Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
14,014 exploits
GitHub PoC
cve-2018-16283
CVE-2018-1628315 Mar 2019
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
50RISK
open
GitHub PoC
Bits generated while analyzing CVE-2019-6340 Drupal RESTful RCE
CVE-2019-6340HIGHunder attack12 Mar 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
GitHub PoC
AeolusTF/CVE-2018-20250
CVE-2018-20250HIGHunder attackransomware11 Mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC16
CVE-2018-19276 - OpenMRS Insecure Object Deserialization RCE
CVE-2018-19276CRITICAL11 Mar 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISK
open
GitHub PoC7
CVE-2018-20250-WINRAR-ACE Exploit with a UI
CVE-2018-20250HIGHunder attackransomware08 Mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC209
A WebKit exploit using CVE-2018-4441 to obtain RCE on PS4 6.20.
CVE-2018-444108 Mar 2019
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1,
28RISK
open
GitHub PoC
Python CVE-2019-1003000 and CVE-2018-1999002 Pre-Auth RCE Jenkins
CVE-2018-199900206 Mar 2019
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewor
45RISK
open
GitHub PoC
Python CVE-2019-1003000 and CVE-2018-1999002 Pre-Auth RCE Jenkins
CVE-2019-100300006 Mar 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
GitHub PoC2
Python tool exploiting CVE-2018-20250 found by CheckPoint folks
CVE-2018-20250HIGHunder attackransomware05 Mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC126
ze0r/CVE-2018-8639-exp
CVE-2018-8639HIGHunder attackransomware05 Mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RISK
open
GitHub PoC1
WinRar is a very widely known software for windows. Previous version of WinRaR was a vulnerability which has been patched in Feb-2019. Most of the people didn't update winrar so they are vulnerable in this Absolute Path Traversal bug [CVE-2018-20250]
CVE-2018-20250HIGHunder attackransomware04 Mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC2
STP5940/CVE-2018-20250
CVE-2018-20250HIGHunder attackransomware28 Feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC
yyqs2008/CVE-2019-5736-PoC-2
CVE-2019-573628 Feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC2
Demonstration of the Heartbleed Bug CVE-2014-0160
CVE-2014-0160HIGHunder attack27 Feb 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
cve-2019-6340
CVE-2019-6340HIGHunder attack26 Feb 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
GitHub PoC2
CVE-2019-6340 Drupal 8.6.9 REST Auth Bypass examples
CVE-2019-6340HIGHunder attack25 Feb 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
GitHub PoC73
A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.
CVE-2019-894225 Feb 2019
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISK
open
GitHub PoC12
CVE-2019-6340 POC Drupal rce
CVE-2019-6340HIGHunder attack25 Feb 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
GitHub PoC153
🐱‍💻 Poc of CVE-2019-7238 - Nexus Repository Manager 3 Remote Code Execution 🐱‍💻
CVE-2019-7238CRITICALunder attack24 Feb 2019
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISK
open
GitHub PoC42
Environment for CVE-2019-6340 (Drupal)
CVE-2019-6340HIGHunder attack23 Feb 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
GitHub PoC21
Proof of concept code in C# to exploit the WinRAR ACE file extraction path (CVE-2018-20250).
CVE-2018-20250HIGHunder attackransomware23 Feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC30
CVE-2019-6340-Drupal SA-CORE-2019-003
CVE-2019-6340HIGHunder attack22 Feb 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
GitHub PoC
A version of the binary patched to address CVE-2018-20250
CVE-2018-20250HIGHunder attackransomware22 Feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC26
010 Editor template for ACE archive format & CVE-2018-2025[0-3]
CVE-2018-20250HIGHunder attackransomware22 Feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC492
exp for https://research.checkpoint.com/extracting-code-execution-from-winrar
CVE-2018-20250HIGHunder attackransomware22 Feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC
nmweizi/CVE-2018-20250-poc-winrar
CVE-2018-20250HIGHunder attackransomware22 Feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC1
CVE-2019-6249 Hucart cms 复现环境
CVE-2019-624921 Feb 2019
An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/inde
23RISK
open
GitHub PoC86
CVE-2019-5736 POCs
CVE-2019-573620 Feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC1
An app demo for test android webview security issue: CVE-2012-6636
CVE-2012-663619 Feb 2019
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta
50RISK
open
GitHub PoC1
b3d3c/poc-cve-2019-5736
CVE-2019-573619 Feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
previouspage 429 / 468next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.