Critical Vulnerabilities with Public Exploits

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,482 CVEs tracked 53,635 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,335 vendors 43,883 researchers
4,103 results Clear all
CVE-2019-15913 9.8 CRITICAL 1 PoC 1 Writeup Analysis EPSS 0.00
Xiaomi Devices - Info Disclosure/DoS
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of service attack, take over smart home devices, and tamper with messages.
CWE-639 Dec 20, 2019
CVE-2019-15911 9.8 CRITICAL 1 PoC 1 Writeup Analysis EPSS 0.01
ASUS - Info Disclosure
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive information, cause the multiple denial of service attacks, take over smart home devices, and tamper with messages.
CWE-319 Dec 20, 2019
CVE-2019-25232 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
NetPCLinker 1.0.0.0 - Buffer Overflow
NetPCLinker 1.0.0.0 contains a buffer overflow vulnerability in the Clients Control Panel DNS/IP field that allows attackers to execute arbitrary shellcode. Attackers can craft a malicious payload in the DNS/IP input to overwrite SEH handlers and execute shellcode when adding a new client.
CWE-120 Jan 30, 2026
CVE-2019-0219 9.8 CRITICAL 1 PoC Analysis EPSS 0.09
Website - XSS
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.
Jan 14, 2020
CVE-2019-17570 9.8 CRITICAL 3 PoCs Analysis EPSS 0.71
Apache Xml-rpc - Insecure Deserialization
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.
CWE-502 Jan 23, 2020
CVE-2019-3025 9.0 CRITICAL 1 PoC Analysis EPSS 0.31
Oracle Food and Beverage Apps <5.7 - RCE
Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications. The supported version that is affected is 5.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality RES 3700. While the vulnerability is in Oracle Hospitality RES 3700, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality RES 3700. CVSS 3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Oct 16, 2019
CVE-2019-17658 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
FortiClient Windows <6.2.2 - Privilege Escalation
An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path.
CWE-428 Mar 12, 2020
CVE-2019-16383 9.4 CRITICAL 1 PoC Analysis EPSS 0.01
Progress MOVEit Transfer <11.1.1 - SQL Injection
MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, or may be able to alter the database via the REST API, aka SQL Injection.
CWE-89 Sep 24, 2019
CVE-2019-13086 9.8 CRITICAL 1 PoC Analysis EPSS 0.51
Cszcms Csz Cms < 1.2.2 - SQL Injection
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.
CWE-89 Jun 30, 2019
CVE-2019-13956 9.8 CRITICAL 1 PoC Analysis EPSS 0.43
Discuz!ML <3.4 - RCE
Discuz!ML 3.2 through 3.4 allows remote attackers to execute arbitrary PHP code via a modified language cookie, as demonstrated by changing 4gH4_0df5_language=en to 4gH4_0df5_language=en'.phpinfo().'; (if the random prefix 4gH4_0df5_ were used).
CWE-94 Jul 18, 2019
CVE-2019-17625 9.0 CRITICAL 1 PoC Analysis EPSS 0.05
Rambox - XSS
There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such as an exec of OS commands within the onerror attribute of an IMG element.
CWE-78 Oct 16, 2019
CVE-2019-12765 9.8 CRITICAL 1 PoC Analysis EPSS 0.31
Joomla! <3.9.7 - Code Injection
An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection.
CWE-1236 Jun 11, 2019
CVE-2019-19905 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Nethack < 3.6.4 - Buffer Overflow
NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared systems that allow users to upload their own configuration files.
CWE-120 Dec 19, 2019
CVE-2019-5096 9.8 CRITICAL 1 PoC Analysis EPSS 0.80
GoAhead <v5.0.1,v4.1.1,v3.6.5 - Code Injection
An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to a use-after-free condition during the processing of this request that can be used to corrupt heap structures that could lead to full code execution. The request can be unauthenticated in the form of GET or POST requests, and does not require the requested resource to exist on the server.
CWE-416 Dec 03, 2019
CVE-2019-14514 9.8 CRITICAL 1 PoC Analysis EPSS 0.11
Microvirt MEmu <7.0.2 - Info Disclosure
An issue was discovered in Microvirt MEmu all versions prior to 7.0.2. A guest Android operating system inside the MEmu emulator contains a /system/bin/systemd binary that is run with root privileges on startup (this is unrelated to Red Hat's systemd init program, and is a closed-source proprietary tool that seems to be developed by Microvirt). This program opens TCP port 21509, presumably to receive installation-related commands from the host OS. Because everything after the installer:uninstall command is concatenated directly into a system() call, it is possible to execute arbitrary commands by supplying shell metacharacters.
CWE-78 Feb 11, 2020
CVE-2019-14314 9.8 CRITICAL 1 PoC Analysis EPSS 0.32
Imagely NextGEN Gallery <3.2.11 - SQL Injection
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.
CWE-89 Aug 27, 2019
CVE-2019-19740 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Octeth Oempro - SQL Injection
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
CWE-89 Dec 12, 2019
CVE-2019-19576 9.8 CRITICAL 2 PoCs Analysis EPSS 0.51
verot.net class.upload <2.0.4 - Info Disclosure
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
CWE-434 Dec 04, 2019
CVE-2019-12489 9.8 CRITICAL 2 PoCs Analysis EPSS 0.11
Fastweb Askey Rtv1907vw Firmware - OS Command Injection
An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_remove service through an HTTP request, it is possible to inject and execute a command between two & characters in the mount parameter.
CWE-78 Nov 26, 2019
CVE-2019-3663 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Mcafee Advanced Threat Defense - Insufficiently Protected Credentials
Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the system. This was originally published with a CVSS rating of High, further investigation has resulted in this being updated to Critical. The root password is common across all instances of ATD prior to 4.8. See the Security bulletin for further details
CWE-522 Nov 14, 2019