Critical Vulnerabilities with Public Exploits
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,103 results
Clear all
CVE-2019-7257
10.0
CRITICAL
1 PoC
Analysis
EPSS 0.37
Linear eMerge E3-Series - Unrestricted File Upload
Linear eMerge E3-Series devices allow Unrestricted File Upload.
CWE-434
Jul 02, 2019
CVE-2019-7269
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.52
Linear eMerge 50P/5000P - Command Injection
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
CWE-78
Jul 02, 2019
CVE-2019-7265
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.42
Linear eMerge E3-Series - RCE
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
CWE-798
Jul 02, 2019
CVE-2019-7274
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.64
Optergy Proton/Enterprise - Code Injection
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
CWE-434
Jul 01, 2019
CVE-2019-7671
9.0
CRITICAL
1 PoC
Analysis
EPSS 0.13
Prima Systems FlexAir <2.3.38 - RCE
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site.
CWE-79
Jun 05, 2019
CVE-2019-8662
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.12
Apple Iphone OS < 12.4 - Insecure Deserialization
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary.
CWE-502
Dec 18, 2019
CVE-2019-8196
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.30
Adobe Acrobat DC < 15.006.30504 - Memory Corruption
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-119
Oct 17, 2019
CVE-2019-8195
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.30
Adobe Acrobat DC < 15.006.30504 - Memory Corruption
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-119
Oct 17, 2019
CVE-2019-25235
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Smartwares HOME easy <1.0.9 - Auth Bypass
Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to bypass client-side validation and access sensitive system information.
CWE-639
Dec 24, 2025
CVE-2019-12314
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.92
Deltek Maconomy 2.2.5 - Path Traversal
Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as demonstrated by a cgi-bin/Maconomy/MaconomyWS.macx1.W_MCS/etc/passwd URI.
CWE-22
May 24, 2019
CVE-2019-25298
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.00
html5_snmp 1.11 - SQL Injection
html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through Router_ID and Router_IP parameters. Attackers can exploit error-based, time-based, and union-based injection techniques to potentially extract or modify database information by sending crafted payloads.
CWE-89
Feb 06, 2026
CVE-2019-25361
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Ayukov NFTP 1.71 - Buffer Overflow
Ayukov NFTP client 1.71 contains a buffer overflow vulnerability in the SYST command handling that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted SYST command with oversized payload to trigger a buffer overflow and execute a bind shell on port 5150.
CWE-121
Feb 18, 2026
CVE-2019-25360
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Aida64 Engineer 6.10.5200 - Buffer Overflow
Aida64 Engineer 6.10.5200 contains a buffer overflow vulnerability in the CSV logging configuration that allows attackers to execute malicious code by crafting a specially designed payload. Attackers can exploit the vulnerability by creating a malformed log file with carefully constructed SEH (Structured Exception Handler) overwrite techniques to achieve remote code execution.
CWE-121
Feb 18, 2026
CVE-2019-0192
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache Solr < 5.5.5 - Insecure Deserialization
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.
CWE-502
Mar 07, 2019
CVE-2019-25362
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.00
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 - Buffer Overflow
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the license name and license code fields. Attackers can craft a malicious payload of 6000 bytes to trigger a bind shell on port 4444 by exploiting a stack-based buffer overflow in the application's input handling.
CWE-787
Feb 18, 2026
CVE-2019-25236
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
iSeeQ Hybrid DVR WH-H4 1.03R - Info Disclosure
iSeeQ Hybrid DVR WH-H4 1.03R contains an unauthenticated vulnerability in the get_jpeg script that allows unauthorized access to live video streams. Attackers can retrieve video snapshots from specific camera channels by sending requests to the /cgi-bin/get_jpeg endpoint without authentication.
CWE-306
Dec 24, 2025
CVE-2019-25364
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
MailCarrier 2.51 - Buffer Overflow
MailCarrier 2.51 contains a buffer overflow vulnerability in the POP3 USER command that allows remote attackers to execute arbitrary code. Attackers can send a crafted oversized buffer to the POP3 service, overwriting memory and potentially gaining remote system access.
CWE-121
Feb 18, 2026
CVE-2019-25365
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
ChaosPro 2.0 - Buffer Overflow
ChaosPro 2.0 contains a buffer overflow vulnerability in the configuration file path handling that allows attackers to execute arbitrary code by overwriting the Structured Exception Handler. Attackers can craft a malicious configuration file with carefully constructed payload to overwrite memory and gain remote code execution on vulnerable Windows XP systems.
CWE-121
Feb 18, 2026
CVE-2019-18418
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
ClonOS WEB control panel 19.09 - RCE
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.
CWE-384
Oct 24, 2019
CVE-2019-12719
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
AUO Sunveillance Monitoring System & ... - Unrestricted File Upload
An issue was discovered in Picture_Manage_mvc.aspx in AUO SunVeillance Monitoring System before v1.1.9e. There is an incorrect access control vulnerability that can allow an unauthenticated user to upload files via a modified authority parameter.
CWE-434
Nov 12, 2019