Critical Vulnerabilities with Public Exploits
Updated 40m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,103 results
Clear all
CVE-2019-11469
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.05
Zoho ManageEngine Apps Mgr <15 - SQL Injection
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.
CWE-89
Apr 23, 2019
CVE-2019-11223
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.44
Supportcandy < 2.0.0 - Unrestricted File Upload
An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
CWE-434
Apr 18, 2019
CVE-2019-11448
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.16
Zoho ManageEngine Applications Manager <14.0 - Privilege Escalation
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file.
CWE-89
Apr 22, 2019
CVE-2019-11076
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.17
Cribl - Command Injection
Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request.
CWE-77
Apr 23, 2019
CVE-2019-25628
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Download Accelerator Plus DAP 10.0.6.0 SEH Buffer Overflow
Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting malicious URLs. Attackers can create specially crafted URLs with overflowing buffer data that overwrites SEH pointers and executes embedded shellcode when imported through the application's web page import functionality.
CWE-787
Mar 24, 2026
CVE-2019-25444
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.00
Fiverr Clone Script 1.2.2 - SQL Injection
Fiverr Clone Script 1.2.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parameter. Attackers can supply malicious SQL syntax in the page parameter to extract sensitive database information or modify database contents.
CWE-89
Feb 20, 2026
CVE-2019-8385
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Thomsonreuters Concourse Matter Room < 2.13.0098 - Path Traversal
An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and local file inclusion vulnerability in the ThomsonReuters.Desktop.Service.exe and ThomsonReuters.Desktop.exe allows a remote attacker to list or enumerate sensitive contents of files via a \.. to port 6677. Additionally, this could allow for privilege escalation by dumping the affected machine's SAM and SYSTEM database files, as well as remote code execution.
CWE-22
Jun 05, 2019
CVE-2019-6440
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Zemana AntiMalware <3.0.658 Beta - Info Disclosure
Zemana AntiMalware before 3.0.658 Beta mishandles update logic.
CWE-19
Jan 16, 2019
CVE-2019-9653
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.69
NUUO Network Video Recorder <3.3.x - RCE
NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php.
CWE-78
May 31, 2019
CVE-2019-25646
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Tabs Mail Carrier 2.5.1 Buffer Overflow via MAIL FROM
Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote attackers to execute arbitrary code by sending a crafted MAIL FROM parameter. Attackers can connect to the SMTP service on port 25 and send a malicious MAIL FROM command with an oversized buffer to overwrite the EIP register and execute a bind shell payload.
CWE-787
Mar 24, 2026
CVE-2019-25687
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Pegasus CMS 1.0 Remote Code Execution via extra_fields.php
Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can send POST requests to the submit.php endpoint with malicious PHP code in the action parameter to achieve code execution and obtain an interactive shell.
CWE-22
Apr 05, 2026
CVE-2019-9618
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.86
WordPress Media Player 1.0 - Local File Inclusion
The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter.
CWE-22
May 13, 2019
CVE-2019-9623
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.17
Feng Office <3.7.0.5 - RCE
Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.
CWE-434
Mar 07, 2019
CVE-2019-8375
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.19
Webkitgtk < 2.23.90 - Memory Corruption
The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).
CWE-119
Feb 24, 2019
CVE-2019-25568
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Memu Play 6.0.7 Privilege Escalation via Insecure File Permissions
Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuService.exe executable. Attackers can rename and overwrite MemuService.exe in the installation directory with a malicious executable, which executes with system-level privileges when the service restarts after a computer reboot.
CWE-306
Mar 21, 2026
CVE-2019-8923
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Apachefriends Xampp < 5.6.8 - SQL Injection
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.
CWE-89
May 14, 2019
CVE-2019-8387
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
EPSS 0.67
MASTER IPCAMERA01 <3.3.4.2103 - RCE
MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.
May 08, 2019
CVE-2019-11393
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
M/Monit <3.7.3 - Privilege Escalation
An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the admin parameter.
CWE-640
Apr 22, 2019
CVE-2019-6714
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.17
Blogengine.net < 3.3.6.0 - Path Traversal
An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially untrusted location on the local filesystem. This is especially dangerous if an authenticated user uploads a PostView.ascx file using the file manager utility, which is currently allowed. This results in remote code execution for an authenticated user.
CWE-22
Mar 21, 2019
CVE-2019-6543
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.32
Aveva Indusoft Web Studio - Missing Authentication
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine.
CWE-306
Feb 13, 2019