Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,596cataloged exploits
36,656CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC5
Crestron/Barco/Extron/InFocus/TeqAV Remote Command Injection (CVE-2019-3929) Metasploit Module
CVE-2019-3929CRITICALunder attack17 Sep 2019
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-3929CRITICALunder attack17 Sep 2019
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware17 Sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DB
Notepad++ < 7.7 (x64) - Denial of Service
CVE-2019-16294doswindows_x86-6416 Sep 2019
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode ch
23RISK
open
Exploit-DB
Symantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File Upload
CVE-2016-10258webappscfm16 Sep 2019
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A
23RISK
open
VulnCheck XDB
infoleak
CVE-2019-845116 Sep 2019
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RISK
open
VulnCheck XDB
client-side
CVE-2018-1261316 Sep 2019
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
GitHub PoC4
Modified standalone exploit ported for Python 3
CVE-2018-1261316 Sep 2019
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
Exploit-DB
AppXSvc - Privilege Escalation
CVE-2019-1253HIGHunder attackransomwarelocalwindows16 Sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISK
open
GitHub PoC
Tool to exploit CVE-2018-7284 and CVE-2018-19278
CVE-2018-728415 Sep 2019
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Ce
35RISK
open
GitHub PoC3
CVE-2019-0604: SharePoint RCE detection rules and sample PCAP
CVE-2019-0604CRITICALunder attackransomware15 Sep 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISK
open
Metasploit600
Micro Focus (HPE) Data Protector SUID Privilege Escalation
CVE-2019-1166013 Sep 2019
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30,
38RISK
open
Exploit-DBVexDay Proof
LimeSurvey 3.17.13 - Cross-Site Scripting
CVE-2019-16173webappsphp13 Sep 2019
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example,
23RISK
open
Exploit-DB
Dolibarr ERP-CRM 10.0.1 - 'User-Agent' Cross-Site Scripting
CVE-2019-16197webappsphp13 Sep 2019
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document
23RISK
open
Exploit-DBVexDay Proof
LimeSurvey 3.17.13 - Cross-Site Scripting
CVE-2019-16172webappsphp13 Sep 2019
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RISK
open
Exploit-DBVexDay Proof
Microsoft DirectWrite - Invalid Read in SplicePixel While Processing OTF Fonts
CVE-2019-1245doswindows12 Sep 2019
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
28RISK
open
Exploit-DBVexDay Proof
Microsoft DirectWrite - Out-of-Bounds Read in sfac_GetSbitBitmap While Processing TTF Fonts
CVE-2019-1244doswindows12 Sep 2019
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
28RISK
open
GitHub PoC152
Poc for CVE-2019-1253
CVE-2019-1253HIGHunder attackransomware11 Sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISK
open
GitHub PoC1
CVE-2019-0708 C#验证漏洞
CVE-2019-0708CRITICALunder attackransomware11 Sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
likekabin/CVE-2019-1253
CVE-2019-1253HIGHunder attackransomware11 Sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISK
open
GitHub PoC19
AppXSvc Arbitrary File Security Descriptor Overwrite EoP
CVE-2019-1253HIGHunder attackransomware11 Sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware11 Sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
distance-vector/CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware11 Sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
local
CVE-2019-1253HIGHunder attackransomware11 Sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISK
open
VulnCheck XDB
local
CVE-2019-1253HIGHunder attackransomware11 Sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISK
open
Exploit-DB
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting
CVE-2019-16117webappsphp10 Sep 2019
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi
23RISK
open
Exploit-DB
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting (2)
CVE-2019-16118webappsphp10 Sep 2019
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi
23RISK
open
VulnCheck XDB
initial-access
CVE-2019-1579HIGHunder attackransomware10 Sep 2019
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RISK
open
VulnCheck XDB
local
CVE-2019-1609810 Sep 2019
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user t
28RISK
open
Exploit-DB
WordPress Plugin Photo Gallery 1.5.34 - SQL Injection
CVE-2019-16119webappsphp10 Sep 2019
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/control
28RISK
open
previouspage 816 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.