Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,230 exploits
Exploit-DB
eMerge E3 1.00-06 - Unauthenticated Directory Traversal
CVE-2019-7254webappshardware12 Nov 2019
Linear eMerge E3-Series devices allow File Inclusion.
60RISK
open
Exploit-DB
Atlassian Confluence 6.15.1 - Directory Traversal
CVE-2019-3398HIGHunder attackwebappsjsp12 Nov 2019
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-0708CRITICALunder attackransomware12 Nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DB
FlexAir Access Control 2.3.35 - Authentication Bypass
CVE-2019-7666webappshardware12 Nov 2019
Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash valu
28RISK
open
Exploit-DB
Adrenalin Core HCM 5.4.0 - 'ReportID' Reflected Cross-Site Scripting
CVE-2018-12653webappsaspx12 Nov 2019
A Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0. An attacker can input malicious Jav
23RISK
open
GitHub PoC19
Suricata LUA scripts to detect CVE-2019-12255, CVE-2019-12256, CVE-2019-12258, and CVE-2019-12260
CVE-2019-1225512 Nov 2019
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TC
45RISK
open
Exploit-DB
Adrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site Scripting
CVE-2018-12234webappsaspx12 Nov 2019
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied
23RISK
open
Exploit-DB
Optergy 2.3.0a - Remote Code Execution (Backdoor)
CVE-2019-7276webappshardware12 Nov 2019
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RISK
open
Exploit-DB
eMerge E3 1.00-06 - Remote Code Execution
CVE-2019-7256CRITICALunder attackwebappshardware12 Nov 2019
Linear eMerge E3-Series devices allow Command Injections.
100RISK
open
GitHub PoC1
load-scripts.php file, which purpose is to retrieve several JavaScript packages through one single request.
CVE-2018-638911 Nov 2019
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC16
Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix)
CVE-2019-11043HIGHunder attackransomware11 Nov 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8641dosmultiple11 Nov 2019
An out-of-bounds read was addressed with improved input validation.
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed OTF Font (CFF Table)
CVE-2019-8196doswindows11 Nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISK
open
GitHub PoC
cve-2019-14287
CVE-2019-1428711 Nov 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
VulnCheck XDB
infoleak
CVE-2019-11043HIGHunder attackransomware11 Nov 2019
Underflow in PHP-FPM can lead to RCE
100RISK
open
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8662dosmultiple11 Nov 2019
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
CVE-2019-8195doswindows11 Nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISK
open
GitHub PoC13
The official exploit for rConfig 3.9.2 Pre-auth Remote Code Execution CVE-2019-16662
CVE-2019-1666210 Nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-1666210 Nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISK
open
VulnCheck XDB
local
CVE-2022-21882HIGHunder attackransomware10 Nov 2019
Win32k Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC8
A standalone POC for CVE-2019-12840
CVE-2019-1284009 Nov 2019
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISK
open
Exploit-DB
Jenkins build-metrics plugin 1.3 - 'label' Cross-Site Scripting
CVE-2019-10475webappsjava08 Nov 2019
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RISK
open
GitHub PoC1
Centreon v.19.04 Remote Code Execution exploit (CVE-2019-13024)
CVE-2019-1302408 Nov 2019
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitra
35RISK
open
Exploit-DBVexDay Proof
Android Janus - APK Signature Bypass (Metasploit)
CVE-2017-13156localandroid08 Nov 2019
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISK
open
Exploit-DB
Adive Framework 2.0.7 - Privilege Escalation
CVE-2019-14347webappsphp08 Nov 2019
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an ad
23RISK
open
Exploit-DBVexDay Proof
rConfig - install Command Execution (Metasploit)
CVE-2019-16662remotelinux08 Nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISK
open
VulnCheck XDB
infoleak
CVE-2018-14847CRITICALunder attack08 Nov 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
GitHub PoC10
Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation
CVE-2017-1263507 Nov 2019
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISK
open
GitHub PoC1
phongld97/detect-cve-2018-16858
CVE-2018-16858HIGH07 Nov 2019
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RISK
open
GitHub PoC
create12138/CVE-2018-15982
CVE-2018-15982HIGHunder attackransomware06 Nov 2019
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISK
open
previouspage 805 / 2,641next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.