Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
24,475 exploits
Exploit-DBVexDay Proof
Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-1653HIGHunder attackremotehardware03 Apr 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
Exploit-DBVexDay Proof
SpiderMonkey - IonMonkey Compiled Code Fails to Update Inferred Property Types (Type Confusion)
CVE-2019-9813dosmultiple03 Apr 2019
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbi
23RISK
open
Exploit-DBVexDay Proof
iOS < 12.2 / macOS < 10.14.4 XNU - pidversion Increment During execve is Unsafe
CVE-2019-8514dosmultiple03 Apr 2019
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS
23RISK
open
Exploit-DBVexDay Proof
WebKit JavaScriptCore - Out-Of-Bounds Access in FTL JIT due to LICM Moving Array Access Before the Bounds Check
CVE-2019-8518dosmultiple03 Apr 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12
28RISK
open
Exploit-DB
LimeSurvey < 3.16 - Remote Code Execution
CVE-2018-17057webappsphp02 Apr 2019
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar://
28RISK
open
Exploit-DB
JioFi 4G M2S 1.0.2 - Cross-Site Request Forgery
CVE-2019-7440webappshardware02 Apr 2019
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_S
23RISK
open
Exploit-DB
CMS Made Simple < 2.2.10 - SQL Injection
CVE-2019-9053webappsphp02 Apr 2019
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
Exploit-DB
WordPress Plugin PayPal Checkout Payment Gateway 1.6.8 - Parameter Tampering
CVE-2019-7441webappsphp02 Apr 2019
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter
23RISK
open
Exploit-DB
i-doit 1.12 - 'qr.php' Cross-Site Scripting
CVE-2019-6965webappsphp28 Mar 2019
An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.
23RISK
open
Exploit-DBVexDay Proof
Oracle Weblogic Server Deserialization RCE - Raw Object (Metasploit)
CVE-2015-4852CRITICALunder attackremotemultiple28 Mar 2019
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISK
open
Exploit-DBVexDay Proof
CMS Made Simple (CMSMS) Showtime2 - File Upload Remote Code Execution (Metasploit)
CVE-2019-9692remotephp28 Mar 2019
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RISK
open
Exploit-DB
Thomson Reuters Concourse & Firm Central < 2.13.0097 - Directory Traversal / Local File Inclusion
CVE-2019-8385webappswindows28 Mar 2019
An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and loca
28RISK
open
Exploit-DB
Fat Free CRM 0.19.0 - HTML Injection
CVE-2019-10226webappsruby28 Mar 2019
HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to th
23RISK
open
Exploit-DB
Microsoft Windows 7/2008 - 'Win32k' Denial of Service (PoC)
CVE-2019-0808HIGHunder attackdoswindows26 Mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
Exploit-DB
Rukovoditel ERP & CRM 2.4.1 - 'path' Cross-Site Scripting
CVE-2019-7400webappsphp26 Mar 2019
Rukovoditel before 2.4.1 allows XSS.
23RISK
open
Exploit-DB
Firefox < 66.0.1 - 'Array.prototype.slice' Buffer Overflow
CVE-2019-9810dosmultiple26 Mar 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISK
open
Exploit-DBVexDay Proof
Spidermonkey - IonMonkey Type Inference is Incorrect for Constructors Entered via OSR
CVE-2019-9791dosmultiple26 Mar 2019
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects w
28RISK
open
Exploit-DBVexDay Proof
VMware Workstation 14.1.5 / VMware Player 15 - Host VMX Process COM Class Hijack Privilege Escalation
CVE-2019-5512localwindows25 Mar 2019
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately
23RISK
open
Exploit-DBVexDay Proof
VMware Workstation 14.1.5 / VMware Player 15.0.2 - Host VMX Process Impersonation Hijack Privilege Escalation
CVE-2018-5511localwindows25 Mar 2019
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Manageme
28RISK
open
Exploit-DB
Rails 5.2.1 - Arbitrary File Content Disclosure
CVE-2019-5418HIGHunder attackwebappsmultiple21 Mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
Exploit-DB
Canarytokens 2019-03-01 - Detection Bypass
CVE-2019-9768doswindows21 Mar 2019
Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timesta
28RISK
open
Exploit-DB
DVD X Player 5.5.3 - '.plf' Buffer Overflow
CVE-2018-9128localwindows21 Mar 2019
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISK
open
Exploit-DB
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Request Forgery
CVE-2019-6282webappshardware20 Mar 2019
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpag
23RISK
open
Exploit-DB
PLC Wireless Router GPN2.4P21-C-CN - Incorrect Access Control
CVE-2019-6279webappshardware20 Mar 2019
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnera
23RISK
open
Exploit-DBVexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
CVE-2019-1003001remotejava19 Mar 2019
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RISK
open
Exploit-DBVexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
CVE-2019-1003002remotejava19 Mar 2019
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RISK
open
Exploit-DBVexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
CVE-2019-1003000remotejava19 Mar 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Flash click2play Bypass with CObjectElement::FinalCreateObject
CVE-2019-0612doswindows19 Mar 2019
A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash obj
28RISK
open
Exploit-DB
MyBB Upcoming Events Plugin 1.32 - Cross-Site Scripting
CVE-2019-9650webappsphp19 Mar 2019
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name
23RISK
open
Exploit-DBVexDay Proof
Google Chrome < M73 - MidiManagerWin Use-After-Free
CVE-2019-5789dosmultiple19 Mar 2019
An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.