Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC144
Cisco Exploit (CVE-2019-1821 Cisco Prime Infrastructure Remote Code Execution/CVE-2019-1653/Cisco SNMP RCE/Dump Cisco RV320 Password)
CVE-2019-1821HIGH21 May 2019
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RISK
open
Exploit-DB
WordPress Plugin WPGraphQL 0.2.3 - Multiple Vulnerabilities
CVE-2019-9881webappsphp21 May 2019
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on
43RISK
open
Exploit-DB
WordPress Plugin WPGraphQL 0.2.3 - Multiple Vulnerabilities
CVE-2019-9880webappsphp21 May 2019
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible,
50RISK
open
Exploit-DB
WordPress Plugin WPGraphQL 0.2.3 - Multiple Vulnerabilities
CVE-2019-9879webappsphp21 May 2019
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever
50RISK
open
Exploit-DBVexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 XNU - 'in6_pcbdetach' Stale Pointer Use-After-Free
CVE-2019-8605HIGHunder attackdosmultiple21 May 2019
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RISK
open
Exploit-DBVexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 JavaScriptCore - AIR Optimization Incorrectly Removes Assignment to Register
CVE-2019-8611dosmultiple21 May 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS M
23RISK
open
Exploit-DBVexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 JavaScriptCore - Loop-Invariant Code Motion (LICM) in DFG JIT Leaves Stack Variable Uninitialized
CVE-2019-8623dosmultiple21 May 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS M
23RISK
open
Exploit-DBVexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 DFG JIT Compiler - 'HasIndexedProperty' Use-After-Free
CVE-2019-8622dosmultiple21 May 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS M
23RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware21 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DBVexDay Proof
Brocade Network Advisor 14.4.1 - Unauthenticated Remote Code Execution
CVE-2018-6443webappsjava21 May 2019
A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log
23RISK
open
GitHub PoC1
Report fraud
CVE-2019-0708CRITICALunder attackransomware21 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DB
TP-LINK TL-WR840N v5 00000005 - Cross-Site Scripting
CVE-2019-12195webappshardware21 May 2019
TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking
23RISK
open
GitHub PoC2
Announces fraud
CVE-2019-0708CRITICALunder attackransomware20 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DB
Huawei eSpace 1.1.11.103 - 'ContactsCtrl.dll' / 'eSpaceStatusCtrl.dll' ActiveX Heap Overflow
CVE-2014-9418doswindows20 May 2019
The eSpace Meeting ActiveX control (eSpaceStatusCtrl.dll) in Huawei eSpace Desktop before V200R001C03 allows local users
23RISK
open
Exploit-DB
Huawei eSpace 1.1.11.103 - Image File Format Handling Buffer Overflow
CVE-2014-9417doswindows20 May 2019
The Meeting component in Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (progr
23RISK
open
Exploit-DB
Huawei eSpace Meeting 1.1.11.103 - 'cenwpoll.dll' SEH Buffer Overflow (Unicode)
CVE-2014-9415doswindows20 May 2019
Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted QE
23RISK
open
Exploit-DB
eLabFTW 1.8.5 - Arbitrary File Upload / Remote Code Execution
CVE-2019-12185webappsphp20 May 2019
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may
28RISK
open
Exploit-DB
Huawei eSpace 1.1.11.103 - DLL Hijacking
CVE-2014-9416localwindows20 May 2019
Multiple untrusted search path vulnerabilities in Huawei eSpace Desktop before V200R003C00 allow local users to execute
23RISK
open
GitHub PoC
falconz/CVE-2019-12189
CVE-2019-1218920 May 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
23RISK
open
Exploit-DBVexDay Proof
GetSimpleCMS - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-11231remotephp20 May 2019
An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows
60RISK
open
GitHub PoC1
leezp/CVE-2017-1000117
CVE-2017-100011720 May 2019
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RISK
open
GitHub PoC12
It's only hitting vulnerable path in termdd.sys!!! NOT DOS
CVE-2019-0708CRITICALunder attackransomware19 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware19 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
LOL
CVE-2019-0708CRITICALunder attackransomware18 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC7
eLabFTW 1.8.5 'EntityController' Arbitrary File Upload / RCE (CVE-2019-12185)
CVE-2019-1218518 May 2019
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may
28RISK
open
Exploit-DBVexDay Proof
Cisco Prime Infrastructure Health Monitor HA TarArchive - Directory Traversal / Remote Code Execution
CVE-2019-1821HIGHremotelinux17 May 2019
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RISK
open
GitHub PoC1
Win32k Elevation of Privilege Poc
CVE-2019-0803HIGHunder attackransomware17 May 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
83RISK
open
VulnCheck XDB
local
CVE-2019-0803HIGHunder attackransomware17 May 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
83RISK
open
Exploit-DB
Interspire Email Marketer 6.20 - 'surveys_submit.php' Remote Code Execution
CVE-2018-19550webappsphp17 May 2019
Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit
23RISK
open
VulnCheck XDB
local
CVE-2019-0808HIGHunder attack17 May 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
previouspage 835 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.