Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,596cataloged exploits
36,656CVEs with public exploitation
24,695lab-tested
79,305 exploits
Exploit-DBVexDay Proof
macOS / iOS JavaScriptCore - Loop-Invariant Code Motion (LICM) Leaves Object Property Access Unguarded
CVE-2019-8671dosmultiple30 Jul 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS M
23RISK
open
Exploit-DBVexDay Proof
macOS / iOS JavaScriptCore - JSValue Use-After-Free in ValueProfiles
CVE-2019-8672dosmultiple30 Jul 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS M
28RISK
open
Metasploit600
Nagios XI Prior to 5.6.6 getprofile.sh Authenticated Remote Command Execution
CVE-2019-15949HIGHunder attack29 Jul 2019
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RISK
open
Exploit-DBVexDay Proof
Schneider Electric Pelco Endura NET55XX Encoder - Authentication Bypass (Metasploit)
CVE-2019-6814remoteunix29 Jul 2019
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 wh
50RISK
open
GitHub PoC1
quandqn/cve-2018-14667
CVE-2018-14667CRITICALunder attack29 Jul 2019
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISK
open
Exploit-DB
WordPress Plugin Simple Membership 3.8.4 - Cross-Site Request Forgery
CVE-2019-14328webappsphp29 Jul 2019
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
23RISK
open
GitHub PoC4
infiniteLoopers/CVE-2019-2107
CVE-2019-210727 Jul 2019
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RISK
open
GitHub PoC39
Some debug notes and exploit(not blind)
CVE-2019-7238CRITICALunder attack26 Jul 2019
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISK
open
Exploit-DBVexDay Proof
pdfresurrect 0.15 - Buffer Overflow
CVE-2019-14267doslinux26 Jul 2019
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is misha
23RISK
open
GitHub PoC60
EoP POC for CVE-2019-1132
CVE-2019-1132HIGHunder attack26 Jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISK
open
Exploit-DB
Microsoft Windows 7 build 7601 (x86) - Local Privilege Escalation
CVE-2019-1132HIGHunder attacklocalwindows_x8626 Jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISK
open
VulnCheck XDB
initial-access
CVE-2019-7238CRITICALunder attack26 Jul 2019
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISK
open
Exploit-DB
Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection
CVE-2019-10266webappsjsp26 Jul 2019
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL
28RISK
open
Exploit-DB
Ahsay Backup 7.x - 8.1.1.50 - Authenticated Arbitrary File Upload / Remote Code Execution (Metasploit)
CVE-2019-10267webappsjsp26 Jul 2019
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RISK
open
Exploit-DBVexDay Proof
Ahsay Backup 8.1.1.50 - Insecure File Upload and Code Execution (Authenticated)
CVE-2019-10267webappsjsp26 Jul 2019
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RISK
open
VulnCheck XDB
local
CVE-2019-1132HIGHunder attack26 Jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISK
open
Exploit-DB
Moodle Filepicker 3.5.2 - Server Side Request Forgery
CVE-2018-1042webappsphp26 Jul 2019
Moodle 3.x has Server Side Request Forgery in the filepicker.
28RISK
open
VulnCheck XDB
initial-access
CVE-2019-11581CRITICALunder attack25 Jul 2019
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISK
open
GitHub PoC1
收集网上CVE-2018-0708的poc和exp(目前没有找到exp)
CVE-2018-070825 Jul 2019
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RISK
open
GitHub PoC10
CVE-2019–11581 PoC
CVE-2019-11581CRITICALunder attack25 Jul 2019
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISK
open
Exploit-DB
Ovidentia 8.4.3 - Cross-Site Scripting
CVE-2019-13977webappsphp25 Jul 2019
index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=crea
23RISK
open
GitHub PoC1
收集网上CVE-2018-0708的poc和exp(目前没有找到exp)
CVE-2019-0708CRITICALunder attackransomware25 Jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC14
POC for CVE-2019-14339 Canon PRINT 2.5.5
CVE-2019-1433925 Jul 2019
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly res
23RISK
open
Exploit-DBVexDay Proof
WebKit - Universal Cross-Site Scripting due to Synchronous Page Loads
CVE-2019-8649dosmultiple25 Jul 2019
A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management
23RISK
open
GitHub PoC3
Exim Honey Pot for CVE-2019-10149 exploit attempts.
CVE-2019-10149CRITICALunder attack25 Jul 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
Exploit-DBVexDay Proof
Apple iMessage - DigitalTouch tap Message Processing Out-of-Bounds Read
CVE-2019-8624doswatchos24 Jul 2019
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacke
23RISK
open
Exploit-DB
Linux Kernel 4.10 < 5.1.17 - 'PTRACE_TRACEME' pkexec Local Privilege Escalation
CVE-2019-13272HIGHunder attacklocallinux24 Jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
Exploit-DB
Android 7 < 9 - Remote Code Execution
CVE-2019-2107remoteandroid24 Jul 2019
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RISK
open
Exploit-DB
Cisco Wireless Controller 3.6.10E - Cross-Site Request Forgery
CVE-2019-12624HIGHwebappshardware24 Jul 2019
Cisco IOS XE NGWC Legacy Wireless Device Manager GUI Cross-Site Request Forgery Vulnerability
46RISK
open
GitHub PoC6
cve-2016-6187
CVE-2016-618723 Jul 2019
The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buff
23RISK
open
previouspage 824 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.