Critical Vulnerabilities with Public Exploits

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,482 CVEs tracked 53,635 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,335 vendors 43,883 researchers
4,103 results Clear all
CVE-2019-10709 9.8 CRITICAL 1 PoC Analysis EPSS 0.10
Asus Precision Touchpad - Access Control
AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potentially privilege escalation via a crafted DeviceIoControl call.
CWE-264 Sep 04, 2019
CVE-2019-16125 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Jobberbase 2.0 - SQL Injection
In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injection.
CWE-89 Sep 09, 2019
CVE-2019-20447 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Jobberbase - SQL Injection
Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint.
CWE-89 Feb 05, 2020
CVE-2019-9083 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Sqlitemanager - SQL Injection
SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is discontinued.
CWE-89 Mar 21, 2019
CVE-2019-11061 10.0 CRITICAL 1 PoC Analysis EPSS 0.12
Asus Hg100 Firmware < 4.00.09 - Missing Authentication
A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10 (Confidentiality, Integrity and Availability impacts). CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
CWE-306 Aug 29, 2019
CVE-2019-9851 9.8 CRITICAL 1 PoC Analysis EPSS 0.86
LibreOffice - Code Injection
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from document event script handers, e.g. mouse over. However LibreOffice also has a separate feature where documents can specify that pre-installed scripts can be executed on various global script events such as document-open, etc. In the fixed versions, global script event handlers are validated equivalently to document script event handlers. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.
CWE-20 Aug 15, 2019
CVE-2019-10708 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
S-cms - SQL Injection
S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
CWE-89 Apr 02, 2019
CVE-2019-13101 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.86
Dlink Dir-600m Firmware - Missing Authentication
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.
CWE-306 Aug 08, 2019
CVE-2019-8050 9.8 CRITICAL 1 PoC Analysis EPSS 0.31
Adobe Acrobat DC < 15.006.30499 - Out-of-Bounds Write
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-787 Aug 20, 2019
CVE-2019-8049 9.8 CRITICAL 1 PoC Analysis EPSS 0.42
Adobe Acrobat DC < 15.006.30499 - Out-of-Bounds Write
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-787 Aug 20, 2019
CVE-2019-8048 9.8 CRITICAL 1 PoC Analysis EPSS 0.10
Adobe Acrobat DC < 15.006.30499 - Memory Corruption
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-119 Aug 20, 2019
CVE-2019-8046 9.8 CRITICAL 1 PoC Analysis EPSS 0.40
Adobe Acrobat DC < 15.006.30499 - Out-of-Bounds Write
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-787 Aug 20, 2019
CVE-2019-8045 9.8 CRITICAL 1 PoC Analysis EPSS 0.43
Adobe Acrobat DC < 15.006.30499 - Memory Corruption
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-119 Aug 20, 2019
CVE-2019-8044 9.8 CRITICAL 1 PoC Analysis EPSS 0.37
Adobe Acrobat DC < 15.006.30499 - Double Free
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a double free vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-415 Aug 20, 2019
CVE-2019-8042 9.8 CRITICAL 1 PoC Analysis EPSS 0.40
Adobe Acrobat DC < 15.006.30499 - Out-of-Bounds Write
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-787 Aug 20, 2019
CVE-2019-8041 9.8 CRITICAL 1 PoC Analysis EPSS 0.40
Adobe Acrobat DC < 15.006.30499 - Out-of-Bounds Write
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-787 Aug 20, 2019
CVE-2019-8024 9.8 CRITICAL 1 PoC Analysis EPSS 0.35
Adobe Acrobat DC < 15.006.30499 - Use After Free
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-416 Aug 20, 2019
CVE-2019-8017 9.8 CRITICAL 1 PoC Analysis EPSS 0.35
Adobe Acrobat DC < 15.006.30499 - Memory Corruption
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-119 Aug 20, 2019
CVE-2019-8016 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
Adobe Acrobat DC < 15.006.30499 - Out-of-Bounds Write
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-787 Aug 20, 2019
CVE-2019-1181 9.8 CRITICAL 1 PoC EPSS 0.78
Remote Desktop Services - RCE
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP. The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests.
Aug 14, 2019