Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack15 Oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware15 Oct 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack14 Oct 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
VulnCheck XDB
infoleak
CVE-2018-13379CRITICALunder attackransomware14 Oct 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
Exploit-DB
Apache Httpd mod_proxy - Error Page Cross-Site Scripting
CVE-2019-10092webappsmultiple14 Oct 2019
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page
60RISK
open
Metasploit600
Ajenti auth username Command Injection
CVE-2019-25066MEDIUM14 Oct 2019
ajenti API privileges management
28RISK
open
GitHub PoC12
CVE-2018-13379 Script for Nmap NSE.
CVE-2018-13379CRITICALunder attackransomware14 Oct 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
Exploit-DB
WordPress Core < 5.2.3 - Viewing Unauthenticated/Password/Private Posts
CVE-2019-17671webappsmultiple14 Oct 2019
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is m
50RISK
open
GitHub PoC
Spring Security OAuth 2.3 Open Redirection 分析复现篇
CVE-2019-377814 Oct 2019
Open Redirect in spring-security-oauth2
28RISK
open
GitHub PoC136
Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215
CVE-2019-2215HIGHunder attack14 Oct 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
Exploit-DB
Kirona-DRS 5.5.3.5 - Information Disclosure
CVE-2019-17504webappsphp14 Oct 2019
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vuln
23RISK
open
Exploit-DB
Kirona-DRS 5.5.3.5 - Information Disclosure
CVE-2019-17503webappsphp14 Oct 2019
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REG
50RISK
open
Exploit-DB
Apache Httpd mod_rewrite - Open Redirects
CVE-2019-10098webappsmultiple14 Oct 2019
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential m
60RISK
open
GitHub PoC
h-wookie/cve-2019-5736-poc
CVE-2019-573612 Oct 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC4
Interactive-Like Command-Line Console for CVE-2019-16759
CVE-2019-16759CRITICALunder attack12 Oct 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack12 Oct 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16759CRITICALunder attack12 Oct 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-11776HIGHunder attack10 Oct 2019
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-6789CRITICALunder attackransomware10 Oct 2019
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware10 Oct 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in CI!CipFixImageType While Parsing Malformed PE File
CVE-2019-1344doswindows10 Oct 2019
An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memo
23RISK
open
Exploit-DB
TP-Link TL-WR1043ND 2 - Authentication Bypass
CVE-2019-6971webappshardware10 Oct 2019
An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packe
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in nt!MiRelocateImage While Parsing Malformed PE File
CVE-2019-1347doswindows10 Oct 2019
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in CI!HashKComputeFirstPageHash While Parsing Malformed PE File
CVE-2019-1346doswindows10 Oct 2019
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - NULL Pointer Dereference in nt!MiOffsetToProtos While Parsing Malformed PE File
CVE-2019-1343doswindows10 Oct 2019
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - win32k.sys TTF Font Processing Pool Corruption in win32k!ulClearTypeFilter
CVE-2019-1364doswindows10 Oct 2019
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
23RISK
open
Exploit-DB
SMA Solar Technology AG Sunny WebBox device - 1.6 - Cross-Site Request Forgery
CVE-2019-13529HIGHwebappshardware10 Oct 2019
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in nt!MiParseImageLoadConfig While Parsing Malformed PE File
CVE-2019-1345doswindows10 Oct 2019
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
23RISK
open
GitHub PoC10
PoC materials to exploit CVE-2018-6789
CVE-2018-6789CRITICALunder attackransomware10 Oct 2019
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open
GitHub PoC1
CVE-2018-7600 and CVE-2018-7602 Mass Exploiter
CVE-2018-7600CRITICALunder attackransomware10 Oct 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
previouspage 812 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.