Critical Vulnerabilities with Public Exploits
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,103 results
Clear all
CVE-2019-25249
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
devolo dLAN 500 AV Wireless+ <3.1.0-1 - Auth Bypass
devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration parameters.
CWE-266
Dec 24, 2025
CVE-2019-6716
9.4
CRITICAL
1 PoC
Analysis
EPSS 0.03
Logonbox Nervepoint Access Manager - IDOR
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Active Directory usernames and group names, and alter back-end server jobs (backup and synchronization jobs), which could allow for the possibility of a Denial of Service attack via a modified jobId parameter in a runJob.html GET request.
CWE-639
Mar 21, 2019
CVE-2019-6441
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.50
Coship Rt3050 Firmware - Authentication Bypass
An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation for the current password and doesn't require any type of authentication. By making a POST request to the apply.cgi file of the router, the attacker can change the admin username and password of the router.
CWE-287
Mar 21, 2019
CVE-2019-6444
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.13
Ntpsec < 1.1.3 - Out-of-Bounds Read
An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read because attacker-controlled data is dereferenced by ntohl() in ntpd.
CWE-125
Jan 16, 2019
CVE-2019-6443
9.1
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.44
Ntpsec < 1.1.3 - Out-of-Bounds Read
An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read in read_sysvars in ntp_control.c in ntpd.
CWE-125
Jan 16, 2019
CVE-2019-5722
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.05
Portier - SQL Injection
An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handling, it has various SQL injections, including on the login form, and on the search form for a key ring number.
CWE-89
Mar 21, 2019
CVE-2019-5893
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.09
Nelson-it Open Source Erp - SQL Injection
Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter.
CWE-89
Jan 10, 2019
CVE-2019-25709
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
CF Image Hosting Script 1.6.5 Unauthorized Database Access
CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter.
CWE-552
Apr 12, 2026
CVE-2019-8982
9.6
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.86
Wavemaker Wavemarker Studio - SSRF
com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.
CWE-918
Feb 21, 2019
CVE-2018-7600
9.8
CRITICAL
KEV
RANSOMWARE
64 PoCs
Analysis
NUCLEI
EPSS 0.94
Drupal Drupalgeddon 2 Forms API Property Injection
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
CWE-20
Mar 29, 2018
CVE-2018-8733
9.8
CRITICAL
4 PoCs
Analysis
EPSS 0.77
Nagios XI <5.4.13 - Auth Bypass
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.
CWE-89
Apr 18, 2018
CVE-2018-6328
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.71
Kaseya Unitrends Backup < 10.1 - Authentication Bypass
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.
CWE-287
Mar 14, 2018
CVE-2018-12465
9.1
CRITICAL
2 PoCs
Analysis
EPSS 0.82
Micro Focus SMG <471 - Command Injection
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server. This can be exploited in conjunction with CVE-2018-12464 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that used GWAVA product name (i.e. GWAVA 6.5).
CWE-78
Jun 29, 2018
CVE-2018-10662
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.88
Axis IP Cameras - Info Disclosure
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
Jun 26, 2018
CVE-2018-10661
9.8
CRITICAL
EXPLOITED
3 PoCs
Analysis
EPSS 0.89
Axis IP Cameras - Auth Bypass
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
Jun 26, 2018
CVE-2018-16763
9.8
CRITICAL
EXPLOITED
30 PoCs
Analysis
NUCLEI
EPSS 0.94
FUEL CMS 1.4.1 - RCE
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
CWE-74
Sep 09, 2018
CVE-2018-6537
9.8
CRITICAL
4 PoCs
Analysis
EPSS 0.02
Flexense Syncbreeze - Memory Corruption
A buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port 9121.
CWE-119
Feb 02, 2018
CVE-2018-1207
9.8
CRITICAL
EXPLOITED
5 PoCs
Analysis
NUCLEI
EPSS 0.94
Dell Emc Idrac7 < 2.52.52.52 - Code Injection
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentially be able to use CGI variables to execute remote code.
CWE-94
Mar 23, 2018
CVE-2018-18912
9.8
CRITICAL
1 PoC
1 Writeup
Analysis
EPSS 0.03
Sharing-file Easy File Sharing Web Server - Out-of-Bounds Write
An issue was discovered in Easy File Sharing (EFS) Web Server 7.2. A stack-based buffer overflow vulnerability occurs when a malicious POST request has been made to forum.ghp upon creating a new topic in the forums, which allows remote attackers to execute arbitrary code.
CWE-787
May 13, 2019
CVE-2018-10933
9.1
CRITICAL
43 PoCs
Analysis
EPSS 0.78
libssh Authentication Bypass Scanner
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
CWE-287
Oct 17, 2018