Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
24,460 exploits
Exploit-DB
WordPress Plugin WPGraphQL 0.2.3 - Multiple Vulnerabilities
CVE-2019-9879webappsphp21 May 2019
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever
50RISK
open
Exploit-DBVexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 JavaScriptCore - Loop-Invariant Code Motion (LICM) in DFG JIT Leaves Stack Variable Uninitialized
CVE-2019-8623dosmultiple21 May 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS M
23RISK
open
Exploit-DBVexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 XNU - Wild-read due to bad cast in stf_ioctl
CVE-2019-8591dosmultiple21 May 2019
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.
23RISK
open
Exploit-DB
WordPress Plugin WPGraphQL 0.2.3 - Multiple Vulnerabilities
CVE-2019-9880webappsphp21 May 2019
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible,
50RISK
open
Exploit-DB
WordPress Plugin WPGraphQL 0.2.3 - Multiple Vulnerabilities
CVE-2019-9881webappsphp21 May 2019
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on
43RISK
open
Exploit-DB
TP-LINK TL-WR840N v5 00000005 - Cross-Site Scripting
CVE-2019-12195webappshardware21 May 2019
TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking
23RISK
open
Exploit-DBVexDay Proof
Brocade Network Advisor 14.4.1 - Unauthenticated Remote Code Execution
CVE-2018-6443webappsjava21 May 2019
A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log
23RISK
open
Exploit-DB
Huawei eSpace 1.1.11.103 - Image File Format Handling Buffer Overflow
CVE-2014-9417doswindows20 May 2019
The Meeting component in Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (progr
23RISK
open
Exploit-DB
Huawei eSpace 1.1.11.103 - 'ContactsCtrl.dll' / 'eSpaceStatusCtrl.dll' ActiveX Heap Overflow
CVE-2014-9418doswindows20 May 2019
The eSpace Meeting ActiveX control (eSpaceStatusCtrl.dll) in Huawei eSpace Desktop before V200R001C03 allows local users
23RISK
open
Exploit-DBVexDay Proof
GetSimpleCMS - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-11231remotephp20 May 2019
An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows
60RISK
open
Exploit-DB
Huawei eSpace 1.1.11.103 - DLL Hijacking
CVE-2014-9416localwindows20 May 2019
Multiple untrusted search path vulnerabilities in Huawei eSpace Desktop before V200R003C00 allow local users to execute
23RISK
open
Exploit-DB
eLabFTW 1.8.5 - Arbitrary File Upload / Remote Code Execution
CVE-2019-12185webappsphp20 May 2019
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may
28RISK
open
Exploit-DB
Huawei eSpace Meeting 1.1.11.103 - 'cenwpoll.dll' SEH Buffer Overflow (Unicode)
CVE-2014-9415doswindows20 May 2019
Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted QE
23RISK
open
Exploit-DBVexDay Proof
Cisco Prime Infrastructure Health Monitor HA TarArchive - Directory Traversal / Remote Code Execution
CVE-2019-1821HIGHremotelinux17 May 2019
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RISK
open
Exploit-DB
Interspire Email Marketer 6.20 - 'surveys_submit.php' Remote Code Execution
CVE-2018-19550webappsphp17 May 2019
Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit
23RISK
open
Exploit-DB
SEL AcSELerator Architect 2.2.24 - CPU Exhaustion Denial of Service
CVE-2018-10608doswindows16 May 2019
SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects
23RISK
open
Exploit-DBVexDay Proof
VMware Workstation 15.1.0 - DLL Hijacking
CVE-2019-5526localwindows16 May 2019
VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by t
23RISK
open
Exploit-DB
Microsoft Windows - 'Win32k' Local Privilege Escalation
CVE-2019-0803HIGHunder attackransomwarelocalwindows15 May 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
83RISK
open
Exploit-DB
Schneider Electric U.Motion Builder 1.3.4 - 'track_import_export.php object_id' Unauthenticated Command Injection
CVE-2018-7841CRITICALunder attackwebappsphp14 May 2019
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code
100RISK
open
Exploit-DBVexDay Proof
OpenProject 5.0.0 - 8.3.1 - SQL Injection
CVE-2019-11600webappsphp13 May 2019
A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbi
45RISK
open
Exploit-DB
CyberArk Enterprise Password Vault 10.7 - XML External Entity Injection
CVE-2019-7442webappsmultiple10 May 2019
An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault
35RISK
open
Exploit-DBVexDay Proof
Cortex Unshortenlink Analyzer < 1.1 - Server-Side Request Forgery
CVE-2019-7652webappsmultiple10 May 2019
TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the
23RISK
open
Exploit-DB
Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build - Cross-Site Scripting
CVE-2018-20484webappsphp09 May 2019
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
23RISK
open
Exploit-DB
Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build - Cross-Site Scripting
CVE-2018-20485webappsphp09 May 2019
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
23RISK
open
Exploit-DBVexDay Proof
Google Chrome 72.0.3626.119 - 'FileReader' Use-After-Free (Metasploit)
CVE-2019-5786MEDIUMunder attackremotewindows_x8608 May 2019
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISK
open
Exploit-DBVexDay Proof
PostgreSQL 9.3 - COPY FROM PROGRAM Command Execution (Metasploit)
CVE-2019-9193remotemultiple08 May 2019
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
Exploit-DBVexDay Proof
Oracle Weblogic Server - 'AsyncResponseService' Deserialization Remote Code Execution (Metasploit)
CVE-2019-2725HIGHunder attackransomwareremotemultiple08 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
Exploit-DB
Lotus Domino 8.5.3 - 'EXAMINE' Stack Buffer Overflow DEP/ASLR Bypass (NSA's EMPHASISMINE)
CVE-2017-1274remotewindows08 May 2019
IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated
23RISK
open
Exploit-DB
Prinect Archive System 2015 Release 2.6 - Cross-Site Scripting
CVE-2019-10685webappsmultiple07 May 2019
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
23RISK
open
Exploit-DB
ReadyAPI 2.5.0 / 2.6.0 - Remote Code Execution
CVE-2018-20580webappsmultiple06 May 2019
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.