fix this issue.
CWE-79 Sep 21, 2024
CVE-2024-8782 6.3 MEDIUM SSVC PoC 1 PoC 1 Writeup EPSS 0.00
JFinalCMS <1.0 - Path Traversal
A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete of the file /admin/template/edit. The manipulation of the argument name leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-22 Sep 13, 2024
CVE-2024-8706 4.3 MEDIUM SSVC PoC 1 PoC 1 Writeup EPSS 0.01
JFinalCMS <20240903 - Path Traversal
A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of the component com.cms.util.TemplateUtils. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-22 Sep 12, 2024
CVE-2024-8694 3.8 LOW SSVC PoC 1 PoC 1 Writeup EPSS 0.00
JFinalCMS <20240903 - Path Traversal
A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the component com.cms.controller.admin.TemplateController. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-22 Sep 11, 2024
CVE-2024-42991 8.1 HIGH SSVC PoC 1 PoC EPSS 0.02
MCMS <5.4.1 - RCE
MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
CWE-434 Sep 03, 2024
CVE-2024-42523 7.2 HIGH SSVC PoC 1 PoC EPSS 0.00
publiccms <V4.0.202302.e - Any File Upload
publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData
CWE-434 Aug 23, 2024
CVE-2024-8112 4.3 MEDIUM 1 PoC EPSS 0.00
thinkgem JeeSite 5.3 - XSS
A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown processing of the file /js/a/login of the component Cookie Handler. The manipulation of the argument skinName leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-79 Aug 23, 2024
CVE-2024-42599 8.8 HIGH SSVC PoC 1 PoC Analysis EPSS 0.00
SeaCMS 13.0 - RCE
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.
CWE-94 Aug 22, 2024
CVE-2024-42598 6.7 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.00
SeaCMS 13.0 - RCE
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.
CWE-94 Aug 20, 2024
CVE-2024-7733 3.5 LOW SSVC PoC 1 PoC EPSS 0.00
Xjd2020 Fastcms < 0.1.5 - XSS
A vulnerability, which was classified as problematic, was found in FastCMS up to 0.1.5. Affected is an unknown function of the component New Article Category Page. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-79 Aug 13, 2024
CVE-2024-7552 6.3 MEDIUM SSVC PoC 1 PoC EPSS 0.00
DataGear <5.0.0 - Improper Neutralization
A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file ConversionSqlParamValueMapper.java of the component Data Schema Page. The manipulation leads to improper neutralization of special elements used in an expression language statement. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273697 was assigned to this vulnerability.
CWE-917 Aug 06, 2024
CVE-2024-40560 7.3 HIGH SSVC PoC 1 PoC EPSS 0.00
Tmall_demo <v2024.07.03 - SQL Injection
Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.
CWE-89 Jul 15, 2024
CVE-2024-40555 5.3 MEDIUM 1 PoC EPSS 0.00
Tmall_demo v2024.07.03 - File Upload
Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.
CWE-434 Jul 15, 2024
CVE-2024-40554 7.5 HIGH SSVC PoC 1 PoC EPSS 0.00
Tmall_demo v2024.07.03 - Info Disclosure
An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information.
CWE-200 Jul 15, 2024
CVE-2024-40553 4.9 MEDIUM SSVC PoC 1 PoC EPSS 0.00
Tmall_demo v2024.07.03 - File Upload
Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.
CWE-434 Jul 15, 2024
CVE-2024-40552 8.8 HIGH 1 PoC EPSS 0.00
PublicCMS <4.0.202302.e - RCE
PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent.java.
CWE-94 Jul 12, 2024
CVE-2024-40551 8.8 HIGH SSVC PoC 1 PoC EPSS 0.00
PublicCMS <4.0.202302.e - RCE
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CWE-434 Jul 12, 2024
CVE-2024-40550 8.8 HIGH 1 PoC EPSS 0.01
Public CMS <4.0.202302.e - RCE
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CWE-22 Jul 12, 2024
CVE-2024-40549 8.8 HIGH SSVC PoC 1 PoC EPSS 0.00
PublicCMS <4.0.202302.e - RCE
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CWE-434 Jul 12, 2024
CVE-2024-40548 8.8 HIGH SSVC PoC 1 PoC EPSS 0.00
PublicCMS <4.0.202302.e - RCE
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CWE-434 Jul 12, 2024