Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
14,014 exploits
GitHub PoC28
patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428
CVE-2019-1135830 Mar 2019
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISK
open
GitHub PoC3
IBM Lotus Domino <= R8 Password Hash Extraction Exploit
CVE-2005-242829 Mar 2019
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hid
60RISK
open
GitHub PoC23
ASUS SmartHome Exploit for CVE-2019-11061 and CVE-2019-11063
CVE-2019-11061CRITICAL29 Mar 2019
HG100 has a broken access control vulnerability in its Web API Server
48RISK
open
GitHub PoC
stillan00b/CVE-2019-5736
CVE-2019-573627 Mar 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC
cve-2016-9838
CVE-2016-983827 Mar 2019
An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of
28RISK
open
GitHub PoC
cve-2019-5420
CVE-2019-542027 Mar 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
GitHub PoC8
CVE-2019-9978 - RCE on a Wordpress plugin: Social Warfare < 3.5.3
CVE-2019-9978MEDIUMunder attack25 Mar 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC47
cve-2019-0808-poc
CVE-2019-0808HIGHunder attack25 Mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
GitHub PoC67
Array.prototype.slice wrong alias information.
CVE-2019-981025 Mar 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISK
open
GitHub PoC1
CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware24 Mar 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC129
CVE-2019-0604
CVE-2019-0604CRITICALunder attackransomware23 Mar 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISK
open
GitHub PoC133
RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)
CVE-2019-5418HIGHunder attack23 Mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC
PoC Scan. (cve-2011-3368)
CVE-2011-336822 Mar 2019
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does
60RISK
open
GitHub PoC
CVE-2017-5638 (PoC Exploits)
CVE-2017-5638CRITICALunder attackransomware22 Mar 2019
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC8
CVE-2019-5420 (Ruby on Rails)
CVE-2019-542021 Mar 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
GitHub PoC6
CVE-2018-11686 - FlexPaper PHP Publish Service RCE <= 2.3.6
CVE-2018-1168620 Mar 2019
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_c
50RISK
open
GitHub PoC14
GUI版 EXP
CVE-2018-133520 Mar 2019
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
GitHub PoC254
FileReader Exploit
CVE-2019-5786MEDIUMunder attack20 Mar 2019
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISK
open
GitHub PoC4
POC for CVE-2017-10271. Since java.lang.ProcessBuilder was the original vector for RCE, there are multiple signature based rules that block this particular payload. Added java.lang.Runtime and will add others in the future. This is for educational purposes only: I take no responsibility for how you use this code.
CVE-2017-10271HIGHunder attackransomware20 Mar 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC
Herramienta para revisar si es que un payload tiene componente malicioso de acuerdo a CVE-2018-20250
CVE-2018-20250HIGHunder attackransomware19 Mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC36
A multi-threaded Golang scanner to identify Ruby endpoints vulnerable to CVE-2019-5418
CVE-2019-5418HIGHunder attack19 Mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC5
File Content Disclosure on Rails Test Case - CVE-2019-5418
CVE-2019-5418HIGHunder attack18 Mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC7
xConsoIe/CVE-2019-0193
CVE-2019-0193HIGHunder attack18 Mar 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISK
open
GitHub PoC6
thinkphp5.*Rce CVE-2018-20062
CVE-2018-20062CRITICALunder attack17 Mar 2019
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISK
open
GitHub PoC201
CVE-2019-5418 - File Content Disclosure on Ruby on Rails
CVE-2019-5418HIGHunder attack16 Mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC
cve-2018-16283
CVE-2018-1628315 Mar 2019
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
50RISK
open
GitHub PoC
cve-2019-9194
CVE-2019-919415 Mar 2019
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open
GitHub PoC
cve-2019-9184
CVE-2019-918415 Mar 2019
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr
23RISK
open
GitHub PoC10
Noodle [Moodle RCE] (v3.4.1) - CVE-2018-1133
CVE-2018-113315 Mar 2019
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec
35RISK
open
GitHub PoC1
原创作者:Bearcat@secfree.com
CVE-2017-10271HIGHunder attackransomware15 Mar 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
previouspage 428 / 468next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.