Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,596cataloged exploits
36,656CVEs with public exploitation
24,695lab-tested
79,305 exploits
Metasploit600
Linear eMerge E3-Series Access Controller Command Injection
CVE-2019-7256CRITICALunder attack29 Oct 2019
Linear eMerge E3-Series devices allow Command Injections.
100RISK
open
Exploit-DB
Microsoft Windows Server 2012 - 'Group Policy' Security Feature Bypass (MS15-014)
CVE-2015-0009remotewindows29 Oct 2019
The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, W
23RISK
open
GitHub PoC146
(PoC) Python version of CVE-2019-11043 exploit by neex
CVE-2019-11043HIGHunder attackransomware28 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
GitHub PoC
TEST
CVE-2019-3396CRITICALunder attackransomware28 Oct 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC1
CVE-2019-11043 PHP远程代码执行
CVE-2019-11043HIGHunder attackransomware28 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
Metasploit600
rConfig install Command Execution
CVE-2019-1666228 Oct 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISK
open
GitHub PoC
huang919/cve-2019-14287-PPT
CVE-2019-1428728 Oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
VulnCheck XDB
initial-access
CVE-2019-11043HIGHunder attackransomware28 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-11043HIGHunder attackransomware28 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
Exploit-DB
PHP-FPM + Nginx - Remote Code Execution
CVE-2019-11043HIGHunder attackransomwarewebappsphp28 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
GitHub PoC19
CVE-2019-10149 : A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
CVE-2019-10149CRITICALunder attack27 Oct 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC7
FUDForum 3.0.9 - XSS / Remote Code Execution (CVE-2019-18873, CVE-2019-18839)
CVE-2019-1887327 Oct 2019
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An
23RISK
open
GitHub PoC4
apache axis1.4远程代码执行漏洞
CVE-2019-022727 Oct 2019
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2
45RISK
open
VulnCheck XDB
initial-access
CVE-2019-10149CRITICALunder attack27 Oct 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC2
CVE-2000-0979
CVE-2000-097926 Oct 2019
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file
35RISK
open
Exploit-DB
ClonOs WEB UI 19.09 - Improper Access Control
CVE-2019-18418webappsphp25 Oct 2019
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests be
23RISK
open
GitHub PoC27
akamajoris/CVE-2019-11043-Docker
CVE-2019-11043HIGHunder attackransomware24 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
GitHub PoC
CVE-2015-7547 initial research.
CVE-2015-754724 Oct 2019
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISK
open
VulnCheck XDB
initial-access
CVE-2019-11043HIGHunder attackransomware24 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-11043HIGHunder attackransomware24 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2015-754724 Oct 2019
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware24 Oct 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC1
fairyming/CVE-2019-11043
CVE-2019-11043HIGHunder attackransomware24 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
GitHub PoC
ianxtianxt/CVE-2019-11043
CVE-2019-11043HIGHunder attackransomware24 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
GitHub PoC4
PHP-FPM Remote Code Execution Vulnerability (CVE-2019-11043) POC in Python
CVE-2019-11043HIGHunder attackransomware24 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
Exploit-DBVexDay Proof
Linux Polkit - pkexec helper PTRACE_TRACEME local root (Metasploit)
CVE-2019-13272HIGHunder attacklocallinux24 Oct 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC3
Remote Code Execution Vulnerability in Webmin
CVE-2019-15107CRITICALunder attackransomware24 Oct 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC
melardev/CVE-2019-5418
CVE-2019-5418HIGHunder attack24 Oct 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
Exploit-DB
Rocket.Chat 2.1.0 - Cross-Site Scripting
CVE-2019-17220webappslinux23 Oct 2019
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
23RISK
open
GitHub PoC1
CVE-2019-16278 Python3 Exploit Code
CVE-2019-16278CRITICALunder attack23 Oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
previouspage 809 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.