Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
14,080 exploits
GitHub PoC
artofscripting-zz/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS
CVE-2014-0160HIGHunder attack02 Apr 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC2
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Print Archive System v2015 release 2.6
CVE-2019-1068502 Apr 2019
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
23RISK
open
GitHub PoC4
Just a PoC tool to extract password using CVE-2019-1653.
CVE-2019-1653HIGHunder attack01 Apr 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
GitHub PoC3
a demo for Ruby on Rails CVE-2019-5418
CVE-2019-5418HIGHunder attack01 Apr 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC36
CVE-2018-9276 PRTG < 18.2.39 Authenticated Command Injection (Reverse Shell)
CVE-2018-9276HIGHunder attack31 Mar 2019
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
GitHub PoC10
eps漏洞(CVE-2017-0261)漏洞分析
CVE-2017-0261HIGHunder attack31 Mar 2019
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the softwar
93RISK
open
GitHub PoC28
patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428
CVE-2019-1135830 Mar 2019
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISK
open
GitHub PoC23
ASUS SmartHome Exploit for CVE-2019-11061 and CVE-2019-11063
CVE-2019-11061CRITICAL29 Mar 2019
HG100 has a broken access control vulnerability in its Web API Server
48RISK
open
GitHub PoC3
IBM Lotus Domino <= R8 Password Hash Extraction Exploit
CVE-2005-242829 Mar 2019
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hid
60RISK
open
GitHub PoC
cve-2019-5420
CVE-2019-542027 Mar 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
GitHub PoC
cve-2016-9838
CVE-2016-983827 Mar 2019
An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of
28RISK
open
GitHub PoC
stillan00b/CVE-2019-5736
CVE-2019-573627 Mar 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC47
cve-2019-0808-poc
CVE-2019-0808HIGHunder attack25 Mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
GitHub PoC8
CVE-2019-9978 - RCE on a Wordpress plugin: Social Warfare < 3.5.3
CVE-2019-9978MEDIUMunder attack25 Mar 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC67
Array.prototype.slice wrong alias information.
CVE-2019-981025 Mar 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISK
open
GitHub PoC1
CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware24 Mar 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC133
RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)
CVE-2019-5418HIGHunder attack23 Mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC129
CVE-2019-0604
CVE-2019-0604CRITICALunder attackransomware23 Mar 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISK
open
GitHub PoC
CVE-2017-5638 (PoC Exploits)
CVE-2017-5638CRITICALunder attackransomware22 Mar 2019
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
PoC Scan. (cve-2011-3368)
CVE-2011-336822 Mar 2019
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does
60RISK
open
GitHub PoC8
CVE-2019-5420 (Ruby on Rails)
CVE-2019-542021 Mar 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
GitHub PoC254
FileReader Exploit
CVE-2019-5786MEDIUMunder attack20 Mar 2019
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISK
open
GitHub PoC6
CVE-2018-11686 - FlexPaper PHP Publish Service RCE <= 2.3.6
CVE-2018-1168620 Mar 2019
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_c
50RISK
open
GitHub PoC14
GUI版 EXP
CVE-2018-133520 Mar 2019
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
GitHub PoC4
POC for CVE-2017-10271. Since java.lang.ProcessBuilder was the original vector for RCE, there are multiple signature based rules that block this particular payload. Added java.lang.Runtime and will add others in the future. This is for educational purposes only: I take no responsibility for how you use this code.
CVE-2017-10271HIGHunder attackransomware20 Mar 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC
Herramienta para revisar si es que un payload tiene componente malicioso de acuerdo a CVE-2018-20250
CVE-2018-20250HIGHunder attackransomware19 Mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC36
A multi-threaded Golang scanner to identify Ruby endpoints vulnerable to CVE-2019-5418
CVE-2019-5418HIGHunder attack19 Mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC5
File Content Disclosure on Rails Test Case - CVE-2019-5418
CVE-2019-5418HIGHunder attack18 Mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC7
xConsoIe/CVE-2019-0193
CVE-2019-0193HIGHunder attack18 Mar 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISK
open
GitHub PoC6
thinkphp5.*Rce CVE-2018-20062
CVE-2018-20062CRITICALunder attack17 Mar 2019
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISK
open
previouspage 430 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.