Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,570cataloged exploits
34,981CVEs with public exploitation
24,695lab-tested
13,960 exploits
GitHub PoC3
OpenSSH Username Enumeration - CVE-2016-6210
CVE-2016-6210MEDIUM25 Aug 2019
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISK
open
GitHub PoC11
A collection of tools for the Janus exploit [CVE-2017-13156].
CVE-2017-1315625 Aug 2019
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISK
open
GitHub PoC8
The official exploit code for FusionPBX v4.4.8 Remote Code Execution CVE-2019-15029
CVE-2019-1502924 Aug 2019
FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service
28RISK
open
GitHub PoC11
The official exploit code for Centreon v19.04 Remote Code Execution CVE-2019-13024
CVE-2019-1302424 Aug 2019
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitra
35RISK
open
GitHub PoC52
WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit
CVE-2019-2725HIGHunder attackransomware23 Aug 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC5
CVE-2019-15107 webmin python3
CVE-2019-15107CRITICALunder attackransomware23 Aug 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC
Implementation of CVE-2019-15107 exploit in python
CVE-2019-15107CRITICALunder attackransomware22 Aug 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC2
Dockerfiles for CVE-2019-15107(webmin RCE) recurrence including v1.890 and v1.920 with Exp for each version.
CVE-2019-15107CRITICALunder attackransomware22 Aug 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC13
Jboss Java Deserialization RCE (CVE-2017-12149)
CVE-2017-12149CRITICALunder attackransomware22 Aug 2019
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
GitHub PoC50
Pulse Secure SSL VPN pre-auth file reading
CVE-2019-11510CRITICALunder attackransomware22 Aug 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open
GitHub PoC360
Exploit for Arbitrary File Read on Pulse Secure SSL VPN (CVE-2019-11510)
CVE-2019-11510CRITICALunder attackransomware21 Aug 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open
GitHub PoC
Pulse Secure VPN CVE-2019-11510
CVE-2019-11510CRITICALunder attackransomware21 Aug 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open
GitHub PoC
CVE-2019-3396 漏洞验证txt与模板文件。
CVE-2019-3396CRITICALunder attackransomware21 Aug 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC66
CVE-2019-15107 Webmin RCE (unauthorized)
CVE-2019-15107CRITICALunder attackransomware19 Aug 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC42
Exploit code for CVE-2019-11707 on Firefox 66.0.3 running on Ubuntu
CVE-2019-11707HIGHunder attack18 Aug 2019
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RISK
open
GitHub PoC4
Research Regarding CVE-2019-0708.
CVE-2019-0708CRITICALunder attackransomware18 Aug 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC5
Fortigate CVE-2018-13379 - Tool to search for vulnerable Fortigate hosts in Rapid7 Project Sonar data anonymously through The Tor network.
CVE-2018-13379CRITICALunder attackransomware18 Aug 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
GitHub PoC122
rce exploit , made to work with pocsuite3
CVE-2019-0708CRITICALunder attackransomware17 Aug 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
used to generate a valid attack chain to exploit CVE-2017-11774 tied to iranian apt only reasearch poc dont use for harm please
CVE-2017-11774HIGHunder attack16 Aug 2019
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary command
83RISK
open
GitHub PoC5
Scan a list of given IP's for CVE-2017-12542
CVE-2017-1254216 Aug 2019
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISK
open
GitHub PoC1
Zimbra RCE CVE-2019-9670
CVE-2019-9670CRITICALunder attack16 Aug 2019
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open
GitHub PoC27
Zimbra RCE PoC - CVE-2019-9670 XXE/SSRF
CVE-2019-9670CRITICALunder attack16 Aug 2019
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open
GitHub PoC
Demo app of THAT data broker's security breach
CVE-2017-5638CRITICALunder attackransomware15 Aug 2019
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
Simple Python script for D-Link vulnerability scan and test [CVE-2019-13101]
CVE-2019-1310115 Aug 2019
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without
50RISK
open
GitHub PoC
major203/cve-2019-1181
CVE-2019-1181CRITICAL14 Aug 2019
Remote Desktop Services Remote Code Execution Vulnerability
70RISK
open
GitHub PoC1
CVE-2017-16995 ubuntun本地提权 POC
CVE-2017-1699514 Aug 2019
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
GitHub PoC5
CVE-2017-11882(通杀Office 2003到2016)
CVE-2017-11882HIGHunder attackransomware14 Aug 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC7
Linux 本地提权漏洞
CVE-2016-5195HIGHunder attack13 Aug 2019
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
OpenEMR security issue
CVE-2019-1453013 Aug 2019
An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can
50RISK
open
GitHub PoC65
Apache Solr远程代码执行漏洞(CVE-2019-0193) Exploit
CVE-2019-0193HIGHunder attack12 Aug 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISK
open
previouspage 417 / 466next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.