Critical Vulnerabilities with Public Exploits

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,453 CVEs tracked 53,634 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,330 vendors 43,881 researchers
4,103 results Clear all
CVE-2019-25249 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
devolo dLAN 500 AV Wireless+ <3.1.0-1 - Auth Bypass
devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration parameters.
CWE-266 Dec 24, 2025
CVE-2019-6716 9.4 CRITICAL 1 PoC Analysis EPSS 0.03
Logonbox Nervepoint Access Manager - IDOR
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Active Directory usernames and group names, and alter back-end server jobs (backup and synchronization jobs), which could allow for the possibility of a Denial of Service attack via a modified jobId parameter in a runJob.html GET request.
CWE-639 Mar 21, 2019
CVE-2019-6441 9.8 CRITICAL 1 PoC Analysis EPSS 0.50
Coship Rt3050 Firmware - Authentication Bypass
An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation for the current password and doesn't require any type of authentication. By making a POST request to the apply.cgi file of the router, the attacker can change the admin username and password of the router.
CWE-287 Mar 21, 2019
CVE-2019-6444 9.1 CRITICAL 1 PoC Analysis EPSS 0.13
Ntpsec < 1.1.3 - Out-of-Bounds Read
An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read because attacker-controlled data is dereferenced by ntohl() in ntpd.
CWE-125 Jan 16, 2019
CVE-2019-6443 9.1 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.44
Ntpsec < 1.1.3 - Out-of-Bounds Read
An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read in read_sysvars in ntp_control.c in ntpd.
CWE-125 Jan 16, 2019
CVE-2019-5722 9.8 CRITICAL 1 PoC Analysis EPSS 0.05
Portier - SQL Injection
An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handling, it has various SQL injections, including on the login form, and on the search form for a key ring number.
CWE-89 Mar 21, 2019
CVE-2019-5893 9.8 CRITICAL 2 PoCs Analysis EPSS 0.09
Nelson-it Open Source Erp - SQL Injection
Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter.
CWE-89 Jan 10, 2019
CVE-2019-25709 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
CF Image Hosting Script 1.6.5 Unauthorized Database Access
CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter.
CWE-552 Apr 12, 2026
CVE-2019-8982 9.6 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.86
Wavemaker Wavemarker Studio - SSRF
com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.
CWE-918 Feb 21, 2019
CVE-2018-7600 9.8 CRITICAL KEV RANSOMWARE 64 PoCs Analysis NUCLEI EPSS 0.94
Drupal Drupalgeddon 2 Forms API Property Injection
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
CWE-20 Mar 29, 2018
CVE-2018-8733 9.8 CRITICAL 4 PoCs Analysis EPSS 0.77
Nagios XI <5.4.13 - Auth Bypass
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.
CWE-89 Apr 18, 2018
CVE-2018-6328 9.8 CRITICAL 3 PoCs Analysis EPSS 0.71
Kaseya Unitrends Backup < 10.1 - Authentication Bypass
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.
CWE-287 Mar 14, 2018
CVE-2018-12465 9.1 CRITICAL 2 PoCs Analysis EPSS 0.82
Micro Focus SMG <471 - Command Injection
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server. This can be exploited in conjunction with CVE-2018-12464 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that used GWAVA product name (i.e. GWAVA 6.5).
CWE-78 Jun 29, 2018
CVE-2018-10662 9.8 CRITICAL 2 PoCs Analysis EPSS 0.88
Axis IP Cameras - Info Disclosure
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
Jun 26, 2018
CVE-2018-10661 9.8 CRITICAL EXPLOITED 3 PoCs Analysis EPSS 0.89
Axis IP Cameras - Auth Bypass
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
Jun 26, 2018
CVE-2018-16763 9.8 CRITICAL EXPLOITED 30 PoCs Analysis NUCLEI EPSS 0.94
FUEL CMS 1.4.1 - RCE
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
CWE-74 Sep 09, 2018
CVE-2018-6537 9.8 CRITICAL 4 PoCs Analysis EPSS 0.02
Flexense Syncbreeze - Memory Corruption
A buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port 9121.
CWE-119 Feb 02, 2018
CVE-2018-1207 9.8 CRITICAL EXPLOITED 5 PoCs Analysis NUCLEI EPSS 0.94
Dell Emc Idrac7 < 2.52.52.52 - Code Injection
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentially be able to use CGI variables to execute remote code.
CWE-94 Mar 23, 2018
CVE-2018-18912 9.8 CRITICAL 1 PoC 1 Writeup Analysis EPSS 0.03
Sharing-file Easy File Sharing Web Server - Out-of-Bounds Write
An issue was discovered in Easy File Sharing (EFS) Web Server 7.2. A stack-based buffer overflow vulnerability occurs when a malicious POST request has been made to forum.ghp upon creating a new topic in the forums, which allows remote attackers to execute arbitrary code.
CWE-787 May 13, 2019
CVE-2018-10933 9.1 CRITICAL 43 PoCs Analysis EPSS 0.78
libssh Authentication Bypass Scanner
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
CWE-287 Oct 17, 2018