Latest Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,880 CVEs tracked 53,712 with exploits 4,860 exploited in wild 1,585 CISA KEV 4,078 Nuclei templates 53,664 vendors 43,956 researchers
53,712 results Clear all
CVE-2024-29510 6.3 MEDIUM EXPLOITED SSVC PoC 2 PoCs Analysis EPSS 0.08
Ghostscript Command Execution via Format String
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.
CWE-693 Jul 03, 2024
CVE-2024-3116 7.4 HIGH SSVC PoC 2 PoCs Analysis EPSS 0.91
pgAdmin <=8.4 - RCE
pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.
CWE-77 Apr 04, 2024
CVE-2024-1800 9.9 CRITICAL SSVC PoC 3 PoCs Analysis EPSS 0.72
Progress Telerik Report Server - Insecure Deserialization
In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.
CWE-502 Mar 20, 2024
CVE-2024-2044 9.9 CRITICAL SSVC PoC 1 PoC Analysis EPSS 0.83
pgAdmin <= 8.3 - Path Traversal
pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server is running on POSIX/Linux, an authenticated attacker can upload pickle objects, deserialize them, and gain code execution.
CWE-31 Mar 07, 2024
CVE-2024-23985 7.5 HIGH SSVC PoC 1 PoC Analysis EPSS 0.33
Ezhometech Ezserver - Denial of Service
EzServer 6.4.017 allows a denial of service (daemon crash) via a long string, such as one for the RNTO command.
Jan 25, 2024
CVE-2024-30085 7.8 HIGH SSVC PoC 3 PoCs Analysis EPSS 0.54
Windows Cloud Files Mini Filter Driver - Privilege Escalation
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CWE-122 Jun 11, 2024
CVE-2024-29824 8.8 HIGH KEV SSVC ACTIVE 3 PoCs Analysis NUCLEI EPSS 0.94
Ivanti EPM RecordGoodApp SQLi RCE
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
CWE-89 May 31, 2024
CVE-2024-30038 7.8 HIGH 1 PoC Analysis EPSS 0.09
Win32k - Privilege Escalation
Win32k Elevation of Privilege Vulnerability
CWE-122 May 14, 2024
CVE-2024-28741 8.8 HIGH SSVC PoC 2 PoCs Analysis EPSS 0.88
NorthStar C2 XSS to Agent RCE
Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.
CWE-79 Apr 06, 2024
CVE-2024-53326 1 PoC Analysis
LINQPad Deserialization
This module exploits a bug in LIQPad up to version 5.48.00. The bug is only exploitable in paid version of software. The core of a bug is cache file containing deserialized data, which attacker can overwrite with malicious payload. The data gets deserialized every time the app restarts.
CVE-2024-55964 9.8 CRITICAL 1 PoC Analysis EPSS 0.67
Appsmith < 1.52 - Code Injection
An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution inside the Appsmith Docker container. The attacker must be able to access Appsmith, login to it, create a datasource, create a query against that datasource, and execute that query.
CWE-94 Mar 26, 2025
CVE-2024-47407 10.0 CRITICAL 1 PoC Analysis EPSS 0.69
mySCADA myPRO Manager Unauthenticated Command Injection (CVE-2024-47407)
A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.
CWE-78 Nov 22, 2024
CVE-2024-11320 9.8 CRITICAL 2 PoCs Analysis NUCLEI EPSS 0.93
Pandora FMS authenticated command injection leading to RCE via LDAP using default DB password
Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4
CWE-77 Nov 21, 2024
CVE-2024-42365 7.4 HIGH SSVC PoC 1 PoC Analysis EPSS 0.32
Asterisk < 18.24.2 - Remote Code Execution
Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2, an AMI user with `write=originate` may change all configuration files in the `/etc/asterisk/` directory. This occurs because they are able to curl remote files and write them to disk, but are also able to append to existing files using the `FILE` function inside the `SET` application. This issue may result in privilege escalation, remote code execution and/or blind server-side request forgery with arbitrary protocol. Asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2 contain a fix for this issue.
CWE-1220 Aug 08, 2024
CVE-2024-4548 9.8 CRITICAL 1 PoC Analysis EPSS 0.45
DIAEnergie SQL Injection (CVE-2024-4548)
An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.
CWE-20 May 06, 2024
CVE-2024-31839 4.8 MEDIUM EXPLOITED SSVC PoC 1 PoC Analysis NUCLEI EPSS 0.85
CHAOS 5.0.1 - XSS
Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via the sendCommandHandler function in the handler.go component.
CWE-79 Apr 12, 2024
CVE-2024-0546 5.3 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.37
EasyFTP 1.7.0 - DoS
A vulnerability, which was classified as problematic, has been found in EasyFTP 1.7.0. This issue affects some unknown processing of the component LIST Command Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250715.
CWE-404 Jan 15, 2024
CVE-2024-46506 10.0 CRITICAL EXPLOITED SSVC PoC 2 PoCs Analysis NUCLEI EPSS 0.91
Unauthenticated RCE in NetAlertX
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.
CWE-306 May 13, 2025
CVE-2024-12971 8.8 HIGH 1 PoC Analysis EPSS 0.83
Pandora FMS authenticated command injection leading to RCE via chromium_path or phantomjs_bin
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6
CWE-77 Mar 17, 2025
CVE-2024-12847 9.8 CRITICAL EXPLOITED SSVC PoC 3 PoCs Analysis EPSS 0.69
Netgear Dgn1000 Firmware < 1.1.00.48 - Missing Authentication
NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been observed to be exploited in the wild since at least 2017 and specifically by the Shadowserver Foundation on 2025-02-06 UTC.
CWE-78 Jan 10, 2025