Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,596cataloged exploits
36,656CVEs with public exploitation
24,695lab-tested
24,460 exploits
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow in CoolType.dll
CVE-2019-8041doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat CoolType (AFDKO) - Call from Uninitialized Memory due to Empty FDArray in Type 1 Fonts
CVE-2019-8017doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow due to Malformed Font Stream
CVE-2019-8049doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in MakeFormat12MergedGlyphList
CVE-2019-1152HIGHdoswindows15 Aug 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in GetGlyphIdx
CVE-2019-1148MEDIUMdoswindows15 Aug 2019
Microsoft Graphics Component Information Disclosure Vulnerability
33RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Memory Corruption due to Malformed TTF Font
CVE-2019-8042doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - free() of Uninitialized Pointer due to Malformed JBIG2Globals Stream
CVE-2019-8045doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat CoolType (AFDKO) - Memory Corruption in the Handling of Type 1 Font load/store Operators
CVE-2019-8016doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow While Processing Malformed PDF
CVE-2019-8050doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
35RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in FixSbitSubTables
CVE-2019-1149HIGHdoswindows15 Aug 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in WriteTableFromStructure
CVE-2019-1150HIGHdoswindows15 Aug 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use-After-Free due to Malformed JP2 Stream
CVE-2019-8024doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow due to Malformed JP2 Stream
CVE-2019-8046doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Out-of-Bounds read due to Malformed JP2 Stream
CVE-2019-8043doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Double Free due to Malformed JP2 Stream
CVE-2019-8044doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Static Buffer Overflow due to Malformed Font Stream
CVE-2019-8048doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
35RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in ReadTableIntoStructure
CVE-2019-1150HIGHdoswindows15 Aug 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Returning a Dangling Pointer via MergeFontPackage
CVE-2019-1145HIGHdoswindows15 Aug 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in ReadAllocFormat12CharGlyphMapList
CVE-2019-1151HIGHdoswindows15 Aug 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
Exploit-DBVexDay Proof
NSKeyedUnarchiver - Info Leak in Decoding SGBigUTF8String
CVE-2019-8663dosmultiple15 Aug 2019
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6. A remote attacker
23RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in FixSbitSubTableFormat1
CVE-2019-1153MEDIUMdoswindows15 Aug 2019
Microsoft Graphics Component Information Disclosure Vulnerability
33RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Double Free in MergeFormat12Cmap / MakeFormat12MergedGlyphList
CVE-2019-1144HIGHdoswindows15 Aug 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
Exploit-DB
TortoiseSVN 1.12.1 - Remote Code Execution
CVE-2019-14422webappswindows14 Aug 2019
An issue was discovered in in TortoiseSVN 1.12.1. The Tsvncmd: URI handler allows a customised diff operation on Excel w
28RISK
open
Exploit-DB
D-Link DIR-600M - Authentication Bypass (Metasploit)
CVE-2019-13101webappshardware14 Aug 2019
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without
50RISK
open
Exploit-DB
Mitsubishi Electric smartRTU / INEA ME-RTU - Unauthenticated OS Command Injection Bind Shell
CVE-2019-14931webappsphp12 Aug 2019
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3
35RISK
open
Exploit-DB
UNA 10.0.0 RC1 - 'polyglot.php' Persistent Cross-Site Scripting
CVE-2019-14804webappsphp12 Aug 2019
studio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template
23RISK
open
Exploit-DB
Mitsubishi Electric smartRTU / INEA ME-RTU - Unauthenticated Configuration Download
CVE-2019-14927webappsphp12 Aug 2019
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3
35RISK
open
Exploit-DBVexDay Proof
WebKit - UXSS via XSLT and Nested Document Replacements
CVE-2019-8690dosmultiple12 Aug 2019
A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This i
23RISK
open
Exploit-DB
BSI Advance Hotel Booking System 2.0 - 'booking_details.php Persistent Cross-Site Scripting
CVE-2014-4035webappsphp12 Aug 2019
Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0
23RISK
open
Exploit-DB
VxWorks 6.8 - TCP Urgent Pointer = 0 Integer Underflow
CVE-2019-12255dosvxworks12 Aug 2019
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TC
45RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.