Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,457cataloged exploits
36,589CVEs with public exploitation
24,695lab-tested
79,305 exploits
Metasploit600
Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization
CVE-2019-18935CRITICALunder attackransomware09 Dec 2019
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC1
CVE-2008-1611 TFTP 1.41 buffer overflow exploit in the filepath
CVE-2008-161108 Dec 2019
Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or ex
50RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware07 Dec 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC109
CVE-2019-0708 (BlueKeep)
CVE-2019-0708CRITICALunder attackransomware07 Dec 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-11510CRITICALunder attackransomware07 Dec 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open
Exploit-DB
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack
CVE-2019-9810localwindows_x86-6407 Dec 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISK
open
Exploit-DB
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack
CVE-2019-11708CRITICALunder attacklocalwindows_x86-6407 Dec 2019
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RISK
open
GitHub PoC9
Automated script for Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API. You must have a Shodan account to use this script.
CVE-2019-11510CRITICALunder attackransomware07 Dec 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open
Exploit-DBVexDay Proof
Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
CVE-2019-15627localwindows06 Dec 2019
Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, w
23RISK
open
Exploit-DB
Integard Pro NoJs 2.2.0.9026 - Remote Buffer Overflow
CVE-2019-16702remotewindows06 Dec 2019
Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs pa
28RISK
open
Exploit-DB
Verot 2.0.3 - Remote Code Execution
CVE-2019-19576webappsphp06 Dec 2019
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! an
28RISK
open
Exploit-DBVexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
CVE-2018-9021webappswindows05 Dec 2019
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
23RISK
open
Exploit-DBVexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
CVE-2018-9022webappswindows05 Dec 2019
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
28RISK
open
GitHub PoC3
AppXSvc Arbitrary File Overwrite DoS
CVE-2019-147605 Dec 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
23RISK
open
GitHub PoC12
This is a filter bypass exploit that results in arbitrary file upload and remote code execution in class.upload.php <= 2.0.3
CVE-2019-1957604 Dec 2019
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! an
28RISK
open
Exploit-DB
Cisco WLC 2504 8.9 - Denial of Service (PoC)
CVE-2019-15276HIGHdoshardware04 Dec 2019
Cisco Wireless LAN Controller HTTP Parsing Engine Denial of Service Vulnerability
53RISK
open
Exploit-DB
Intelbras Router RF1200 1.1.3 - Cross-Site Request Forgery
CVE-2019-19516webappshardware03 Dec 2019
Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a pa
23RISK
open
Exploit-DB
Revive Adserver 4.2 - Remote Code Execution
CVE-2019-5434webappsphp03 Dec 2019
An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() cal
50RISK
open
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALunder attack01 Dec 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
GitHub PoC21
hekadan/CVE-2019-7609
CVE-2019-7609CRITICALunder attack01 Dec 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
GitHub PoC1
IE7 buffer overflow through an ANI file
CVE-2007-003829 Nov 2019
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISK
open
VulnCheck XDB
client-side
CVE-2007-003829 Nov 2019
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISK
open
Metasploit300
Anviz CrossChex Buffer Overflow
CVE-2019-1251828 Nov 2019
Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.
50RISK
open
GitHub PoC72
guest→system(UAC手动提权)
CVE-2019-1388HIGHunder attackransomware27 Nov 2019
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RISK
open
GitHub PoC4
Exploit for CVE-2017-12945.
CVE-2017-1294527 Nov 2019
Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authen
28RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack26 Nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack26 Nov 2019
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
Exploit the dirtycow vulnerability to login as root
CVE-2016-5195HIGHunder attack26 Nov 2019
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC6
Python script to exploit RCE in Nostromo nhttpd <= 1.9.6.
CVE-2019-16278CRITICALunder attack26 Nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
Metasploit300
QNAP QTS and Photo Station Local File Inclusion
CVE-2019-7194CRITICALunder attackransomware25 Nov 2019
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
100RISK
open
previouspage 803 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.