Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
79,305 exploits
VulnCheck XDB
remote-with-credentials
CVE-2019-2729CRITICAL09 Jan 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISK
open
Exploit-DBVexDay Proof
JetBrains TeamCity 2018.2.4 - Remote Code Execution
CVE-2019-15039remotejava08 Jan 2020
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in
28RISK
open
GitHub PoC2
weblogic CVE-2019-2725利用exp。
CVE-2019-2725HIGHunder attackransomware08 Jan 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
Exploit-DB
Cisco DCNM JBoss 10.4 - Credential Leakage
CVE-2019-15999MEDIUMremotejava08 Jan 2020
Cisco Data Center Network Manager JBoss EAP Unauthorized Access Vulnerability
33RISK
open
Exploit-DB
EBBISLAND EBBSHAVE 6100-09-04-1441 - Remote Buffer Overflow
CVE-2017-3623remotehardware08 Jan 2020
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported ve
28RISK
open
GitHub PoC
geropl/CVE-2019-5736
CVE-2019-573608 Jan 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC2
Simple Overflow demo, like CVE-2017-11882 exp
CVE-2017-11882HIGHunder attackransomware08 Jan 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-2725HIGHunder attackransomware08 Jan 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
Exploit-DB
Microsoft Windows 10 (19H1 1901 x64) - 'ws2ifsl.sys' Use After Free Local Privilege Escalation (kASLR kCFG SMEP)
CVE-2019-1215HIGHunder attackransomwarelocalwindows_x86-6407 Jan 2020
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Win
76RISK
open
Metasploit300
"Cablehaunt" Cable Modem WebSocket DoS
CVE-2019-1949407 Jan 2020
Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker
23RISK
open
Exploit-DBVexDay Proof
piSignage 2.6.4 - Directory Traversal
CVE-2019-20354webappshardware07 Jan 2020
The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user)
23RISK
open
GitHub PoC149
bluefrostsecurity/CVE-2019-1215
CVE-2019-1215HIGHunder attackransomware06 Jan 2020
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Win
76RISK
open
VulnCheck XDB
local
CVE-2019-1215HIGHunder attackransomware06 Jan 2020
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Win
76RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack06 Jan 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
CVE-2017-9841 detector script
CVE-2017-9841CRITICALunder attack06 Jan 2020
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC1
Any3ite/CVE-2014-6271
CVE-2014-6271CRITICALunder attack06 Jan 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC5
CVE-2019-10758
CVE-2019-10758CRITICALunder attack05 Jan 2020
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-10758CRITICALunder attack05 Jan 2020
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse
100RISK
open
GitHub PoC
CVE-2017-8759 use file
CVE-2017-8759HIGHunder attack02 Jan 2020
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware02 Jan 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
client-side
CVE-2017-8759HIGHunder attack02 Jan 2020
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
Exploit-DB
Microsoft Windows - Shell COM Server Registrar Local Privilege Escalation
CVE-2019-1184MEDIUMlocalwindows02 Jan 2020
Windows Elevation of Privilege Vulnerability
55RISK
open
Exploit-DBVexDay Proof
nostromo 1.9.6 - Remote Code Execution
CVE-2019-16278CRITICALunder attackremotemultiple01 Jan 2020
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC
CVE-2019-16278:Nostromo Web服务器的RCE漏洞
CVE-2019-16278CRITICALunder attack01 Jan 2020
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack01 Jan 2020
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack31 Dec 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
Exploit-DB
Sony Playstation 4 (PS4) < 6.72 - WebKit Code Execution (PoC)
CVE-2018-4386webappshardware31 Dec 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISK
open
GitHub PoC1
(Nhttpd) Nostromo 1.9.6 RCE due to Directory Traversal
CVE-2019-16278CRITICALunder attack31 Dec 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
Exploit-DBVexDay Proof
FreeBSD-SA-19:02.fd - Privilege Escalation
CVE-2019-5596localfreebsd30 Dec 2019
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RISK
open
Exploit-DBVexDay Proof
Microsoft UPnP - Local Privilege Elevation (Metasploit)
CVE-2019-1405HIGHunder attackransomwarelocalwindows30 Dec 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISK
open
previouspage 800 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.