Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,230 exploits
VulnCheck XDB
initial-access
CVE-2019-10758CRITICALunder attack05 Jan 2020
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse
100RISK
open
GitHub PoC5
CVE-2019-10758
CVE-2019-10758CRITICALunder attack05 Jan 2020
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse
100RISK
open
VulnCheck XDB
client-side
CVE-2017-8759HIGHunder attack02 Jan 2020
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
Exploit-DB
Microsoft Windows - Shell COM Server Registrar Local Privilege Escalation
CVE-2019-1184MEDIUMlocalwindows02 Jan 2020
Windows Elevation of Privilege Vulnerability
55RISK
open
GitHub PoC
CVE-2017-8759 use file
CVE-2017-8759HIGHunder attack02 Jan 2020
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware02 Jan 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack01 Jan 2020
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC
CVE-2019-16278:Nostromo Web服务器的RCE漏洞
CVE-2019-16278CRITICALunder attack01 Jan 2020
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
Exploit-DBVexDay Proof
nostromo 1.9.6 - Remote Code Execution
CVE-2019-16278CRITICALunder attackremotemultiple01 Jan 2020
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC1
(Nhttpd) Nostromo 1.9.6 RCE due to Directory Traversal
CVE-2019-16278CRITICALunder attack31 Dec 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack31 Dec 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
Exploit-DB
Sony Playstation 4 (PS4) < 6.72 - WebKit Code Execution (PoC)
CVE-2018-4386webappshardware31 Dec 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISK
open
Exploit-DBVexDay Proof
Microsoft UPnP - Local Privilege Elevation (Metasploit)
CVE-2019-1405HIGHunder attackransomwarelocalwindows30 Dec 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISK
open
GitHub PoC
samba 4.5.9
CVE-2017-7494CRITICALunder attackransomware30 Dec 2019
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
Exploit-DBVexDay Proof
OpenBSD - Dynamic Loader chpass Privilege Escalation (Metasploit)
CVE-2019-19726localopenbsd30 Dec 2019
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RISK
open
Exploit-DBVexDay Proof
FreeBSD-SA-19:02.fd - Privilege Escalation
CVE-2019-5596localfreebsd30 Dec 2019
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RISK
open
Exploit-DBVexDay Proof
Microsoft UPnP - Local Privilege Elevation (Metasploit)
CVE-2019-1322HIGHunder attackransomwarelocalwindows30 Dec 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RISK
open
VulnCheck XDB
initial-access
CVE-2019-16759CRITICALunder attack29 Dec 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
GitHub PoC4
Identify vulnerable (RCE) vBulletin 5.0.0 - 5.5.4 instances using Shodan (CVE-2019-16759)
CVE-2019-16759CRITICALunder attack29 Dec 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
GitHub PoC
webmin_CVE-2019-15107
CVE-2019-15107CRITICALunder attackransomware29 Dec 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALunder attack27 Dec 2019
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
GitHub PoC
HttpFileServer httpd 2.3
CVE-2014-6287CRITICALunder attack27 Dec 2019
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
GitHub PoC5
CVE-2018-8639-EXP
CVE-2018-8639HIGHunder attackransomware27 Dec 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RISK
open
VulnCheck XDB
local
CVE-2019-10758CRITICALunder attack26 Dec 2019
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse
100RISK
open
GitHub PoC111
masahiro331/CVE-2019-10758
CVE-2019-10758CRITICALunder attack26 Dec 2019
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse
100RISK
open
GitHub PoC78
Apache Log4j 1.2.X存在反序列化远程代码执行漏洞
CVE-2019-17571CRITICAL25 Dec 2019
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be explo
60RISK
open
GitHub PoC8
poc exploit for webmin backdoor (CVE-2019-15107 and CVE-2019-15231)
CVE-2019-15107CRITICALunder attackransomware25 Dec 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-15107CRITICALunder attackransomware25 Dec 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC8
PoC for CVE-2019-19844 ( https://www.djangoproject.com/weblog/2019/dec/18/security-releases/ )
CVE-2019-1984425 Dec 2019
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RISK
open
Exploit-DBVexDay Proof
Django < 3.0 < 2.2 < 1.11 - Account Hijack
CVE-2019-19844webappspython24 Dec 2019
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RISK
open
previouspage 799 / 2,641next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.