Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,466cataloged exploits
36,589CVEs with public exploitation
24,695lab-tested
79,305 exploits
Exploit-DBVexDay Proof
Pulse Secure VPN - Arbitrary Command Execution (Metasploit)
CVE-2019-11539HIGHunder attackransomwareremotemultiple20 Nov 2019
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-261819 Nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
35RISK
open
VulnCheck XDB
initial-access
CVE-2018-289419 Nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Su
50RISK
open
GitHub PoC52
Ladon Scanner For Python, Large Network Penetration Scanner & Cobalt Strike, vulnerability / exploit / detection / MS17010/SmbGhost/CVE-2020-0796/CVE-2018-2894
CVE-2020-0796CRITICALunder attackransomware19 Nov 2019
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC5
random-robbie/CVE-2019-5418
CVE-2019-5418HIGHunder attack19 Nov 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-11882HIGHunder attackransomware19 Nov 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware19 Nov 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
Metasploit600
OpenNetAdmin Ping Command Injection
CVE-2019-25065MEDIUM19 Nov 2019
OpenNetAdmin os command injection
48RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-5418HIGHunder attack19 Nov 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
Exploit-DB
Microsoft Windows 7 (x86) - 'BlueKeep' Remote Desktop Protocol (RDP) Remote Windows Kernel Use After Free
CVE-2019-0708CRITICALunder attackransomwareremotewindows_x8619 Nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DB
Lexmark Services Monitor 2.27.4.0.39 - Directory Traversal
CVE-2019-16758webappshardware18 Nov 2019
In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal tech
28RISK
open
Exploit-DB
nipper-ng 0.11.10 - Remote Buffer Overflow (PoC)
CVE-2019-17424remotelinux18 Nov 2019
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows re
28RISK
open
GitHub PoC1
remote debug environment for CLion
CVE-2019-11043HIGHunder attackransomware17 Nov 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
Exploit-DB
Microsoft Windows 10 Build 1803 < 1903 - 'COMahawk' Local Privilege Escalation
CVE-2019-1322HIGHunder attackransomwarelocalwindows14 Nov 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RISK
open
Exploit-DB
Microsoft Windows 10 Build 1803 < 1903 - 'COMahawk' Local Privilege Escalation
CVE-2019-1405HIGHunder attackransomwarelocalwindows14 Nov 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISK
open
Exploit-DB
Xfilesharing 2.5.1 - Arbitrary File Upload
CVE-2019-18951webappsphp14 Nov 2019
SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.
28RISK
open
Metasploit300
WordPress Email Subscribers and Newsletter Hash SQLi Scanner
CVE-2019-20361HIGH13 Nov 2019
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b
78RISK
open
Exploit-DB
Technicolor TD5130.2 - Remote Command Execution
CVE-2019-18396webappshardware13 Nov 2019
An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Comm
28RISK
open
Exploit-DB
FUDForum 3.0.9 - Remote Code Execution
CVE-2019-18873webappsphp13 Nov 2019
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An
23RISK
open
GitHub PoC
Sindayifu/CVE-2019-14287-CVE-2014-6271
CVE-2019-1428713 Nov 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC348
Privilege Escalation: Weaponizing CVE-2019-1405 and CVE-2019-1322
CVE-2019-1405HIGHunder attackransomware13 Nov 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISK
open
VulnCheck XDB
local
CVE-2019-1405HIGHunder attackransomware13 Nov 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISK
open
VulnCheck XDB
local
CVE-2019-1322HIGHunder attackransomware13 Nov 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RISK
open
GitHub PoC
cve-2014-6271
CVE-2014-6271CRITICALunder attack13 Nov 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Sindayifu/CVE-2019-14287-CVE-2014-6271
CVE-2014-6271CRITICALunder attack13 Nov 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-0708CRITICALunder attackransomware12 Nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DB
Adrenalin Core HCM 5.4.0 - 'ReportID' Reflected Cross-Site Scripting
CVE-2018-12653webappsaspx12 Nov 2019
A Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0. An attacker can input malicious Jav
23RISK
open
Exploit-DB
CBAS-Web 19.0.0 - Cross-Site Request Forgery (Add Super Admin)
CVE-2019-10847webappshardware12 Nov 2019
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
23RISK
open
Metasploit600
Microsoft UPnP Local Privilege Elevation Vulnerability
CVE-2019-1405HIGHunder attackransomware12 Nov 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISK
open
Metasploit600
Microsoft UPnP Local Privilege Elevation Vulnerability
CVE-2019-1322HIGHunder attackransomware12 Nov 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RISK
open
previouspage 805 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.