Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
MikroTik RouterOS < 6.43.12 (stable) / < 6.42.12 (long-term) - Firewall and NAT Bypass
CVE-2019-3924remotehardware21 Feb 2019
MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The so
28RISK
open
Exploit-DBVexDay Proof
FaceTime - Texture Processing Memory Corruption
CVE-2019-6224dosmacos20 Feb 2019
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.
23RISK
open
Exploit-DBVexDay Proof
Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution (PoC)
CVE-2019-1003001webappsjava19 Feb 2019
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RISK
open
Exploit-DBVexDay Proof
Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution (PoC)
CVE-2019-1003002webappsjava19 Feb 2019
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RISK
open
Exploit-DBVexDay Proof
Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution (PoC)
CVE-2019-1003000webappsjava19 Feb 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
Exploit-DBVexDay Proof
Linux - 'kvm_ioctl_create_device()' NULL Pointer Dereference
CVE-2019-6974doslinux15 Feb 2019
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because
28RISK
open
Exploit-DBVexDay Proof
DomainMOD 4.11.01 - 'assets/edit/host.php?whid=5' Cross-Site Scripting
CVE-2018-19915webappsphp14 Feb 2019
DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.
38RISK
open
Exploit-DBVexDay Proof
DomainMOD 4.11.01 - 'assets/add/dns.php' Cross-Site Scripting
CVE-2018-19914webappsphp14 Feb 2019
DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.
38RISK
open
Exploit-DBVexDay Proof
DomainMOD 4.11.01 - 'ssl-provider-name' Cross-Site Scripting
CVE-2018-20009webappsphp14 Feb 2019
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.
38RISK
open
Exploit-DBVexDay Proof
DomainMOD 4.11.01 - 'category.php CatagoryName_ StakeHolder' Cross-Site Scripting
CVE-2018-20011webappsphp14 Feb 2019
DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.
38RISK
open
Exploit-DBVexDay Proof
DomainMOD 4.11.01 - 'ssl-accounts.php username' Cross-Site Scripting
CVE-2018-20010webappsphp14 Feb 2019
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.
38RISK
open
Exploit-DBVexDay Proof
BlogEngine.NET 3.3.6 - Directory Traversal / Remote Code Execution
CVE-2019-6714webappsaspx12 Feb 2019
An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in Po
28RISK
open
Exploit-DBVexDay Proof
Android - binder Use-After-Free via fdget() Optimization
CVE-2019-2000dosandroid12 Feb 2019
In several functions of binder.c, there is possible memory corruption due to a use after free. This could lead to local
23RISK
open
Exploit-DBVexDay Proof
Android - binder Use-After-Free of VMA via race Between reclaim and munmap
CVE-2019-1999dosandroid12 Feb 2019
In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to
23RISK
open
Exploit-DBVexDay Proof
NUUO NVRmini - upgrade_handle.php Remote Command Execution (Metasploit)
CVE-2018-14933CRITICALunder attackremotephp11 Feb 2019
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
100RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player - DeleteRangeTimelineOperation Type Confusion (Metasploit)
CVE-2016-4117HIGHunder attackremoteosx11 Feb 2019
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as
100RISK
open
Exploit-DBVexDay Proof
Evince - CBT File Command Injection (Metasploit)
CVE-2017-1000083locallinux11 Feb 2019
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RISK
open
Exploit-DBVexDay Proof
macOS XNU - Copy-on-Write Behaviour Bypass via Partial-Page Truncation of File
CVE-2019-6208dosmacos31 Jan 2019
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Moja
23RISK
open
Exploit-DBVexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 XNU - 'vm_map_copy' Optimization which Requires Atomicity isn't Atomic
CVE-2019-6205dosmultiple31 Jan 2019
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Moja
23RISK
open
Exploit-DBVexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Sandbox Escapes due to Type Confusions and Memory Safety Issues in iohideventsystem
CVE-2019-6214dosmultiple31 Jan 2019
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.1
23RISK
open
Exploit-DBVexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Arbitrary mach Port Name Deallocation in XPC Services due to Invalid mach Message Parsing in _xpc_serializer_unpack
CVE-2019-6218dosmultiple31 Jan 2019
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave
28RISK
open
Exploit-DBVexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Kernel Heap Overflow in PF_KEY due to Lack of Bounds Checking when Retrieving Statistics
CVE-2019-6213dosmultiple31 Jan 2019
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3,
28RISK
open
Exploit-DBVexDay Proof
iOS/macOS 10.13.6 - 'if_ports_used_update_wakeuuid()' 16-byte Uninitialized Kernel Stack Disclosure
CVE-2019-6209dosmultiple30 Jan 2019
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input
23RISK
open
Exploit-DBVexDay Proof
Cisco Firepower Management Center 6.2.2.2 / 6.2.3 - Cross-Site Scripting
CVE-2019-1642MEDIUMwebappshardware28 Jan 2019
Cisco Firepower Management Center Cross-Site Scripting Vulnerability
33RISK
open
Exploit-DBVexDay Proof
Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection
CVE-2019-1652HIGHunder attackwebappshardware25 Jan 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RISK
open
Exploit-DBVexDay Proof
iOS/macOS - 'task_swap_mach_voucher()' Use-After-Free
CVE-2019-6225dosmultiple25 Jan 2019
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RISK
open
Exploit-DBVexDay Proof
Ghostscript 9.26 - Pseudo-Operator Remote Code Execution
CVE-2019-6116remotelinux24 Jan 2019
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'NewScObjectNoCtor' or 'InitProto' Type Confusion
CVE-2019-0567doswindows18 Jan 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JsBuiltInEngineInterfaceExtensionObject::InjectJsBuiltInLibraryCode' Use-After-Free
CVE-2019-0568doswindows18 Jan 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'InlineArrayPush' Type Confusion
CVE-2018-8617doswindows18 Jan 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.