Critical Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,482 CVEs tracked 53,635 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,335 vendors 43,883 researchers
4,103 results Clear all
CVE-2019-7257 10.0 CRITICAL 1 PoC Analysis EPSS 0.37
Linear eMerge E3-Series - Unrestricted File Upload
Linear eMerge E3-Series devices allow Unrestricted File Upload.
CWE-434 Jul 02, 2019
CVE-2019-7269 9.8 CRITICAL 1 PoC Analysis EPSS 0.52
Linear eMerge 50P/5000P - Command Injection
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
CWE-78 Jul 02, 2019
CVE-2019-7265 9.8 CRITICAL 1 PoC Analysis EPSS 0.42
Linear eMerge E3-Series - RCE
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
CWE-798 Jul 02, 2019
CVE-2019-7274 9.8 CRITICAL 1 PoC Analysis EPSS 0.64
Optergy Proton/Enterprise - Code Injection
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
CWE-434 Jul 01, 2019
CVE-2019-7671 9.0 CRITICAL 1 PoC Analysis EPSS 0.13
Prima Systems FlexAir <2.3.38 - RCE
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site.
CWE-79 Jun 05, 2019
CVE-2019-8662 9.8 CRITICAL 2 PoCs Analysis EPSS 0.12
Apple Iphone OS < 12.4 - Insecure Deserialization
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary.
CWE-502 Dec 18, 2019
CVE-2019-8196 9.8 CRITICAL 1 PoC Analysis EPSS 0.30
Adobe Acrobat DC < 15.006.30504 - Memory Corruption
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-119 Oct 17, 2019
CVE-2019-8195 9.8 CRITICAL 1 PoC Analysis EPSS 0.30
Adobe Acrobat DC < 15.006.30504 - Memory Corruption
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-119 Oct 17, 2019
CVE-2019-25235 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Smartwares HOME easy <1.0.9 - Auth Bypass
Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to bypass client-side validation and access sensitive system information.
CWE-639 Dec 24, 2025
CVE-2019-12314 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.92
Deltek Maconomy 2.2.5 - Path Traversal
Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as demonstrated by a cgi-bin/Maconomy/MaconomyWS.macx1.W_MCS/etc/passwd URI.
CWE-22 May 24, 2019
CVE-2019-25298 9.1 CRITICAL 1 PoC Analysis EPSS 0.00
html5_snmp 1.11 - SQL Injection
html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through Router_ID and Router_IP parameters. Attackers can exploit error-based, time-based, and union-based injection techniques to potentially extract or modify database information by sending crafted payloads.
CWE-89 Feb 06, 2026
CVE-2019-25361 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Ayukov NFTP 1.71 - Buffer Overflow
Ayukov NFTP client 1.71 contains a buffer overflow vulnerability in the SYST command handling that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted SYST command with oversized payload to trigger a buffer overflow and execute a bind shell on port 5150.
CWE-121 Feb 18, 2026
CVE-2019-25360 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Aida64 Engineer 6.10.5200 - Buffer Overflow
Aida64 Engineer 6.10.5200 contains a buffer overflow vulnerability in the CSV logging configuration that allows attackers to execute malicious code by crafting a specially designed payload. Attackers can exploit the vulnerability by creating a malformed log file with carefully constructed SEH (Structured Exception Handler) overwrite techniques to achieve remote code execution.
CWE-121 Feb 18, 2026
CVE-2019-0192 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.94
Apache Solr < 5.5.5 - Insecure Deserialization
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.
CWE-502 Mar 07, 2019
CVE-2019-25362 9.8 CRITICAL 2 PoCs Analysis EPSS 0.00
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 - Buffer Overflow
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the license name and license code fields. Attackers can craft a malicious payload of 6000 bytes to trigger a bind shell on port 4444 by exploiting a stack-based buffer overflow in the application's input handling.
CWE-787 Feb 18, 2026
CVE-2019-25236 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
iSeeQ Hybrid DVR WH-H4 1.03R - Info Disclosure
iSeeQ Hybrid DVR WH-H4 1.03R contains an unauthenticated vulnerability in the get_jpeg script that allows unauthorized access to live video streams. Attackers can retrieve video snapshots from specific camera channels by sending requests to the /cgi-bin/get_jpeg endpoint without authentication.
CWE-306 Dec 24, 2025
CVE-2019-25364 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
MailCarrier 2.51 - Buffer Overflow
MailCarrier 2.51 contains a buffer overflow vulnerability in the POP3 USER command that allows remote attackers to execute arbitrary code. Attackers can send a crafted oversized buffer to the POP3 service, overwriting memory and potentially gaining remote system access.
CWE-121 Feb 18, 2026
CVE-2019-25365 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
ChaosPro 2.0 - Buffer Overflow
ChaosPro 2.0 contains a buffer overflow vulnerability in the configuration file path handling that allows attackers to execute arbitrary code by overwriting the Structured Exception Handler. Attackers can craft a malicious configuration file with carefully constructed payload to overwrite memory and gain remote code execution on vulnerable Windows XP systems.
CWE-121 Feb 18, 2026
CVE-2019-18418 9.8 CRITICAL 1 PoC Analysis EPSS 0.11
ClonOS WEB control panel 19.09 - RCE
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.
CWE-384 Oct 24, 2019
CVE-2019-12719 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
AUO Sunveillance Monitoring System & ... - Unrestricted File Upload
An issue was discovered in Picture_Manage_mvc.aspx in AUO SunVeillance Monitoring System before v1.1.9e. There is an incorrect access control vulnerability that can allow an unauthenticated user to upload files via a modified authority parameter.
CWE-434 Nov 12, 2019