Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,526cataloged exploits
36,593CVEs with public exploitation
24,695lab-tested
79,305 exploits
Exploit-DB
Adrenalin Core HCM 5.4.0 - 'ReportID' Reflected Cross-Site Scripting
CVE-2018-12653webappsaspx12 Nov 2019
A Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0. An attacker can input malicious Jav
23RISK
open
Exploit-DB
CBAS-Web 19.0.0 - Cross-Site Request Forgery (Add Super Admin)
CVE-2019-10847webappshardware12 Nov 2019
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
23RISK
open
GitHub PoC
Sindadziy/cve-2014-6271
CVE-2014-6271CRITICALunder attack12 Nov 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC19
Suricata LUA scripts to detect CVE-2019-12255, CVE-2019-12256, CVE-2019-12258, and CVE-2019-12260
CVE-2019-1225512 Nov 2019
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TC
45RISK
open
Metasploit600
Microsoft UPnP Local Privilege Elevation Vulnerability
CVE-2019-1322HIGHunder attackransomware12 Nov 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RISK
open
Exploit-DB
Atlassian Confluence 6.15.1 - Directory Traversal
CVE-2019-3398HIGHunder attackwebappsjsp12 Nov 2019
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISK
open
Exploit-DB
eMerge E3 1.00-06 - Cross-Site Request Forgery
CVE-2019-7262webappshardware12 Nov 2019
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
28RISK
open
Metasploit600
Microsoft UPnP Local Privilege Elevation Vulnerability
CVE-2019-1405HIGHunder attackransomware12 Nov 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISK
open
Exploit-DB
eMerge E3 1.00-06 - Unauthenticated Directory Traversal
CVE-2019-7254webappshardware12 Nov 2019
Linear eMerge E3-Series devices allow File Inclusion.
60RISK
open
Exploit-DB
FlexAir Access Control 2.3.35 - Authentication Bypass
CVE-2019-7666webappshardware12 Nov 2019
Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash valu
28RISK
open
Exploit-DB
eMerge E3 1.00-06 - Arbitrary File Upload
CVE-2019-7257webappshardware12 Nov 2019
Linear eMerge E3-Series devices allow Unrestricted File Upload.
35RISK
open
Exploit-DB
Optergy 2.3.0a - Username Disclosure
CVE-2019-7272webappshardware12 Nov 2019
Optergy Proton/Enterprise devices allow Username Disclosure.
28RISK
open
Exploit-DB
CBAS-Web 19.0.0 - Username Enumeration
CVE-2019-10848webappshardware12 Nov 2019
Computrols CBAS 18.0.0 allows Username Enumeration.
23RISK
open
GitHub PoC
Sindadziy/cve-2019-14287
CVE-2019-1428712 Nov 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
Exploit-DB
Optergy 2.3.0a - Remote Code Execution
CVE-2019-7274webappshardware12 Nov 2019
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
28RISK
open
Exploit-DB
Optergy 2.3.0a - Cross-Site Request Forgery (Add Admin)
CVE-2019-7273webappshardware12 Nov 2019
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
23RISK
open
Exploit-DB
CBAS-Web 19.0.0 - Information Disclosure
CVE-2019-10849remotehardware12 Nov 2019
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
23RISK
open
Exploit-DB
eMerge E3 1.00-06 - 'layout' Reflected Cross-Site Scripting
CVE-2019-7255webappshardware12 Nov 2019
Linear eMerge E3-Series devices allow XSS.
50RISK
open
Exploit-DB
Adrenalin Core HCM 5.4.0 - 'prntDDLCntrlName' Reflected Cross-Site Scripting
CVE-2018-12650webappsaspx12 Nov 2019
Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSe
23RISK
open
Exploit-DB
eMerge50P 5000P 4.6.07 - Remote Code Execution
CVE-2019-7269webappshardware12 Nov 2019
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
35RISK
open
Exploit-DB
Adrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site Scripting
CVE-2018-12234webappsaspx12 Nov 2019
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied
23RISK
open
Exploit-DB
eMerge E3 1.00-06 - Privilege Escalation
CVE-2019-7254webappshardware12 Nov 2019
Linear eMerge E3-Series devices allow File Inclusion.
60RISK
open
Exploit-DB
Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting
CVE-2019-7671webappsalpha12 Nov 2019
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being ret
23RISK
open
Exploit-DB
Optergy 2.3.0a - Remote Code Execution (Backdoor)
CVE-2019-7276webappshardware12 Nov 2019
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RISK
open
Exploit-DB
Computrols CBAS-Web 19.0.0 - 'username' Reflected Cross-Site Scripting
CVE-2019-10846webappshardware12 Nov 2019
Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and passw
23RISK
open
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8641dosmultiple11 Nov 2019
An out-of-bounds read was addressed with improved input validation.
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed OTF Font (CFF Table)
CVE-2019-8196doswindows11 Nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISK
open
GitHub PoC1
load-scripts.php file, which purpose is to retrieve several JavaScript packages through one single request.
CVE-2018-638911 Nov 2019
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
CVE-2019-8195doswindows11 Nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISK
open
GitHub PoC16
Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix)
CVE-2019-11043HIGHunder attackransomware11 Nov 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
previouspage 806 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.