Latest Vulnerabilities with Public Exploits
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
53,708 results
Clear all
CVE-2024-9048
3.1
LOW
SSVC PoC
2 PoCs
EPSS 0.00
Ruoyi < 4.7.9 - XSS
A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is the function SysUserServiceImpl of the file ruoyi-system/src/main/java/com/ruoyi/system/service/impl/SysUserServiceImpl.java of the component Backend User Import. The manipulation of the argument loginName leads to cross site scripting. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The patch is named 9b68013b2af87b9c809c4637299abd929bc73510. It is recommended to apply a patch to fix this issue.
CWE-79
Sep 21, 2024
CVE-2024-8782
6.3
MEDIUM
SSVC PoC
1 PoC
1 Writeup
EPSS 0.00
JFinalCMS <1.0 - Path Traversal
A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete of the file /admin/template/edit. The manipulation of the argument name leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-22
Sep 13, 2024
CVE-2024-8706
4.3
MEDIUM
SSVC PoC
1 PoC
1 Writeup
EPSS 0.01
JFinalCMS <20240903 - Path Traversal
A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of the component com.cms.util.TemplateUtils. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-22
Sep 12, 2024
CVE-2024-8694
3.8
LOW
SSVC PoC
1 PoC
1 Writeup
EPSS 0.00
JFinalCMS <20240903 - Path Traversal
A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the component com.cms.controller.admin.TemplateController. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-22
Sep 11, 2024
CVE-2024-42991
8.1
HIGH
SSVC PoC
1 PoC
EPSS 0.02
MCMS <5.4.1 - RCE
MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
CWE-434
Sep 03, 2024
CVE-2024-42523
7.2
HIGH
SSVC PoC
1 PoC
EPSS 0.00
publiccms <V4.0.202302.e - Any File Upload
publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData
CWE-434
Aug 23, 2024
CVE-2024-8112
4.3
MEDIUM
1 PoC
EPSS 0.00
thinkgem JeeSite 5.3 - XSS
A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown processing of the file /js/a/login of the component Cookie Handler. The manipulation of the argument skinName leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-79
Aug 23, 2024
CVE-2024-42599
8.8
HIGH
SSVC PoC
1 PoC
Analysis
EPSS 0.00
SeaCMS 13.0 - RCE
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.
CWE-94
Aug 22, 2024
CVE-2024-42598
6.7
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
SeaCMS 13.0 - RCE
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.
CWE-94
Aug 20, 2024
CVE-2024-7733
3.5
LOW
SSVC PoC
1 PoC
EPSS 0.00
Xjd2020 Fastcms < 0.1.5 - XSS
A vulnerability, which was classified as problematic, was found in FastCMS up to 0.1.5. Affected is an unknown function of the component New Article Category Page. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-79
Aug 13, 2024
CVE-2024-7552
6.3
MEDIUM
SSVC PoC
1 PoC
EPSS 0.00
DataGear <5.0.0 - Improper Neutralization
A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file ConversionSqlParamValueMapper.java of the component Data Schema Page. The manipulation leads to improper neutralization of special elements used in an expression language statement. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273697 was assigned to this vulnerability.
CWE-917
Aug 06, 2024
CVE-2024-40560
7.3
HIGH
SSVC PoC
1 PoC
EPSS 0.00
Tmall_demo <v2024.07.03 - SQL Injection
Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.
CWE-89
Jul 15, 2024
CVE-2024-40555
5.3
MEDIUM
1 PoC
EPSS 0.00
Tmall_demo v2024.07.03 - File Upload
Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.
CWE-434
Jul 15, 2024
CVE-2024-40554
7.5
HIGH
SSVC PoC
1 PoC
EPSS 0.00
Tmall_demo v2024.07.03 - Info Disclosure
An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information.
CWE-200
Jul 15, 2024
CVE-2024-40553
4.9
MEDIUM
SSVC PoC
1 PoC
EPSS 0.00
Tmall_demo v2024.07.03 - File Upload
Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.
CWE-434
Jul 15, 2024
CVE-2024-40552
8.8
HIGH
1 PoC
EPSS 0.00
PublicCMS <4.0.202302.e - RCE
PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent.java.
CWE-94
Jul 12, 2024
CVE-2024-40551
8.8
HIGH
SSVC PoC
1 PoC
EPSS 0.00
PublicCMS <4.0.202302.e - RCE
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CWE-434
Jul 12, 2024
CVE-2024-40550
8.8
HIGH
1 PoC
EPSS 0.01
Public CMS <4.0.202302.e - RCE
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CWE-22
Jul 12, 2024
CVE-2024-40549
8.8
HIGH
SSVC PoC
1 PoC
EPSS 0.00
PublicCMS <4.0.202302.e - RCE
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CWE-434
Jul 12, 2024
CVE-2024-40548
8.8
HIGH
SSVC PoC
1 PoC
EPSS 0.00
PublicCMS <4.0.202302.e - RCE
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CWE-434
Jul 12, 2024