Latest Vulnerabilities with Public Exploits

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,876 CVEs tracked 53,708 with exploits 4,860 exploited in wild 1,585 CISA KEV 4,078 Nuclei templates 53,663 vendors 43,954 researchers
53,708 results Clear all
CVE-2024-40547 6.5 MEDIUM SSVC PoC 1 PoC EPSS 0.00
PublicCMS <4.0.202302.e - Code Injection
PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cmsTemplate/replace.
CWE-284 Jul 12, 2024
CVE-2024-40546 8.8 HIGH SSVC PoC 1 PoC EPSS 0.00
PublicCMS <4.0.202302.e - RCE
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CWE-434 Jul 12, 2024
CVE-2024-6681 6.3 MEDIUM SSVC PoC 1 PoC EPSS 0.00
witmy my-springsecurity-plus <2024-07-04 - SQL Injection
A vulnerability, which was classified as critical, has been found in witmy my-springsecurity-plus up to 2024-07-04. Affected by this issue is some unknown functionality of the file /api/dept. The manipulation of the argument params.dataScope leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-271154 is the identifier assigned to this vulnerability.
CWE-89 Jul 11, 2024
CVE-2024-6680 6.3 MEDIUM SSVC PoC 1 PoC EPSS 0.00
my-springsecurity-plus <2024-07-04 - SQL Injection
A vulnerability classified as critical was found in witmy my-springsecurity-plus up to 2024-07-04. Affected by this vulnerability is an unknown functionality of the file /api/dept/build. The manipulation of the argument params.dataScope leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-271153 was assigned to this vulnerability.
CWE-89 Jul 11, 2024
CVE-2024-6679 6.3 MEDIUM SSVC PoC 1 PoC EPSS 0.00
my-springsecurity-plus <2024-07-04 - SQL Injection
A vulnerability classified as critical has been found in witmy my-springsecurity-plus up to 2024-07-04. Affected is an unknown function of the file /api/role. The manipulation of the argument params.dataScope leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-271152.
CWE-89 Jul 11, 2024
CVE-2024-6676 6.3 MEDIUM SSVC PoC 1 PoC EPSS 0.00
witmy my-springsecurity-plus - SQL Injection
A vulnerability has been found in witmy my-springsecurity-plus up to 2024-07-03 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /api/user. The manipulation of the argument params.dataScope leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The associated identifier of this vulnerability is VDB-271111.
CWE-89 Jul 11, 2024
CVE-2024-6539 3.5 LOW SSVC PoC 1 PoC EPSS 0.00
heyewei SpringBootCMS <2024-05-28 - XSS
A vulnerability classified as problematic has been found in heyewei SpringBootCMS up to 2024-05-28. Affected is an unknown function of the file /guestbook of the component Guestbook Handler. The manipulation of the argument Content leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-270450 is the identifier assigned to this vulnerability.
CWE-79 Jul 07, 2024
CVE-2024-6511 3.5 LOW SSVC PoC 1 PoC EPSS 0.01
y_project RuoYi <4.7.9 - XSS
A vulnerability classified as problematic was found in y_project RuoYi up to 4.7.9. Affected by this vulnerability is the function isJsonRequest of the component Content-Type Handler. The manipulation of the argument HttpHeaders.CONTENT_TYPE leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-270343.
CWE-79 Jul 04, 2024
CVE-2024-6266 6.3 MEDIUM SSVC PoC 1 PoC EPSS 0.00
Pear Admin Boot <2.0.2 - SQL Injection
A vulnerability classified as critical has been found in Pear Admin Boot up to 2.0.2. Affected is an unknown function of the file /system/dictData/loadDictItem. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-269478 is the identifier assigned to this vulnerability.
CWE-89 Jun 23, 2024
CVE-2024-6241 6.3 MEDIUM SSVC PoC 2 PoCs EPSS 0.00
Pear Admin Boot <2.0.2 - SQL Injection
A vulnerability was found in Pear Admin Boot up to 2.0.2 and classified as critical. This issue affects the function getDictItems of the file /system/dictData/getDictItems/. The manipulation with the input ,user(),1,1 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269375.
CWE-89 Jun 21, 2024
CVE-2024-5829 3.5 LOW 1 PoC EPSS 0.00
smallweigit Avue <3.4.4 - XSS
A vulnerability classified as problematic was found in smallweigit Avue up to 3.4.4. Affected by this vulnerability is an unknown functionality of the component avueUeditor. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-267895. NOTE: The code maintainer explains, that "rich text is no longer maintained".
CWE-79 Jun 11, 2024
CVE-2024-5766 2.4 LOW 1 PoC EPSS 0.00
Likeshop < 2.5.7 - XSS
A vulnerability was found in Likeshop up to 2.5.7 and classified as problematic. This issue affects some unknown processing of the file /admin of the component Merchandise Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-267449 was assigned to this vulnerability.
CWE-79 Jun 08, 2024
CVE-2024-5383 3.5 LOW 1 PoC EPSS 0.00
lakernote EasyAdmin <20240324 - XSS
A vulnerability classified as problematic has been found in lakernote EasyAdmin up to 20240324. This affects an unknown part of the file /sys/file/upload. The manipulation of the argument file leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The identifier of the patch is 9c8a836ace17a93c45e5ad52a2340788b7795030. It is recommended to apply a patch to fix this issue. The identifier VDB-266301 was assigned to this vulnerability.
CWE-79 May 26, 2024
CVE-2024-5380 3.5 LOW SSVC PoC 1 PoC EPSS 0.00
jsy-1 short-url 1.0.0 - XSS
A vulnerability classified as problematic has been found in jsy-1 short-url 1.0.0. Affected is an unknown function of the file admin.php. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.0.0 is able to address this issue. The name of the patch is 35c790897d6979392bc6f60707fc32da13a98b63. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-266292.
CWE-79 May 26, 2024
CVE-2024-5379 3.5 LOW 1 PoC EPSS 0.01
JFinalCMS <20240111 - XSS
A vulnerability was found in JFinalCMS up to 20240111. It has been rated as problematic. This issue affects some unknown processing of the file /admin/template. The manipulation of the argument directory leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266291.
CWE-79 May 26, 2024
CVE-2024-5310 2.4 LOW SSVC PoC 1 PoC EPSS 0.01
JFinalCMS <20221020 - XSS
A vulnerability classified as problematic has been found in JFinalCMS up to 20221020. This affects an unknown part of the file /admin/content. The manipulation of the argument Title leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266121 was assigned to this vulnerability.
CWE-79 May 24, 2024
CVE-2024-5279 3.5 LOW SSVC PoC 1 PoC EPSS 0.00
Qiwen Netdisk <1.4.0 - XSS
A vulnerability was found in Qiwen Netdisk up to 1.4.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component File Rename Handler. The manipulation with the input <img src="" onerror="alert(document.cookie)"> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266083.
CWE-79 May 23, 2024
CVE-2024-43115 8.8 HIGH 1 PoC Analysis EPSS 0.00
Apache DolphinScheduler <3.2.2 - RCE
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.
CWE-20 Sep 03, 2025
CVE-2024-31866 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Apache Zeppelin <0.11.1 - RCE
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.
CWE-116 Apr 09, 2024
CVE-2024-2961 7.3 HIGH EXPLOITED SSVC PoC 16 PoCs Analysis NUCLEI EPSS 0.92
GNU C Library <2.39 - Buffer Overflow
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
CWE-787 Apr 17, 2024