Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,230 exploits
VulnCheck XDB
initial-access
CVE-2017-950621 Oct 2019
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before
60RISK
open
Exploit-DB
Solaris 11.4 - xscreensaver Privilege Escalation
CVE-2019-3010HIGHunder attacklocalsolaris21 Oct 2019
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RISK
open
GitHub PoC56
RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer
CVE-2019-7609CRITICALunder attack21 Oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack21 Oct 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
VulnCheck XDB
infoleak
CVE-2018-376021 Oct 2019
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12
43RISK
open
GitHub PoC167
exploit CVE-2019-7609(kibana RCE) on right way by python2 scripts
CVE-2019-7609CRITICALunder attack21 Oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALunder attack21 Oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-7609CRITICALunder attack21 Oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
VulnCheck XDB
local
CVE-2019-10149CRITICALunder attack21 Oct 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
Exploit-DBVexDay Proof
Trend Micro Anti-Threat Toolkit 1.62.0.1218 - Remote Code Execution
CVE-2019-9491localwindows21 Oct 2019
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
28RISK
open
GitHub PoC5
Instructions for installing a vulnerable version of Exim and its expluatation
CVE-2019-10149CRITICALunder attack21 Oct 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
Metasploit400
Nostromo Directory Traversal Remote Command Execution
CVE-2019-16278CRITICALunder attack20 Oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC5
RCE Exploit For CVE-2019-17424 (nipper-ng 0.11.10)
CVE-2019-1742420 Oct 2019
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows re
28RISK
open
GitHub PoC9
Metasploit module & Python script for CVE-2019-16405
CVE-2019-1640518 Oct 2019
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code
28RISK
open
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALunder attack18 Oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
GitHub PoC89
kibana < 6.6.0 未授权远程代码命令执行 (Need Timelion And Canvas),CVE-2019-7609
CVE-2019-7609CRITICALunder attack18 Oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
GitHub PoC3
Sudo Security Bypass (CVE-2019-14287)
CVE-2019-1428718 Oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC
CVE-2019-17080
CVE-2019-1708018 Oct 2019
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by a
23RISK
open
GitHub PoC3
CVE 2019-2215 Android Binder Use After Free
CVE-2019-2215HIGHunder attack17 Oct 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
VulnCheck XDB
initial-access
CVE-2012-595917 Oct 2019
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RISK
open
GitHub PoC
CVE-2012-5960, CVE-2012-5959 Proof of Concept
CVE-2012-596017 Oct 2019
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RISK
open
GitHub PoC6
Authenticated Stored XSS in LifeRay 7.2.0 GA1 via MyAccountPortlet executed by Search Results
CVE-2020-793417 Oct 2019
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA
23RISK
open
Exploit-DBVexDay Proof
ThinVNC 1.0b1 - Authentication Bypass
CVE-2019-17662remotewindows17 Oct 2019
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISK
open
GitHub PoC18
Programa para hackear Whatsapp Mediante Gif ,asiendo un exploit con el puerto.
CVE-2019-1193216 Oct 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
GitHub PoC38
This native code file aims to be complementary to the published Whatsapp GIF RCE exploit by Awakened , by calculating the system() function address and ROP gadget address for different types of devices, which then can be used to successfully exploit the vulnerability.
CVE-2019-1193216 Oct 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
GitHub PoC1
Exploit and Mass Pwn3r for CVE-2019-16920
CVE-2019-16920CRITICALunder attack16 Oct 2019
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16920CRITICALunder attack16 Oct 2019
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16920CRITICALunder attack16 Oct 2019
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i
100RISK
open
GitHub PoC
gurneesh/CVE-2019-14287-write-up
CVE-2019-1428716 Oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
VulnCheck XDB
initial-access
CVE-2017-17562HIGHunder attack16 Oct 2019
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open
previouspage 809 / 2,641next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.