Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,781cataloged exploits
36,771CVEs with public exploitation
24,695lab-tested
24,475 exploits
Exploit-DBVexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
CVE-2019-1003002remotejava19 Mar 2019
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RISK
open
Exploit-DBVexDay Proof
Google Chrome < M73 - MidiManagerWin Use-After-Free
CVE-2019-5789dosmultiple19 Mar 2019
An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed
23RISK
open
Exploit-DBVexDay Proof
Google Chrome < M73 - Data Race in ExtensionsGuestViewMessageFilter
CVE-2019-5796dosmultiple19 Mar 2019
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially explo
23RISK
open
Exploit-DBVexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
CVE-2019-1003001remotejava19 Mar 2019
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Flash click2play Bypass with CObjectElement::FinalCreateObject
CVE-2019-0612doswindows19 Mar 2019
A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash obj
28RISK
open
Exploit-DB
Gila CMS 1.9.1 - Cross-Site Scripting
CVE-2019-9647webappsphp19 Mar 2019
Gila CMS 1.9.1 has XSS.
23RISK
open
Exploit-DBVexDay Proof
BMC Patrol Agent - Privilege Escalation Code Execution Execution (Metasploit)
CVE-2018-20735remotemultiple18 Mar 2019
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for l
38RISK
open
Exploit-DB
Moodle 3.4.1 - Remote Code Execution
CVE-2018-1133webappsphp15 Mar 2019
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec
35RISK
open
Exploit-DB
Vembu Storegrid Web Interface 4.4.0 - Multiple Vulnerabilities
CVE-2014-10079webappsphp15 Mar 2019
In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hid
23RISK
open
Exploit-DBVexDay Proof
CMS Made Simple Showtime2 Module 3.6.2 - (Authenticated) Arbitrary File Upload
CVE-2019-9692webappsphp15 Mar 2019
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RISK
open
Exploit-DB
Vembu Storegrid Web Interface 4.4.0 - Multiple Vulnerabilities
CVE-2014-10078webappsphp15 Mar 2019
Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfa
23RISK
open
Exploit-DB
FTPGetter Standard 5.97.0.177 - Remote Code Execution
CVE-2019-9760remotewindows14 Mar 2019
FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-cont
50RISK
open
Exploit-DB
pfSense 2.4.4-p1 (HAProxy Package 0.59_14) - Persistent Cross-Site Scripting
CVE-2019-8953webappsphp13 Mar 2019
The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, re
35RISK
open
Exploit-DBVexDay Proof
elFinder PHP Connector < 2.1.48 - 'exiftran' Command Injection (Metasploit)
CVE-2019-9194remotephp13 Mar 2019
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open
Exploit-DB
WordPress Plugin GraceMedia Media Player 1.0 - Local File Inclusion
CVE-2019-9618webappsphp13 Mar 2019
The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter.
50RISK
open
Exploit-DB
Microsoft Windows MSHTML Engine - 'Edit' Remote Code Execution
CVE-2019-0541HIGHunder attacklocalwindows13 Mar 2019
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML E
83RISK
open
Exploit-DBVexDay Proof
Apache Tika-server < 1.18 - Command Injection
CVE-2018-1335remotewindows13 Mar 2019
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
Exploit-DB
PRTG Network Monitor 18.2.38 - (Authenticated) Remote Code Execution
CVE-2018-9276HIGHunder attackwebappswindows11 Mar 2019
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
Exploit-DB
Linux Kernel 4.4 (Ubuntu 16.04) - 'snd_timer_user_ccallback()' Kernel Pointer Leak
CVE-2016-4578doslinux11 Mar 2019
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local us
23RISK
open
Exploit-DB
Flexpaper PHP Publish Service 2.3.6 - Remote Code Execution
CVE-2018-11686webappsphp11 Mar 2019
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_c
50RISK
open
Exploit-DB
Sony Playstation 4 (PS4) < 6.20 - WebKit Code Execution (PoC)
CVE-2018-4441localhardware08 Mar 2019
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1,
28RISK
open
Exploit-DB
DirectAdmin 1.55 - 'CMD_ACCOUNT_ADMIN' Cross-Site Request Forgery
CVE-2019-9625webappsphp08 Mar 2019
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
23RISK
open
Exploit-DB
McAfee ePO 5.9.1 - Registered Executable Local Access Bypass
CVE-2018-6671MEDIUMwebappswindows08 Mar 2019
SB10240 - ePolicy Orchestrator (ePO) - Application Protection Bypass vulnerability
33RISK
open
Exploit-DBVexDay Proof
Drupal < 8.5.11 / < 8.6.10 - RESTful Web Services unserialize() Remote Command Execution (Metasploit)
CVE-2019-6340HIGHunder attackremotephp07 Mar 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
Exploit-DBVexDay Proof
FreeBSD - Intel SYSRET Privilege Escalation (Metasploit)
CVE-2012-0217localfreebsd_x86-6407 Mar 2019
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and
50RISK
open
Exploit-DBVexDay Proof
Android - getpidcon() Usage in Hardware binder ServiceManager Permits ACL Bypass
CVE-2019-2023dosandroid06 Mar 2019
In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID
23RISK
open
Exploit-DBVexDay Proof
Android - binder Use-After-Free via racy Initialization of ->allow_user_free
CVE-2019-2025dosandroid06 Mar 2019
In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. This could lead to local
23RISK
open
Exploit-DBVexDay Proof
Linux < 4.20.14 - Virtual Address 0 is Mappable via Privileged write() to /proc/*/mem
CVE-2019-9213doslinux06 Mar 2019
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RISK
open
Exploit-DB
zzzphp CMS 1.6.1 - Cross-Site Request Forgery
CVE-2019-9082HIGHunder attackwebappsphp04 Mar 2019
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RISK
open
Exploit-DB
Microsoft Edge Chakra 1.11.4 - Read Permission via Type Confusion
CVE-2019-0539doswindows04 Mar 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.