Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
24,475 exploits
Exploit-DBVexDay Proof
VMware Workstation 15.1.0 - DLL Hijacking
CVE-2019-5526localwindows16 May 2019
VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by t
23RISK
open
Exploit-DB
SEL AcSELerator Architect 2.2.24 - CPU Exhaustion Denial of Service
CVE-2018-10608doswindows16 May 2019
SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects
23RISK
open
Exploit-DB
Microsoft Windows - 'Win32k' Local Privilege Escalation
CVE-2019-0803HIGHunder attackransomwarelocalwindows15 May 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
83RISK
open
Exploit-DB
Schneider Electric U.Motion Builder 1.3.4 - 'track_import_export.php object_id' Unauthenticated Command Injection
CVE-2018-7841CRITICALunder attackwebappsphp14 May 2019
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code
100RISK
open
Exploit-DBVexDay Proof
OpenProject 5.0.0 - 8.3.1 - SQL Injection
CVE-2019-11600webappsphp13 May 2019
A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbi
45RISK
open
Exploit-DB
CyberArk Enterprise Password Vault 10.7 - XML External Entity Injection
CVE-2019-7442webappsmultiple10 May 2019
An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault
35RISK
open
Exploit-DBVexDay Proof
Cortex Unshortenlink Analyzer < 1.1 - Server-Side Request Forgery
CVE-2019-7652webappsmultiple10 May 2019
TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the
23RISK
open
Exploit-DB
Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build - Cross-Site Scripting
CVE-2018-20484webappsphp09 May 2019
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
23RISK
open
Exploit-DB
Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build - Cross-Site Scripting
CVE-2018-20485webappsphp09 May 2019
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
23RISK
open
Exploit-DB
Lotus Domino 8.5.3 - 'EXAMINE' Stack Buffer Overflow DEP/ASLR Bypass (NSA's EMPHASISMINE)
CVE-2017-1274remotewindows08 May 2019
IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated
23RISK
open
Exploit-DBVexDay Proof
Oracle Weblogic Server - 'AsyncResponseService' Deserialization Remote Code Execution (Metasploit)
CVE-2019-2725HIGHunder attackransomwareremotemultiple08 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
Exploit-DBVexDay Proof
PostgreSQL 9.3 - COPY FROM PROGRAM Command Execution (Metasploit)
CVE-2019-9193remotemultiple08 May 2019
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
Exploit-DBVexDay Proof
Google Chrome 72.0.3626.119 - 'FileReader' Use-After-Free (Metasploit)
CVE-2019-5786MEDIUMunder attackremotewindows_x8608 May 2019
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISK
open
Exploit-DB
Prinect Archive System 2015 Release 2.6 - Cross-Site Scripting
CVE-2019-10685webappsmultiple07 May 2019
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
23RISK
open
Exploit-DB
ReadyAPI 2.5.0 / 2.6.0 - Remote Code Execution
CVE-2018-20580webappsmultiple06 May 2019
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co
23RISK
open
Exploit-DB
LG Supersign EZ CMS - Remote Code Execution (Metasploit)
CVE-2018-17173remotehardware06 May 2019
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT
50RISK
open
Exploit-DB
iOS 12.1.3 - 'cfprefsd' Memory Corruption
CVE-2019-7286HIGHunder attackdosios06 May 2019
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave
76RISK
open
Exploit-DB
WordPress Plugin Social Warfare < 3.5.3 - Remote Code Execution
CVE-2019-9978MEDIUMunder attackwebappsphp03 May 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
Exploit-DB
SolarWinds DameWare Mini Remote Control 10.0 - Denial of Service
CVE-2019-9017doswindows03 May 2019
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the m
28RISK
open
Exploit-DB
Zotonic < 0.47.0 mod_admin - Cross-Site Scripting
CVE-2019-11504webappsmultiple03 May 2019
Zotonic before version 0.47 has mod_admin XSS.
23RISK
open
Exploit-DB
Crestron AM/Barco wePresent WiPG/Extron ShareLink/Teq AV IT/SHARP PN-L703WA/Optoma WPS-Pro/Blackbox HD WPS/InFocus LiteShow - Remote Command Injection
CVE-2019-3929CRITICALunder attackwebappshardware03 May 2019
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RISK
open
Exploit-DBVexDay Proof
Ruby On Rails - DoubleTap Development Mode secret_key_base Remote Code Execution (Metasploit)
CVE-2019-5420remotelinux02 May 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
Exploit-DB
CentOS Web Panel 0.9.8.793 (Free) / v0.9.8.753 (Pro) / 0.9.8.807 (Pro) - Domain Field (Add DNS Zone) Cross-Site Scripting
CVE-2019-11429webappslinux01 May 2019
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro)
23RISK
open
Exploit-DBVexDay Proof
Linux - Missing Locking Between ELF coredump code and userfaultfd VMA Modification
CVE-2019-11599doslinux30 Apr 2019
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RISK
open
Exploit-DB
DeviceViewer 3.12.0.1 - 'user' SEH Overflow
CVE-2019-11563localwindows30 Apr 2019
20RISK
open
Exploit-DBVexDay Proof
Domoticz 4.10577 - Unauthenticated Remote Command Execution
CVE-2019-10678webappsmultiple30 Apr 2019
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
28RISK
open
Exploit-DB
Moodle 3.6.3 - 'Install Plugin' Remote Command Execution (Metasploit)
CVE-2019-11631remotephp30 Apr 2019
35RISK
open
Exploit-DB
HumHub 1.3.12 - Cross-Site Scripting
CVE-2019-11564webappsphp30 Apr 2019
A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HT
23RISK
open
Exploit-DB
Intelbras IWR 3000N - Denial of Service (Remote Reboot)
CVE-2019-11415doshardware30 Apr 2019
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. A malformed login request allows remote attackers to cause
28RISK
open
Exploit-DB
Intelbras IWR 3000N 1.5.0 - Cross-Site Request Forgery
CVE-2019-11416webappshardware30 Apr 2019
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstr
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.