Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,230 exploits
VulnCheck XDB
initial-access
CVE-2019-19781CRITICALunder attackransomware11 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALunder attackransomware11 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALunder attackransomware11 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-19781CRITICALunder attackransomware11 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-19781CRITICALunder attackransomware11 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALunder attackransomware11 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-19781CRITICALunder attackransomware11 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-19781CRITICALunder attackransomware10 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
Exploit-DBVexDay Proof
TotalAV 2020 4.14.31 - Privilege Escalation
CVE-2019-18194localwindows10 Jan 2020
TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junctio
23RISK
open
GitHub PoC367
Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [ CVE-2019-19781 ]
CVE-2019-19781CRITICALunder attackransomware10 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC24
CVE-2019-7238 Nexus RCE漏洞图形化一键检测工具。CVE-2019-7238 Nexus RCE Vul POC Tool.
CVE-2019-7238CRITICALunder attack10 Jan 2020
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISK
open
Exploit-DB
PixelStor 5000 K:4.0.1580-20150629 - Remote Code Execution
CVE-2020-6756CRITICALwebappsphp10 Jan 2020
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to re
53RISK
open
Exploit-DB
Oracle Weblogic 10.3.6.0.0 - Remote Command Execution
CVE-2019-2729CRITICALwebappsjava09 Jan 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISK
open
GitHub PoC7
Exploit code for CVE-2019-2729
CVE-2019-2729CRITICAL09 Jan 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-2729CRITICAL09 Jan 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISK
open
GitHub PoC2
Simple Overflow demo, like CVE-2017-11882 exp
CVE-2017-11882HIGHunder attackransomware08 Jan 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC
geropl/CVE-2019-5736
CVE-2019-573608 Jan 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
Exploit-DB
EBBISLAND EBBSHAVE 6100-09-04-1441 - Remote Buffer Overflow
CVE-2017-3623remotehardware08 Jan 2020
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported ve
28RISK
open
VulnCheck XDB
initial-access
CVE-2019-2725HIGHunder attackransomware08 Jan 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
Exploit-DBVexDay Proof
JetBrains TeamCity 2018.2.4 - Remote Code Execution
CVE-2019-15039remotejava08 Jan 2020
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in
28RISK
open
Exploit-DB
Cisco DCNM JBoss 10.4 - Credential Leakage
CVE-2019-15999MEDIUMremotejava08 Jan 2020
Cisco Data Center Network Manager JBoss EAP Unauthorized Access Vulnerability
33RISK
open
GitHub PoC2
weblogic CVE-2019-2725利用exp。
CVE-2019-2725HIGHunder attackransomware08 Jan 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
Exploit-DBVexDay Proof
piSignage 2.6.4 - Directory Traversal
CVE-2019-20354webappshardware07 Jan 2020
The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user)
23RISK
open
Exploit-DB
Microsoft Windows 10 (19H1 1901 x64) - 'ws2ifsl.sys' Use After Free Local Privilege Escalation (kASLR kCFG SMEP)
CVE-2019-1215HIGHunder attackransomwarelocalwindows_x86-6407 Jan 2020
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Win
76RISK
open
Metasploit300
"Cablehaunt" Cable Modem WebSocket DoS
CVE-2019-1949407 Jan 2020
Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker
23RISK
open
GitHub PoC1
Any3ite/CVE-2014-6271
CVE-2014-6271CRITICALunder attack06 Jan 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC149
bluefrostsecurity/CVE-2019-1215
CVE-2019-1215HIGHunder attackransomware06 Jan 2020
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Win
76RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack06 Jan 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
local
CVE-2019-1215HIGHunder attackransomware06 Jan 2020
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Win
76RISK
open
GitHub PoC
CVE-2017-9841 detector script
CVE-2017-9841CRITICALunder attack06 Jan 2020
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
previouspage 798 / 2,641next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.