Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,526cataloged exploits
36,593CVEs with public exploitation
24,695lab-tested
24,460 exploits
Exploit-DB
Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting
CVE-2019-7671webappsalpha12 Nov 2019
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being ret
23RISK
open
Exploit-DB
eMerge E3 Access Controller 4.6.07 - Remote Code Execution
CVE-2019-7265remotehardware12 Nov 2019
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
28RISK
open
Exploit-DB
CBAS-Web 19.0.0 - Information Disclosure
CVE-2019-10849remotehardware12 Nov 2019
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
23RISK
open
Exploit-DB
Adrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site Scripting
CVE-2018-12234webappsaspx12 Nov 2019
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied
23RISK
open
Exploit-DB
Optergy 2.3.0a - Remote Code Execution (Backdoor)
CVE-2019-7276webappshardware12 Nov 2019
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RISK
open
Exploit-DB
CBAS-Web 19.0.0 - Username Enumeration
CVE-2019-10848webappshardware12 Nov 2019
Computrols CBAS 18.0.0 allows Username Enumeration.
23RISK
open
Exploit-DB
Computrols CBAS-Web 19.0.0 - 'username' Reflected Cross-Site Scripting
CVE-2019-10846webappshardware12 Nov 2019
Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and passw
23RISK
open
Exploit-DB
Prima Access Control 2.3.35 - Arbitrary File Upload
CVE-2019-9189webappshardware12 Nov 2019
Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when
28RISK
open
Exploit-DB
eMerge E3 1.00-06 - Remote Code Execution
CVE-2019-7256CRITICALunder attackwebappshardware12 Nov 2019
Linear eMerge E3-Series devices allow Command Injections.
100RISK
open
Exploit-DB
CBAS-Web 19.0.0 - Cross-Site Request Forgery (Add Super Admin)
CVE-2019-10847webappshardware12 Nov 2019
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
23RISK
open
Exploit-DB
Optergy 2.3.0a - Remote Code Execution
CVE-2019-7274webappshardware12 Nov 2019
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
28RISK
open
Exploit-DB
Atlassian Confluence 6.15.1 - Directory Traversal
CVE-2019-3398HIGHunder attackwebappsjsp12 Nov 2019
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISK
open
Exploit-DB
eMerge E3 1.00-06 - Unauthenticated Directory Traversal
CVE-2019-7254webappshardware12 Nov 2019
Linear eMerge E3-Series devices allow File Inclusion.
60RISK
open
Exploit-DB
Optergy 2.3.0a - Cross-Site Request Forgery (Add Admin)
CVE-2019-7273webappshardware12 Nov 2019
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
23RISK
open
Exploit-DB
eMerge E3 1.00-06 - Privilege Escalation
CVE-2019-7254webappshardware12 Nov 2019
Linear eMerge E3-Series devices allow File Inclusion.
60RISK
open
Exploit-DB
eMerge E3 1.00-06 - 'layout' Reflected Cross-Site Scripting
CVE-2019-7255webappshardware12 Nov 2019
Linear eMerge E3-Series devices allow XSS.
50RISK
open
Exploit-DB
eMerge50P 5000P 4.6.07 - Remote Code Execution
CVE-2019-7269webappshardware12 Nov 2019
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
35RISK
open
Exploit-DB
FlexAir Access Control 2.3.35 - Authentication Bypass
CVE-2019-7666webappshardware12 Nov 2019
Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash valu
28RISK
open
Exploit-DB
eMerge E3 1.00-06 - Cross-Site Request Forgery
CVE-2019-7262webappshardware12 Nov 2019
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
28RISK
open
Exploit-DB
eMerge E3 1.00-06 - Arbitrary File Upload
CVE-2019-7257webappshardware12 Nov 2019
Linear eMerge E3-Series devices allow Unrestricted File Upload.
35RISK
open
Exploit-DB
Adrenalin Core HCM 5.4.0 - 'prntDDLCntrlName' Reflected Cross-Site Scripting
CVE-2018-12650webappsaspx12 Nov 2019
Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSe
23RISK
open
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8641dosmultiple11 Nov 2019
An out-of-bounds read was addressed with improved input validation.
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed OTF Font (CFF Table)
CVE-2019-8196doswindows11 Nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
CVE-2019-8195doswindows11 Nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISK
open
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8662dosmultiple11 Nov 2019
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RISK
open
Exploit-DB
Jenkins build-metrics plugin 1.3 - 'label' Cross-Site Scripting
CVE-2019-10475webappsjava08 Nov 2019
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RISK
open
Exploit-DBVexDay Proof
Android Janus - APK Signature Bypass (Metasploit)
CVE-2017-13156localandroid08 Nov 2019
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISK
open
Exploit-DBVexDay Proof
rConfig - install Command Execution (Metasploit)
CVE-2019-16662remotelinux08 Nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISK
open
Exploit-DB
Adive Framework 2.0.7 - Privilege Escalation
CVE-2019-14347webappsphp08 Nov 2019
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an ad
23RISK
open
Exploit-DBVexDay Proof
JavaScriptCore - Type Confusion During Bailout when Reconstructing Arguments Objects
CVE-2019-8820dosmultiple05 Nov 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPad
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.