Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
3,477 exploits
Metasploit300
WordPress Google Maps Plugin SQL Injection
CVE-2019-1069202 Apr 2019
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize
40RISK
open
Metasploit600
AIS logistics ESEL-Server Unauth SQL Injection RCE
CVE-2019-1012327 Mar 2019
SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app)
50RISK
open
Metasploit600
AwindInc SNMP Service Command Injection
CVE-2017-1670927 Mar 2019
Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote
60RISK
open
Metasploit300
CMS Made Simple Authenticated RCE via object injection
CVE-2019-905526 Mar 2019
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php an
23RISK
open
Metasploit600
Atlassian Confluence Widget Connector Macro Velocity Template Injection
CVE-2019-3396CRITICALunder attackransomware25 Mar 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
Metasploit600
Horde Form File Upload Vulnerability
CVE-2019-985824 Mar 2019
Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulner
23RISK
open
Metasploit0
Chrome 72.0.3626.119 FileReader UaF exploit for Windows 7 x86
CVE-2019-5786MEDIUMunder attack21 Mar 2019
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISK
open
Metasploit600
PostgreSQL COPY FROM PROGRAM Command Execution
CVE-2019-919320 Mar 2019
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
Metasploit300
IBM BigFix Relay Server Sites and Package Enum
CVE-2019-4061MEDIUM18 Mar 2019
IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the upd
33RISK
open
Metasploit600
Zimbra Collaboration Autodiscover Servlet XXE and ProxyServlet SSRF
CVE-2019-9670CRITICALunder attack13 Mar 2019
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open
Metasploit600
Ruby On Rails DoubleTap Development Mode secret_key_base Vulnerability
CVE-2019-542013 Mar 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
Metasploit600
Zimbra Collaboration Autodiscover Servlet XXE and ProxyServlet SSRF
CVE-2019-9621HIGHunder attack13 Mar 2019
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RISK
open
Metasploit300
Microsoft Windows NtUserMNDragOver Local Privilege Elevation
CVE-2019-0808HIGHunder attack12 Mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
Metasploit300
CMS Made Simple (CMSMS) Showtime2 File Upload RCE
CVE-2019-969211 Mar 2019
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RISK
open
Metasploit300
Pimcore Unserialize RCE
CVE-2019-1086711 Mar 2019
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/c
50RISK
open
Metasploit0
Google Chrome 72 and 73 Array.map exploit
CVE-2019-5825MEDIUMunder attack07 Mar 2019
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi
90RISK
open
Metasploit400
Cisco RV110W/RV130(W)/RV215W Routers Management Interface Remote Command Execution
CVE-2019-1663CRITICAL27 Feb 2019
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISK
open
Metasploit600
elFinder PHP Connector exiftran Command Injection
CVE-2019-919426 Feb 2019
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open
Metasploit300
Drupal RESTful Web Services unserialize() RCE
CVE-2019-6340HIGHunder attack20 Feb 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
Metasploit600
WordPress Crop-image Shell Upload
CVE-2019-894319 Feb 2019
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RISK
open
Metasploit600
WordPress Crop-image Shell Upload
CVE-2019-894219 Feb 2019
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISK
open
Metasploit300
Total.js prior to 3.2.4 Directory Traversal
CVE-2019-890318 Feb 2019
index.js in Total.js Platform before 3.2.3 allows path traversal.
40RISK
open
Metasploit600
RARLAB WinRAR ACE Format Input Validation Remote Code Execution
CVE-2018-20250HIGHunder attackransomware05 Feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
Metasploit300
OpenMRS Java Deserialization RCE
CVE-2018-19276CRITICAL04 Feb 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISK
open
Metasploit600
Schneider Electric Pelco Endura NET55XX Encoder
CVE-2019-681425 Jan 2019
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 wh
50RISK
open
Metasploit300
Cisco RV320/RV326 Configuration Disclosure
CVE-2019-1653HIGHunder attack24 Jan 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
Metasploit300
Microsoft Exchange Privilege Escalation Exploit
CVE-2019-072421 Jan 2019
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of
23RISK
open
Metasploit600
Webmin Upload Authenticated RCE
CVE-2019-962417 Jan 2019
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Dow
43RISK
open
Metasploit600
BMC Patrol Agent Privilege Escalation Cmd Execution
CVE-2018-2073517 Jan 2019
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for l
38RISK
open
Metasploit300
ES File Explorer Open Port
CVE-2019-644716 Jan 2019
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.