Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,596cataloged exploits
36,656CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC3
CVE-2017-3506
CVE-2017-3506HIGHunder attack05 Nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC
Optional Mitigation Steps
CVE-2019-1231405 Nov 2019
Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as
60RISK
open
GitHub PoC1
CVE-2017-0005 POC
CVE-2017-0005HIGHunder attack05 Nov 2019
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
76RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware05 Nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-261805 Nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
35RISK
open
GitHub PoC2
CVE-2018-3245
CVE-2018-324505 Nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
45RISK
open
Exploit-DBVexDay Proof
Micro Focus (HPE) Data Protector - SUID Privilege Escalation (Metasploit)
CVE-2019-11660locallinux04 Nov 2019
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30,
38RISK
open
Metasploit600
Microsoft Spooler Local Privilege Elevation Vulnerability
CVE-2020-1337HIGH04 Nov 2019
Windows Print Spooler Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC3
POC for CVE-2019-13720
CVE-2019-13720HIGHunder attack04 Nov 2019
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap
93RISK
open
Metasploit300
Microsoft Spooler Local Privilege Elevation Vulnerability
CVE-2020-1048HIGH04 Nov 2019
Windows Print Spooler Elevation of Privilege Vulnerability
61RISK
open
Metasploit600
Windows Update Orchestrator unchecked ScheduleWork call
CVE-2020-131304 Nov 2019
An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file oper
30RISK
open
Metasploit600
FreeSWITCH Event Socket Command Execution
CVE-2019-1949203 Nov 2019
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISK
open
GitHub PoC
Standalone Python ≥3.6 RCE Unauthenticated exploit for Supervisor 3.0a1 to 3.3.2
CVE-2017-1161002 Nov 2019
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISK
open
VulnCheck XDB
client-side
CVE-2017-1161002 Nov 2019
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-019201 Nov 2019
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP
60RISK
open
Exploit-DB
Apache Solr 8.2.0 - Remote Code Execution
CVE-2019-17558HIGHunder attackwebappsjava01 Nov 2019
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RISK
open
Exploit-DBVexDay Proof
Nostromo - Directory Traversal Remote Command Execution (Metasploit)
CVE-2019-16278CRITICALunder attackremotemultiple01 Nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC
CVE-2018-15473-Exploit
CVE-2018-15473MEDIUM01 Nov 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
Exploit-DB
MikroTik RouterOS 6.45.6 - DNS Cache Poisoning
CVE-2019-3978remotehardware31 Oct 2019
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queri
28RISK
open
Metasploit0
Kibana Timelion Prototype Pollution RCE
CVE-2019-7609CRITICALunder attack30 Oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-11043HIGHunder attackransomware30 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
GitHub PoC
3rg1s/CVE-2016-2098
CVE-2016-209830 Oct 2019
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISK
open
GitHub PoC8
Docker image and commands to check CVE-2019-11043 vulnerability on nginx/php-fpm applications.
CVE-2019-11043HIGHunder attackransomware30 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
Exploit-DBVexDay Proof
JavaScriptCore - GetterSetter Type Confusion During DFG Compilation
CVE-2019-8765dosmultiple30 Oct 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Proc
23RISK
open
GitHub PoC10
Mayter/CVE-2019-1315
CVE-2019-1315HIGHunder attackransomware29 Oct 2019
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka '
71RISK
open
GitHub PoC5
Python exp for CVE-2019-11043
CVE-2019-11043HIGHunder attackransomware29 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
Exploit-DB
Microsoft Windows Server 2012 - 'Group Policy' Security Feature Bypass (MS15-014)
CVE-2015-0009remotewindows29 Oct 2019
The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, W
23RISK
open
VulnCheck XDB
initial-access
CVE-2019-11043HIGHunder attackransomware29 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
Exploit-DB
rConfig 3.9.2 - Remote Code Execution
CVE-2019-16662webappsphp29 Oct 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISK
open
Metasploit600
Linear eMerge E3-Series Access Controller Command Injection
CVE-2019-7256CRITICALunder attack29 Oct 2019
Linear eMerge E3-Series devices allow Command Injections.
100RISK
open
previouspage 808 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.