Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Micro Focus (HPE) Data Protector - SUID Privilege Escalation (Metasploit)
CVE-2019-11660locallinux04 Nov 2019
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30,
38RISK
open
Exploit-DBVexDay Proof
Nostromo - Directory Traversal Remote Command Execution (Metasploit)
CVE-2019-16278CRITICALunder attackremotemultiple01 Nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
Exploit-DBVexDay Proof
JavaScriptCore - GetterSetter Type Confusion During DFG Compilation
CVE-2019-8765dosmultiple30 Oct 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Proc
23RISK
open
Exploit-DBVexDay Proof
Linux Polkit - pkexec helper PTRACE_TRACEME local root (Metasploit)
CVE-2019-13272HIGHunder attacklocallinux24 Oct 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
Exploit-DBVexDay Proof
Total.js CMS 12 - Widget JavaScript Code Injection (Metasploit)
CVE-2019-15954remotemultiple22 Oct 2019
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote
60RISK
open
Exploit-DBVexDay Proof
Trend Micro Anti-Threat Toolkit 1.62.0.1218 - Remote Code Execution
CVE-2019-9491localwindows21 Oct 2019
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow due to Malformed JP2 Stream (2)
CVE-2019-8197doswindows21 Oct 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISK
open
Exploit-DBVexDay Proof
ThinVNC 1.0b1 - Authentication Bypass
CVE-2019-17662remotewindows17 Oct 2019
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in CI!HashKComputeFirstPageHash While Parsing Malformed PE File
CVE-2019-1346doswindows10 Oct 2019
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in CI!CipFixImageType While Parsing Malformed PE File
CVE-2019-1344doswindows10 Oct 2019
An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memo
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - NULL Pointer Dereference in nt!MiOffsetToProtos While Parsing Malformed PE File
CVE-2019-1343doswindows10 Oct 2019
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in nt!MiParseImageLoadConfig While Parsing Malformed PE File
CVE-2019-1345doswindows10 Oct 2019
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in nt!MiRelocateImage While Parsing Malformed PE File
CVE-2019-1347doswindows10 Oct 2019
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - win32k.sys TTF Font Processing Pool Corruption in win32k!ulClearTypeFilter
CVE-2019-1364doswindows10 Oct 2019
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
23RISK
open
Exploit-DBVexDay Proof
XNU - Remote Double-Free via Data Race in IPComp Input Path
CVE-2019-8717dosmacos09 Oct 2019
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15, tvOS
23RISK
open
Exploit-DBVexDay Proof
Android - Binder Driver Use-After-Free
CVE-2019-2215HIGHunder attacklocalandroid04 Oct 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0147HIGHunder attackransomwareremotewindows02 Oct 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0144HIGHunder attackransomwareremotewindows02 Oct 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0145HIGHunder attackransomwareremotewindows02 Oct 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0146HIGHunder attackransomwareremotewindows02 Oct 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0143HIGHunder attackransomwareremotewindows02 Oct 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0148HIGHunder attackransomwareremotewindows02 Oct 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DBVexDay Proof
ABRT - sosreport Privilege Escalation (Metasploit)
CVE-2015-5287locallinux25 Sep 2019
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
38RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - BlueKeep RDP Remote Windows Kernel Use After Free (Metasploit)
CVE-2019-0708CRITICALunder attackransomwareremotewindows24 Sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary Can Read Object Out of Bounds
CVE-2019-8641dosios24 Sep 2019
An out-of-bounds read was addressed with improved input validation.
28RISK
open
Exploit-DBVexDay Proof
LimeSurvey 3.17.13 - Cross-Site Scripting
CVE-2019-16172webappsphp13 Sep 2019
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RISK
open
Exploit-DBVexDay Proof
LimeSurvey 3.17.13 - Cross-Site Scripting
CVE-2019-16173webappsphp13 Sep 2019
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example,
23RISK
open
Exploit-DBVexDay Proof
Microsoft DirectWrite - Out-of-Bounds Read in sfac_GetSbitBitmap While Processing TTF Fonts
CVE-2019-1244doswindows12 Sep 2019
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
28RISK
open
Exploit-DBVexDay Proof
Microsoft DirectWrite - Invalid Read in SplicePixel While Processing OTF Fonts
CVE-2019-1245doswindows12 Sep 2019
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
28RISK
open
Exploit-DBVexDay Proof
LibreNMS - Collectd Command Injection (Metasploit)
CVE-2019-10669remotelinux10 Sep 2019
An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/dev
60RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.