Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,596cataloged exploits
36,656CVEs with public exploitation
24,695lab-tested
79,305 exploits
VulnCheck XDB
initial-access
CVE-2017-9248CRITICALunder attack23 Oct 2019
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISK
open
GitHub PoC
tinker-li/CVE-2019-11043
CVE-2019-11043HIGHunder attackransomware23 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack23 Oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC105
php-fpm+Nginx RCE
CVE-2019-11043HIGHunder attackransomware23 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-11043HIGHunder attackransomware23 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
GitHub PoC
leonardo1101/cve-2017-11176
CVE-2017-1117623 Oct 2019
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISK
open
GitHub PoC
ictnamanh/CVE-2017-9248
CVE-2017-9248CRITICALunder attack23 Oct 2019
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISK
open
Exploit-DB
Rocket.Chat 2.1.0 - Cross-Site Scripting
CVE-2019-17220webappslinux23 Oct 2019
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
23RISK
open
GitHub PoC1
CVE-2019-16278 Python3 Exploit Code
CVE-2019-16278CRITICALunder attack23 Oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
Exploit-DB
Moxa EDR-810 - Command Injection / Information Disclosure
CVE-2019-10963remotehardware22 Oct 2019
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from
23RISK
open
Exploit-DB
Moxa EDR-810 - Command Injection / Information Disclosure
CVE-2019-10969remotehardware22 Oct 2019
Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthor
28RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack22 Oct 2019
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
Metasploit300
PHP-FPM Underflow RCE
CVE-2019-11043HIGHunder attackransomware22 Oct 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
Exploit-DBVexDay Proof
Total.js CMS 12 - Widget JavaScript Code Injection (Metasploit)
CVE-2019-15954remotemultiple22 Oct 2019
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote
60RISK
open
GitHub PoC9
脏牛Linux本地提权漏洞复现(CVE-2016-5195)
CVE-2016-5195HIGHunder attack22 Oct 2019
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow due to Malformed JP2 Stream (2)
CVE-2019-8197doswindows21 Oct 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISK
open
GitHub PoC167
exploit CVE-2019-7609(kibana RCE) on right way by python2 scripts
CVE-2019-7609CRITICALunder attack21 Oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
GitHub PoC56
RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer
CVE-2019-7609CRITICALunder attack21 Oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
Exploit-DB
Solaris 11.4 - xscreensaver Privilege Escalation
CVE-2019-3010HIGHunder attacklocalsolaris21 Oct 2019
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RISK
open
Exploit-DBVexDay Proof
Trend Micro Anti-Threat Toolkit 1.62.0.1218 - Remote Code Execution
CVE-2019-9491localwindows21 Oct 2019
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
28RISK
open
GitHub PoC5
Instructions for installing a vulnerable version of Exim and its expluatation
CVE-2019-10149CRITICALunder attack21 Oct 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-950621 Oct 2019
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before
60RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack21 Oct 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
VulnCheck XDB
local
CVE-2019-10149CRITICALunder attack21 Oct 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALunder attack21 Oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-7609CRITICALunder attack21 Oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
VulnCheck XDB
infoleak
CVE-2018-376021 Oct 2019
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12
43RISK
open
GitHub PoC5
RCE Exploit For CVE-2019-17424 (nipper-ng 0.11.10)
CVE-2019-1742420 Oct 2019
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows re
28RISK
open
Metasploit400
Nostromo Directory Traversal Remote Command Execution
CVE-2019-16278CRITICALunder attack20 Oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALunder attack18 Oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
previouspage 810 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.