Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
8,216 exploits
VulnCheck XDB
infoleak
CVE-2019-15107CRITICALunder attackransomware25 Dec 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware21 Dec 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware20 Dec 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
local
CVE-2017-11882HIGHunder attackransomware19 Dec 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-999516 Dec 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-15107CRITICALunder attackransomware15 Dec 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALunder attackransomware12 Dec 2019
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-2725HIGHunder attackransomware12 Dec 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-19356HIGHunder attack12 Dec 2019
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page.
76RISK
open
VulnCheck XDB
initial-access
CVE-2019-11510CRITICALunder attackransomware07 Dec 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware07 Dec 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALunder attack01 Dec 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
VulnCheck XDB
client-side
CVE-2007-003829 Nov 2019
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack26 Nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack26 Nov 2019
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack24 Nov 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware24 Nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2011-319224 Nov 2019
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISK
open
VulnCheck XDB
initial-access
CVE-2017-17562HIGHunder attack23 Nov 2019
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open
VulnCheck XDB
client-side
CVE-2019-5825MEDIUMunder attack23 Nov 2019
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi
90RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack22 Nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware22 Nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALunder attackransomware21 Nov 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-5418HIGHunder attack19 Nov 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-261819 Nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
35RISK
open
VulnCheck XDB
initial-access
CVE-2018-289419 Nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Su
50RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware19 Nov 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-11882HIGHunder attackransomware19 Nov 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
local
CVE-2019-1405HIGHunder attackransomware13 Nov 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISK
open
VulnCheck XDB
local
CVE-2019-1322HIGHunder attackransomware13 Nov 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RISK
open
previouspage 249 / 274next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.