Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
14,080 exploits
GitHub PoC1
gildaaa/CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC13
A Win7 RDP exploit
CVE-2019-0708CRITICALunder attackransomware14 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC47
proof of concept exploit for Microsoft Windows 7 and Server 2008 RDP vulnerability
CVE-2019-0708CRITICALunder attackransomware14 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
peterpeter228/CNTA-2019-0014xCVE-2019-2725
CVE-2019-2725HIGHunder attackransomware14 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC11
CVE-2019-0211-apache & CVE-2019-6977-imagecolormatch
CVE-2019-0211HIGHunder attack12 May 2019
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
83RISK
open
GitHub PoC15
Speculative Store Bypass (CVE-2018-3639) proof of concept for Linux
CVE-2018-3639MEDIUM11 May 2019
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RISK
open
GitHub PoC7
zhusx110/cve-2019-2725
CVE-2019-2725HIGHunder attackransomware10 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC1
Docker runc CVE-2019-5736 exploit Dockerfile. Credits : https://github.com/Frichetten/CVE-2019-5736-PoC.git
CVE-2019-573609 May 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC
sasqwatch/CVE-2017-8570
CVE-2017-8570HIGHunder attack08 May 2019
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISK
open
GitHub PoC6
Wordpress Social Warfare Remote Code Execution (AUTO UPLOAD SHELL)
CVE-2019-9978MEDIUMunder attack06 May 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC1
cve-2019-10678
CVE-2019-1067806 May 2019
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
28RISK
open
GitHub PoC
cve-2019-9978
CVE-2019-9978MEDIUMunder attack06 May 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC79
Zimbra邮件系统漏洞 XXE/RCE/SSRF/Upload GetShell Exploit 1. (CVE-2019-9621 Zimbra<8.8.11 XXE GetShell Exploit)
CVE-2019-9621HIGHunder attack06 May 2019
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RISK
open
GitHub PoC2
leerina/CVE-2019-2725
CVE-2019-2725HIGHunder attackransomware05 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC227
Exploit for CVE-2019-9810 Firefox on Windows 64-bit.
CVE-2019-981005 May 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISK
open
GitHub PoC2
A proof of concept for ReadyAPI 2.5.0/2.6.0 Remote Code Execution Vulnerability.
CVE-2018-2058003 May 2019
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co
23RISK
open
GitHub PoC22
CVE-2019-9978 - (PoC) RCE in Social WarFare Plugin (<=3.5.2)
CVE-2019-9978MEDIUMunder attack03 May 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC1
davidmthomsen/CVE-2019-2725
CVE-2019-2725HIGHunder attackransomware02 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC4
WordPress crop-image exploitation
CVE-2019-894202 May 2019
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISK
open
GitHub PoC21
lasensio/cve-2019-2725
CVE-2019-2725HIGHunder attackransomware01 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC1
PoC command injection example for cve-2018-1002105 based off https://github.com/gravitational/cve-2018-1002105
CVE-2018-1002105CRITICAL30 Apr 2019
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISK
open
GitHub PoC58
Spring Data Commons RCE 远程命令执行漏洞
CVE-2018-1273CRITICALunder attackransomware29 Apr 2019
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISK
open
GitHub PoC
Confluence Widget Connector path traversal (CVE-2019-3396)
CVE-2019-3396CRITICALunder attackransomware28 Apr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC
shawntns/exploit-CVE-2014-6271
CVE-2014-6271CRITICALunder attack27 Apr 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
An intentionally vulnerable (CVE-2017-8046) SrpingData REST appl with Swagger Support for pentesting purposes
CVE-2017-804627 Apr 2019
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISK
open
GitHub PoC114
WebLogic CNVD-C-2019_48814 CVE-2017-10271 Scan By 7kbstorm
CVE-2017-10271HIGHunder attackransomware25 Apr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC1
WebLogic CNVD-C-2019_48814 CVE-2017-10271
CVE-2017-10271HIGHunder attackransomware25 Apr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC105
CVE-2019-2725poc汇总 更新绕过CVE-2017-10271补丁POC
CVE-2017-10271HIGHunder attackransomware25 Apr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC9
The official exploit code for LibreNMS v1.46 Remote Code Execution CVE-2018-20434
CVE-2018-2043425 Apr 2019
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to htm
60RISK
open
GitHub PoC
likekabin/CVE-2018-20250
CVE-2018-20250HIGHunder attackransomware25 Apr 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
previouspage 428 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.