Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
14,014 exploits
GitHub PoC7
zhusx110/cve-2019-2725
CVE-2019-2725HIGHunder attackransomware10 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC1
Docker runc CVE-2019-5736 exploit Dockerfile. Credits : https://github.com/Frichetten/CVE-2019-5736-PoC.git
CVE-2019-573609 May 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC
sasqwatch/CVE-2017-8570
CVE-2017-8570HIGHunder attack08 May 2019
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISK
open
GitHub PoC79
Zimbra邮件系统漏洞 XXE/RCE/SSRF/Upload GetShell Exploit 1. (CVE-2019-9621 Zimbra<8.8.11 XXE GetShell Exploit)
CVE-2019-9621HIGHunder attack06 May 2019
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RISK
open
GitHub PoC
cve-2019-9978
CVE-2019-9978MEDIUMunder attack06 May 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC1
cve-2019-10678
CVE-2019-1067806 May 2019
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
28RISK
open
GitHub PoC6
Wordpress Social Warfare Remote Code Execution (AUTO UPLOAD SHELL)
CVE-2019-9978MEDIUMunder attack06 May 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC227
Exploit for CVE-2019-9810 Firefox on Windows 64-bit.
CVE-2019-981005 May 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISK
open
GitHub PoC2
leerina/CVE-2019-2725
CVE-2019-2725HIGHunder attackransomware05 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC2
A proof of concept for ReadyAPI 2.5.0/2.6.0 Remote Code Execution Vulnerability.
CVE-2018-2058003 May 2019
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co
23RISK
open
GitHub PoC22
CVE-2019-9978 - (PoC) RCE in Social WarFare Plugin (<=3.5.2)
CVE-2019-9978MEDIUMunder attack03 May 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC1
davidmthomsen/CVE-2019-2725
CVE-2019-2725HIGHunder attackransomware02 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC4
WordPress crop-image exploitation
CVE-2019-894202 May 2019
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISK
open
GitHub PoC21
lasensio/cve-2019-2725
CVE-2019-2725HIGHunder attackransomware01 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC1
PoC command injection example for cve-2018-1002105 based off https://github.com/gravitational/cve-2018-1002105
CVE-2018-1002105CRITICAL30 Apr 2019
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISK
open
GitHub PoC58
Spring Data Commons RCE 远程命令执行漏洞
CVE-2018-1273CRITICALunder attackransomware29 Apr 2019
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISK
open
GitHub PoC
Confluence Widget Connector path traversal (CVE-2019-3396)
CVE-2019-3396CRITICALunder attackransomware28 Apr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC
An intentionally vulnerable (CVE-2017-8046) SrpingData REST appl with Swagger Support for pentesting purposes
CVE-2017-804627 Apr 2019
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISK
open
GitHub PoC
shawntns/exploit-CVE-2014-6271
CVE-2014-6271CRITICALunder attack27 Apr 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
likekabin/CVE-2018-20250
CVE-2018-20250HIGHunder attackransomware25 Apr 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC105
CVE-2019-2725poc汇总 更新绕过CVE-2017-10271补丁POC
CVE-2019-2725HIGHunder attackransomware25 Apr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC9
The official exploit code for LibreNMS v1.46 Remote Code Execution CVE-2018-20434
CVE-2018-2043425 Apr 2019
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to htm
60RISK
open
GitHub PoC105
CVE-2019-2725poc汇总 更新绕过CVE-2017-10271补丁POC
CVE-2017-10271HIGHunder attackransomware25 Apr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC114
WebLogic CNVD-C-2019_48814 CVE-2017-10271 Scan By 7kbstorm
CVE-2017-10271HIGHunder attackransomware25 Apr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC1
WebLogic CNVD-C-2019_48814 CVE-2017-10271
CVE-2017-10271HIGHunder attackransomware25 Apr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC4
A C# module to detect if a Jenkins server is vulnerable to the RCE vulnerability found in CVE-2019-1003000 (chained with CVE-2018-1000861 for pre-auth RCE)
CVE-2018-1000861CRITICALunder attack24 Apr 2019
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISK
open
GitHub PoC
KeyStrOke95/nfsen_1.3.7_CVE-2017-6971
CVE-2017-697124 Apr 2019
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
28RISK
open
GitHub PoC4
A C# module to detect if a Jenkins server is vulnerable to the RCE vulnerability found in CVE-2019-1003000 (chained with CVE-2018-1000861 for pre-auth RCE)
CVE-2019-100300024 Apr 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
GitHub PoC1
rakesh143/CVE-2019-0808
CVE-2019-0808HIGHunder attack21 Apr 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
GitHub PoC
cve-2017-17485 PoC
CVE-2017-17485CRITICAL21 Apr 2019
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o
60RISK
open
previouspage 426 / 468next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.