Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC89
kibana < 6.6.0 未授权远程代码命令执行 (Need Timelion And Canvas),CVE-2019-7609
CVE-2019-7609CRITICALunder attack18 Oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
GitHub PoC3
Sudo Security Bypass (CVE-2019-14287)
CVE-2019-1428718 Oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALunder attack18 Oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
GitHub PoC9
Metasploit module & Python script for CVE-2019-16405
CVE-2019-1640518 Oct 2019
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code
28RISK
open
Exploit-DBVexDay Proof
ThinVNC 1.0b1 - Authentication Bypass
CVE-2019-17662remotewindows17 Oct 2019
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISK
open
VulnCheck XDB
initial-access
CVE-2012-595917 Oct 2019
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RISK
open
GitHub PoC3
CVE 2019-2215 Android Binder Use After Free
CVE-2019-2215HIGHunder attack17 Oct 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
GitHub PoC6
Authenticated Stored XSS in LifeRay 7.2.0 GA1 via MyAccountPortlet executed by Search Results
CVE-2020-793417 Oct 2019
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA
23RISK
open
GitHub PoC
CVE-2012-5960, CVE-2012-5959 Proof of Concept
CVE-2012-596017 Oct 2019
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RISK
open
GitHub PoC
gurneesh/CVE-2019-14287-write-up
CVE-2019-1428716 Oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
Exploit-DB
Whatsapp 2.19.216 - Remote Code Execution
CVE-2019-11932remoteandroid16 Oct 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
VulnCheck XDB
initial-access
CVE-2017-17562HIGHunder attack16 Oct 2019
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open
Metasploit300
ThinVNC Directory Traversal
CVE-2019-1766216 Oct 2019
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISK
open
Metasploit600
Solaris xscreensaver log Privilege Escalation
CVE-2019-3010HIGHunder attack16 Oct 2019
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RISK
open
GitHub PoC1
Exploit and Mass Pwn3r for CVE-2019-16920
CVE-2019-16920CRITICALunder attack16 Oct 2019
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i
100RISK
open
GitHub PoC10
Standalone Python 3 exploit for CVE-2017-17562
CVE-2017-17562HIGHunder attack16 Oct 2019
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open
GitHub PoC38
This native code file aims to be complementary to the published Whatsapp GIF RCE exploit by Awakened , by calculating the system() function address and ROP gadget address for different types of devices, which then can be used to successfully exploit the vulnerability.
CVE-2019-1193216 Oct 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
GitHub PoC18
Programa para hackear Whatsapp Mediante Gif ,asiendo un exploit con el puerto.
CVE-2019-1193216 Oct 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
VulnCheck XDB
initial-access
CVE-2019-16920CRITICALunder attack16 Oct 2019
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16920CRITICALunder attack16 Oct 2019
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware15 Oct 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC13
Sudo exploit
CVE-2019-1428715 Oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack15 Oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack15 Oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC3
CVE-2019-16278Nostromo httpd命令执行
CVE-2019-16278CRITICALunder attack15 Oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack15 Oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC1
FauxFaux/sudo-cve-2019-14287
CVE-2019-1428715 Oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC9
CVE-2019-16728 Proof of Concept
CVE-2019-16278CRITICALunder attack15 Oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC70
Directory transversal to remote code execution
CVE-2019-16278CRITICALunder attack15 Oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
Exploit-DB
sudo 1.8.27 - Security Bypass
CVE-2019-14287locallinux15 Oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
previouspage 811 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.