Critical Vulnerabilities with Public Exploits
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,103 results
Clear all
CVE-2019-8197
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.40
Adobe Acrobat DC < 15.006.30504 - Out-of-Bounds Write
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-787
Oct 17, 2019
CVE-2019-14529
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
OpenEMR <5.0.2 - SQL Injection
OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
CWE-89
Aug 02, 2019
CVE-2019-16692
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.16
phpIPAM 1.4 - SQL Injection
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
CWE-89
Sep 22, 2019
CVE-2019-15846
9.8
CRITICAL
EXPLOITED
RANSOMWARE
1 PoC
Analysis
EPSS 0.64
Exim <4.92.2 - RCE
Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
Sep 06, 2019
CVE-2019-6971
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.12
TP-Link TL-WR1043ND V2 - Auth Bypass
An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packet to the router management web interface, and fully control the router without knowledge of the credentials.
Jun 19, 2019
CVE-2019-17132
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.25
Vbulletin < 5.5.4 - Code Injection
vBulletin through 5.5.4 mishandles custom avatars.
CWE-94
Oct 04, 2019
CVE-2019-4013
9.0
CRITICAL
1 PoC
Analysis
EPSS 0.16
IBM Bigfix Platform < 9.5.11 - Unrestricted File Upload
IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code execution on underlying system with root privileges. IBM X-Force ID: 155887.
CWE-434
Apr 10, 2019
CVE-2019-16941
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.23
NSA Ghidra <9.0.4 - RCE
NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs in Features/BytePatterns/src/main/java/ghidra/bitpatterns/info/FileBitPatternInfoReader.java. An attack could start with an XML document that was originally created by DumpFunctionPatternInfoScript but then directly modified by an attacker (for example, to make a java.lang.Runtime.exec call).
CWE-91
Sep 28, 2019
CVE-2019-25441
9.8
CRITICAL
1 PoC
1 Writeup
Analysis
EPSS 0.03
thesystem 1.0 - Command Injection
thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the run_command endpoint. Attackers can send POST requests with shell commands in the command parameter to execute arbitrary code on the server without authentication.
CWE-78
Feb 20, 2026
CVE-2019-25237
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
V-SOL GPON/EPON OLT Platform v2.03 - Privilege Escalation
V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain administrative access by manipulating the user role parameter. Attackers can send a crafted HTTP POST request to the user management endpoint with 'user_role_mod' set to integer value '1' to elevate their privileges.
CWE-863
Dec 24, 2025
CVE-2019-16894
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
inoERP <4.15 - SQL Injection
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
CWE-502
Sep 26, 2019
CVE-2019-5485
10.0
CRITICAL
1 PoC
Analysis
EPSS 0.50
Gitlabhook - OS Command Injection
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.
CWE-78
Sep 13, 2019
CVE-2019-16399
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Western Digital WD My Book World - Auth Bypass
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_advanced.php?lang=en and login with the default root password welc0me.
CWE-798
Sep 18, 2019
CVE-2019-13144
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
myTinyTodo <1.5 - Code Injection
myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5.
CWE-1236
Jul 05, 2019
CVE-2019-25468
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
NetGain EM Plus 10.1.68 - RCE
NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious parameters to the script_test.jsp endpoint. Attackers can send POST requests with shell commands embedded in the 'content' parameter to execute code and retrieve command output.
CWE-94
Mar 11, 2026
CVE-2019-16119
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.34
10Web Photo Gallery <1.5.35 - SQL Injection
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
CWE-89
Sep 08, 2019
CVE-2019-25240
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Rifatron 5brid DVR - Unauthenticated Access
Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web Viewer module by specifying channel numbers to retrieve sequential video snapshots without authentication.
CWE-306
Dec 24, 2025
CVE-2019-16072
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.89
NETSAS Enigma NMS <65.0.0 - Command Injection
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.
CWE-78
Mar 20, 2020
CVE-2019-25471
9.8
CRITICAL
1 PoC
1 Writeup
Analysis
EPSS 0.01
FileThingie 2.5.7 - Arbitrary File Upload
FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the ft2.php endpoint. Attackers can upload ZIP files containing PHP shells, use the unzip functionality to extract them into accessible directories, and execute arbitrary commands through the extracted PHP files.
CWE-22
Mar 11, 2026
CVE-2019-16124
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
YouPHPTube 7.4 - Info Disclosure
In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.
CWE-862
Sep 09, 2019