Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
VulnCheck XDB
initial-access
CVE-2019-3929CRITICALunder attack17 Sep 2019
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware17 Sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
Escape from Docker using CVE-2017-1000112 and CVE-2017-18344, including gaining root privilage, get all capbilities, namespace recovery, filesystem recovery, cgroup limitation bypass and seccomp bypass.
CVE-2017-100011217 Sep 2019
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISK
open
GitHub PoC4
Modified standalone exploit ported for Python 3
CVE-2018-1261316 Sep 2019
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
Exploit-DB
AppXSvc - Privilege Escalation
CVE-2019-1253HIGHunder attackransomwarelocalwindows16 Sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISK
open
Exploit-DB
Symantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File Upload
CVE-2016-10258webappscfm16 Sep 2019
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A
23RISK
open
Exploit-DB
Notepad++ < 7.7 (x64) - Denial of Service
CVE-2019-16294doswindows_x86-6416 Sep 2019
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode ch
23RISK
open
VulnCheck XDB
client-side
CVE-2018-1261316 Sep 2019
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
VulnCheck XDB
infoleak
CVE-2019-845116 Sep 2019
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RISK
open
GitHub PoC
Tool to exploit CVE-2018-7284 and CVE-2018-19278
CVE-2018-728415 Sep 2019
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Ce
35RISK
open
GitHub PoC3
CVE-2019-0604: SharePoint RCE detection rules and sample PCAP
CVE-2019-0604CRITICALunder attackransomware15 Sep 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISK
open
Exploit-DBVexDay Proof
LimeSurvey 3.17.13 - Cross-Site Scripting
CVE-2019-16172webappsphp13 Sep 2019
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RISK
open
Exploit-DB
Dolibarr ERP-CRM 10.0.1 - 'User-Agent' Cross-Site Scripting
CVE-2019-16197webappsphp13 Sep 2019
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document
23RISK
open
Exploit-DBVexDay Proof
LimeSurvey 3.17.13 - Cross-Site Scripting
CVE-2019-16173webappsphp13 Sep 2019
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example,
23RISK
open
Metasploit600
Micro Focus (HPE) Data Protector SUID Privilege Escalation
CVE-2019-1166013 Sep 2019
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30,
38RISK
open
Exploit-DBVexDay Proof
Microsoft DirectWrite - Invalid Read in SplicePixel While Processing OTF Fonts
CVE-2019-1245doswindows12 Sep 2019
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
28RISK
open
Exploit-DBVexDay Proof
Microsoft DirectWrite - Out-of-Bounds Read in sfac_GetSbitBitmap While Processing TTF Fonts
CVE-2019-1244doswindows12 Sep 2019
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
28RISK
open
GitHub PoC1
CVE-2019-0708 C#验证漏洞
CVE-2019-0708CRITICALunder attackransomware11 Sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
likekabin/CVE-2019-1253
CVE-2019-1253HIGHunder attackransomware11 Sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISK
open
GitHub PoC19
AppXSvc Arbitrary File Security Descriptor Overwrite EoP
CVE-2019-1253HIGHunder attackransomware11 Sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISK
open
GitHub PoC152
Poc for CVE-2019-1253
CVE-2019-1253HIGHunder attackransomware11 Sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISK
open
GitHub PoC1
distance-vector/CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware11 Sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
local
CVE-2019-1253HIGHunder attackransomware11 Sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware11 Sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
local
CVE-2019-1253HIGHunder attackransomware11 Sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISK
open
VulnCheck XDB
initial-access
CVE-2019-1579HIGHunder attackransomware10 Sep 2019
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RISK
open
VulnCheck XDB
local
CVE-2019-1609810 Sep 2019
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user t
28RISK
open
Exploit-DBVexDay Proof
October CMS - Upload Protection Bypass Code Execution (Metasploit)
CVE-2017-1000119remotephp10 Sep 2019
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise
50RISK
open
Exploit-DBVexDay Proof
LibreNMS - Collectd Command Injection (Metasploit)
CVE-2019-10669remotelinux10 Sep 2019
An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/dev
60RISK
open
GitHub PoC
0x6b7966/CVE-2018-1999002
CVE-2018-199900210 Sep 2019
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewor
45RISK
open
previouspage 816 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.