Critical Vulnerabilities with Public Exploits

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,482 CVEs tracked 53,635 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,335 vendors 43,883 researchers
4,103 results Clear all
CVE-2019-14931 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.61
Mitsubishielectric Smartrtu Firmware < 2.02 - OS Command Injection
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell. Functionality in mobile.php provides users with the ability to ping sites or IP addresses via Mobile Connection Test. When the Mobile Connection Test is submitted, action.php is called to execute the test. An attacker can use a shell command separator (;) in the host variable to execute operating system commands upon submitting the test data.
CWE-78 Oct 28, 2019
CVE-2019-15106 9.8 CRITICAL 1 PoC Analysis EPSS 0.37
Zohocorp Manageengine Opmanager < 12.4.034 - Missing Authentication
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For example, if the username is admin, the password is admin@opm.
CWE-306 Aug 16, 2019
CVE-2019-14537 9.8 CRITICAL 1 PoC Analysis EPSS 0.15
YOURLS <1.7.3 - Auth Bypass
YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.
CWE-843 Aug 07, 2019
CVE-2019-13143 9.8 CRITICAL 1 PoC Analysis EPSS 0.04
Shenzhen Dragon Brothers Fb50 Firmware - Improper Input Validation
An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind the existing owner of the lock, and bind themselves instead. This leads to complete takeover of the lock. The user ID, name, and MAC address are trivially obtained from APIs found within the Android or iOS application. With only the MAC address of the lock, any attacker can transfer ownership of the lock from the current user, over to the attacker's account. Thus rendering the lock completely inaccessible to the current user.
CWE-20 Aug 06, 2019
CVE-2019-14348 9.8 CRITICAL 1 PoC Analysis EPSS 0.38
BearDev JoomSport <3.3 - SQL Injection
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.
CWE-89 Aug 05, 2019
CVE-2019-8661 9.8 CRITICAL 1 PoC Analysis EPSS 0.05
Apple Mac OS X < 10.14.6 - Use After Free
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.6. A remote attacker may be able to cause arbitrary code execution.
CWE-416 Dec 18, 2019
CVE-2019-7839 9.8 CRITICAL 1 PoC Analysis EPSS 0.46
ColdFusion <Update 3 - Command Injection
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
CWE-77 Jun 12, 2019
CVE-2019-8660 9.8 CRITICAL 1 PoC Analysis EPSS 0.09
Apple Iphone OS < 12.4 - Out-of-Bounds Write
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
CWE-787 Dec 18, 2019
CVE-2019-8647 9.8 CRITICAL 1 PoC Analysis EPSS 0.08
Apple Iphone OS < 12.4 - Use After Free
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.4, tvOS 12.4, watchOS 5.3. A remote attacker may be able to cause arbitrary code execution.
CWE-416 Dec 18, 2019
CVE-2019-14277 9.8 CRITICAL 1 PoC Analysis EPSS 0.13
Axway SecureTransport <5.3-5.5 - Unauthenticated XXE
Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the REST API. This vulnerability can lead to local file disclosure, DoS, or URI invocation attacks (i.e., SSRF with resultant remote code execution). NOTE: The vendor disputes this issues as not being a vulnerability because “All attacks that use external entities are blocked (no external DTD or file inclusions, no SSRF). The impact on confidentiality, integrity and availability is not proved on any version.
CWE-91 Jul 26, 2019
CVE-2019-25459 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Web Ofisi Emlak V2 - SQL Injection
Web Ofisi Emlak V2 contains multiple SQL injection vulnerabilities in the endpoint that allow unauthenticated attackers to manipulate database queries through GET parameters. Attackers can inject SQL code into parameters like emlak_durumu, emlak_tipi, il, ilce, kelime, and semt to extract sensitive database information or perform time-based blind SQL injection attacks.
CWE-89 Feb 22, 2026
CVE-2019-25458 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Web Ofisi Firma Rehberi v1 - SQL Injection
Web Ofisi Firma Rehberi v1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters. Attackers can send requests to with malicious payloads in the 'il', 'kat', or 'kelime' parameters to extract sensitive database information or perform time-based blind SQL injection attacks.
CWE-89 Feb 22, 2026
CVE-2019-25456 9.1 CRITICAL 1 PoC Analysis EPSS 0.00
Web Ofisi Emlak v2 - SQL Injection
Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'ara' GET parameter. Attackers can send requests to with time-based SQL injection payloads to extract sensitive database information or cause denial of service.
CWE-89 Feb 22, 2026
CVE-2019-13577 9.8 CRITICAL 2 PoCs Analysis EPSS 0.41
MAPLE WBT SNMP Admin <2.0.195.15 - Buffer Overflow
SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string to the CE Remote feature listening on Port 987.
CWE-787 Jul 17, 2019
CVE-2019-13597 9.8 CRITICAL 1 PoC Analysis EPSS 0.50
Sahi Pro 8.0.0 - Command Injection
_s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts via Sahi Launcher. Also, one can create a new script with an editor. It is possible to execute commands on the server using the _execute() function.
CWE-78 Jul 14, 2019
CVE-2019-13027 9.8 CRITICAL 1 PoC Analysis EPSS 0.06
Realization Concerto Critical Chain Planner - SQL Injection
Realization Concerto Critical Chain Planner (aka CCPM) 5.10.8071 has SQL Injection in at least in the taskupdt/taskdetails.aspx webpage via the projectname parameter.
CWE-89 Jul 12, 2019
CVE-2019-0785 9.8 CRITICAL 1 PoC Analysis EPSS 0.52
Windows Server DHCP - Memory Corruption
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
CWE-787 Jul 15, 2019
CVE-2019-12594 9.8 CRITICAL 1 PoC Analysis EPSS 0.28
DOSBox 0.74-2 - DoS
DOSBox 0.74-2 has Incorrect Access Control.
Jul 02, 2019
CVE-2019-25241 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
FaceSentry Access Control System <6.4.8 - Privilege Escalation
FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.
CWE-798 Dec 24, 2025
CVE-2019-0285 9.8 CRITICAL 1 PoC Analysis EPSS 0.07
SAP Crystal Reports - Cleartext Storage
The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by the attacker.
CWE-312 Apr 10, 2019