Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
8,410 exploits
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware15 Mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware15 Mar 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware11 Mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-19276CRITICAL11 Mar 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISK
open
VulnCheck XDB
initial-access
CVE-2019-019210 Mar 2019
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP
60RISK
open
VulnCheck XDB
initial-access
CVE-2018-1724608 Mar 2019
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-100300006 Mar 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware05 Mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
VulnCheck XDB
local
CVE-2018-8639HIGHunder attackransomware05 Mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware05 Mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware04 Mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware28 Feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-7238CRITICALunder attack24 Feb 2019
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-6340HIGHunder attack23 Feb 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware23 Feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware22 Feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
VulnCheck XDB
local
CVE-2019-573620 Feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-100300015 Feb 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
VulnCheck XDB
local
CVE-2019-573614 Feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
VulnCheck XDB
local
CVE-2019-573613 Feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
VulnCheck XDB
local
CVE-2019-573612 Feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
VulnCheck XDB
initial-access
CVE-2018-6961HIGHunder attack08 Feb 2019
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-1653HIGHunder attack30 Jan 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-999528 Jan 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-1885226 Jan 2019
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-in
35RISK
open
VulnCheck XDB
initial-access
CVE-2018-8581HIGHunder attackransomware24 Jan 2019
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RISK
open
VulnCheck XDB
infoleak
CVE-2019-1653HIGHunder attack24 Jan 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-1652HIGHunder attack24 Jan 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALunder attackransomware20 Jan 2019
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-8174HIGHunder attackransomware20 Jan 2019
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
previouspage 264 / 281next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.