Critical Vulnerabilities with Public Exploits
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,103 results
Clear all
CVE-2019-19782
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Labf Aceaxe Plus - Buffer Overflow
The FTP client in AceaXe Plus 1.0 allows a buffer overflow via a long EHLO response from an FTP server.
CWE-120
Dec 13, 2019
CVE-2019-15039
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Jetbrains Teamcity - Path Traversal
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.
CWE-22
Oct 01, 2019
CVE-2019-10758
9.9
CRITICAL
KEV
2 PoCs
Analysis
NUCLEI
EPSS 0.94
Mongo-express < 0.54.0 - Code Injection
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.
CWE-94
Dec 24, 2019
CVE-2019-25321
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.01
FTP Navigator 8.03 - RCE
FTP Navigator 8.03 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload that triggers a buffer overflow when pasted into the Custom Command textbox, enabling remote code execution and launching the calculator as proof of concept.
CWE-121
Feb 12, 2026
CVE-2019-25319
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Domain Quester Pro 6.02 - RCE
Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload targeting the 'Domain Name Keywords' input field to trigger an access violation and execute a bind shell on port 9999.
CWE-121
Feb 12, 2026
CVE-2019-17495
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.12
Smartbear Swagger UI < 3.23.11 - CSRF
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method.
CWE-352
Oct 10, 2019
CVE-2019-25327
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Prime95 <29.8 build 6 - RCE
Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the PrimeNet user ID and proxy host fields to trigger a bind shell on port 3110.
CWE-122
Feb 12, 2026
CVE-2019-16451
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.35
Adobe Acrobat and Reader <2019.021.20056 - RCE
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-787
Dec 19, 2019
CVE-2019-20049
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.26
Al-enterprise Omnivista 4760 - Remote Code Execution
An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a directory traversal (which helps to bypass authentication) with an insecure file upload to achieve Remote Code Execution as SYSTEM. The directory traversal is in the __construct() whereas the insecure file upload is in SetSkinImages().
Dec 27, 2019
CVE-2019-17270
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.94
Yachtcontrol < 2019-10-06 - OS Command Injection
Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?command={COMMAND}" page and parameter, where {COMMAND} will be executed and returning the results to the client. Affects Yachtcontrol webservers disclosed via Dutch GPRS/4G mobile IP-ranges. IP addresses vary due to DHCP client leasing of telco's.
CWE-78
Dec 10, 2019
CVE-2019-19634
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.15
verot.net class.upload <2.0.4 - Info Disclosure
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.
CWE-434
Dec 17, 2019
CVE-2019-12272
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.38
OpenWrt LuCI <0.10 - Command Injection
In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.
CWE-78
May 23, 2019
CVE-2019-16702
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.19
Integard Pro 2.2.0.9026 - Buffer Overflow
Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs parameter to the /LoginAdmin URI.
CWE-120
Sep 23, 2019
CVE-2019-25337
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
OwnCloud 8.1.8 - Info Disclosure
OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php endpoint. Attackers can send crafted GET requests to /index.php/core/ajax/share.php with a wildcard search parameter to retrieve comprehensive user information.
CWE-203
Feb 12, 2026
CVE-2019-19033
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Jalios JCMS 10 - Privilege Escalation
Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password.
CWE-798
Nov 21, 2019
CVE-2019-5434
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.89
XML-RPC - Code Injection
An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. Such vulnerability could be used to perform various types of attacks, e.g. exploit serialize-related PHP vulnerabilities or PHP object injection. It is possible, although unconfirmed, that the vulnerability has been used by some attackers in order to gain access to some Revive Adserver instances and deliver malware through them to third party websites. This vulnerability was addressed in version 4.2.0.
CWE-502
May 06, 2019
CVE-2019-12255
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
EPSS 0.80
Wind River VxWorks - Buffer Overflow
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.
CWE-120
Aug 09, 2019
CVE-2019-19012
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.15
Oniguruma <6.9.4_rc2 - Memory Corruption
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.
CWE-190
Nov 17, 2019
CVE-2019-14345
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
TemaTres 3.0 - Privilege Escalation
TemaTres 3.0 allows remote unprivileged users to create an administrator account
Nov 15, 2019
CVE-2019-12890
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.53
Redwoodhq - Missing Authentication
RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automationframework users insert_one call.
CWE-306
Jun 19, 2019