Critical Vulnerabilities with Public Exploits
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,103 results
Clear all
CVE-2019-10709
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.10
Asus Precision Touchpad - Access Control
AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potentially privilege escalation via a crafted DeviceIoControl call.
CWE-264
Sep 04, 2019
CVE-2019-16125
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Jobberbase 2.0 - SQL Injection
In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injection.
CWE-89
Sep 09, 2019
CVE-2019-20447
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Jobberbase - SQL Injection
Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint.
CWE-89
Feb 05, 2020
CVE-2019-9083
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Sqlitemanager - SQL Injection
SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is discontinued.
CWE-89
Mar 21, 2019
CVE-2019-11061
10.0
CRITICAL
1 PoC
Analysis
EPSS 0.12
Asus Hg100 Firmware < 4.00.09 - Missing Authentication
A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10 (Confidentiality, Integrity and Availability impacts). CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
CWE-306
Aug 29, 2019
CVE-2019-9851
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.86
LibreOffice - Code Injection
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from document event script handers, e.g. mouse over. However LibreOffice also has a separate feature where documents can specify that pre-installed scripts can be executed on various global script events such as document-open, etc. In the fixed versions, global script event handlers are validated equivalently to document script event handlers. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.
CWE-20
Aug 15, 2019
CVE-2019-10708
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
S-cms - SQL Injection
S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
CWE-89
Apr 02, 2019
CVE-2019-13101
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.86
Dlink Dir-600m Firmware - Missing Authentication
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.
CWE-306
Aug 08, 2019
CVE-2019-8050
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.31
Adobe Acrobat DC < 15.006.30499 - Out-of-Bounds Write
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-787
Aug 20, 2019
CVE-2019-8049
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.42
Adobe Acrobat DC < 15.006.30499 - Out-of-Bounds Write
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-787
Aug 20, 2019
CVE-2019-8048
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.10
Adobe Acrobat DC < 15.006.30499 - Memory Corruption
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-119
Aug 20, 2019
CVE-2019-8046
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.40
Adobe Acrobat DC < 15.006.30499 - Out-of-Bounds Write
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-787
Aug 20, 2019
CVE-2019-8045
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.43
Adobe Acrobat DC < 15.006.30499 - Memory Corruption
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-119
Aug 20, 2019
CVE-2019-8044
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.37
Adobe Acrobat DC < 15.006.30499 - Double Free
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a double free vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-415
Aug 20, 2019
CVE-2019-8042
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.40
Adobe Acrobat DC < 15.006.30499 - Out-of-Bounds Write
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-787
Aug 20, 2019
CVE-2019-8041
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.40
Adobe Acrobat DC < 15.006.30499 - Out-of-Bounds Write
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-787
Aug 20, 2019
CVE-2019-8024
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.35
Adobe Acrobat DC < 15.006.30499 - Use After Free
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-416
Aug 20, 2019
CVE-2019-8017
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.35
Adobe Acrobat DC < 15.006.30499 - Memory Corruption
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-119
Aug 20, 2019
CVE-2019-8016
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.07
Adobe Acrobat DC < 15.006.30499 - Out-of-Bounds Write
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-787
Aug 20, 2019
CVE-2019-1181
9.8
CRITICAL
1 PoC
EPSS 0.78
Remote Desktop Services - RCE
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP.
The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests.
Aug 14, 2019