Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
14,080 exploits
GitHub PoC
likekabin/CVE-2018-20250
CVE-2018-20250HIGHunder attackransomware25 Apr 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC4
A C# module to detect if a Jenkins server is vulnerable to the RCE vulnerability found in CVE-2019-1003000 (chained with CVE-2018-1000861 for pre-auth RCE)
CVE-2018-1000861CRITICALunder attack24 Apr 2019
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISK
open
GitHub PoC4
A C# module to detect if a Jenkins server is vulnerable to the RCE vulnerability found in CVE-2019-1003000 (chained with CVE-2018-1000861 for pre-auth RCE)
CVE-2019-100300024 Apr 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
GitHub PoC
KeyStrOke95/nfsen_1.3.7_CVE-2017-6971
CVE-2017-697124 Apr 2019
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
28RISK
open
GitHub PoC
cve-2017-17485 PoC
CVE-2017-17485CRITICAL21 Apr 2019
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o
60RISK
open
GitHub PoC1
rakesh143/CVE-2019-0808
CVE-2019-0808HIGHunder attack21 Apr 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
GitHub PoC
TateYdq/CVE-2018-9995-ModifiedByGwolfs
CVE-2018-999520 Apr 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC15
Python script to exploit confluence path traversal vulnerability cve-2019-3398
CVE-2019-3398HIGHunder attack20 Apr 2019
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISK
open
GitHub PoC
A python script that tests for an exploitable instance of CVE-2018-1235.
CVE-2018-123517 Apr 2019
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command inje
35RISK
open
GitHub PoC31
CVE-2019-3799 - Spring Cloud Config Server: Directory Traversal < 2.1.2, 2.0.4, 1.4.6
CVE-2019-379917 Apr 2019
Directory Traversal with spring-cloud-config-server
60RISK
open
GitHub PoC81
Apache Tomcat Remote Code Execution on Windows - CGI-BIN
CVE-2019-023216 Apr 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
GitHub PoC190
Apache Tomcat Remote Code Execution on Windows
CVE-2019-023215 Apr 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
GitHub PoC3
CVE-2018-16858 exploit implementation
CVE-2018-16858HIGH14 Apr 2019
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RISK
open
GitHub PoC1
Exploit for the CVE-2019-5736 runc vulnerability
CVE-2019-573613 Apr 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC1
🔍 Explore and test the CVE-2025-49844 (RediShell) vulnerability in Redis with this practical lab environment for secure education and research.
CVE-2025-49844CRITICAL13 Apr 2019
Redis Lua Use-After-Free may lead to remote code execution
85RISK
open
GitHub PoC57
jenkins CVE-2017-1000353 POC
CVE-2017-1000353CRITICALunder attack12 Apr 2019
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RISK
open
GitHub PoC2
likekabin/CVE-2019-0841
CVE-2019-0841HIGHunder attackransomware10 Apr 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RISK
open
GitHub PoC
s1xg0d/CVE-2019-3396
CVE-2019-3396CRITICALunder attackransomware10 Apr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC50
rogue-kdc/CVE-2019-1253
CVE-2019-1253HIGHunder attackransomware10 Apr 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISK
open
GitHub PoC174
CVE-2019-3396 confluence SSTI RCE
CVE-2019-3396CRITICALunder attackransomware10 Apr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC
Confluence Widget Connector RCE - ptquan
CVE-2019-3396CRITICALunder attackransomware10 Apr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC39
Confluence Widget Connector RCE
CVE-2019-3396CRITICALunder attackransomware10 Apr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC145
Confluence 未授权 RCE (CVE-2019-3396) 漏洞
CVE-2019-3396CRITICALunder attackransomware10 Apr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC22
Confluence Widget Connector path traversal (CVE-2019-3396)
CVE-2019-3396CRITICALunder attackransomware09 Apr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC
xiaoshuier/CVE-2019-3396
CVE-2019-3396CRITICALunder attackransomware09 Apr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC
Confluence Widget Connector RCE
CVE-2019-3396CRITICALunder attackransomware09 Apr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC239
PoC code for CVE-2019-0841 Privilege Escalation vulnerability
CVE-2019-0841HIGHunder attackransomware05 Apr 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RISK
open
GitHub PoC4
ManageEngine Service Desk Plus 10.0 Privilaged account Hijacking
CVE-2019-1000804 Apr 2019
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session
28RISK
open
GitHub PoC1
likekabin/CVE-2019-0604_sharepoint_CVE
CVE-2019-0604CRITICALunder attackransomware04 Apr 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISK
open
GitHub PoC
Example and demo setup for Heartbleed vulnerability (CVE-2014-0160). This should be used for testing purposes only!💔
CVE-2014-0160HIGHunder attack03 Apr 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
previouspage 429 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.