Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC27
Zimbra RCE PoC - CVE-2019-9670 XXE/SSRF
CVE-2019-9670CRITICALunder attack16 Aug 2019
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open
GitHub PoC5
Scan a list of given IP's for CVE-2017-12542
CVE-2017-1254216 Aug 2019
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-9670CRITICALunder attack16 Aug 2019
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-9670CRITICALunder attack16 Aug 2019
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-1254216 Aug 2019
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISK
open
VulnCheck XDB
client-side
CVE-2017-11774HIGHunder attack16 Aug 2019
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary command
83RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in GetGlyphIdx
CVE-2019-1148MEDIUMdoswindows15 Aug 2019
Microsoft Graphics Component Information Disclosure Vulnerability
33RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware15 Aug 2019
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow due to Malformed Font Stream
CVE-2019-8049doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use-After-Free due to Malformed JP2 Stream
CVE-2019-8024doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow While Processing Malformed PDF
CVE-2019-8050doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
35RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Out-of-Bounds read due to Malformed JP2 Stream
CVE-2019-8043doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in ReadAllocFormat12CharGlyphMapList
CVE-2019-1151HIGHdoswindows15 Aug 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in FixSbitSubTables
CVE-2019-1149HIGHdoswindows15 Aug 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Static Buffer Overflow due to Malformed Font Stream
CVE-2019-8048doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
35RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow in CoolType.dll
CVE-2019-8041doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow due to Malformed JP2 Stream
CVE-2019-8046doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Double Free due to Malformed JP2 Stream
CVE-2019-8044doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Memory Corruption due to Malformed TTF Font
CVE-2019-8042doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat CoolType (AFDKO) - Memory Corruption in the Handling of Type 1 Font load/store Operators
CVE-2019-8016doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
GitHub PoC
Demo app of THAT data broker's security breach
CVE-2017-5638CRITICALunder attackransomware15 Aug 2019
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Returning a Dangling Pointer via MergeFontPackage
CVE-2019-1145HIGHdoswindows15 Aug 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Double Free in MergeFormat12Cmap / MakeFormat12MergedGlyphList
CVE-2019-1144HIGHdoswindows15 Aug 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat CoolType (AFDKO) - Call from Uninitialized Memory due to Empty FDArray in Type 1 Fonts
CVE-2019-8017doswindows15 Aug 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in ReadTableIntoStructure
CVE-2019-1150HIGHdoswindows15 Aug 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
VulnCheck XDB
infoleak
CVE-2019-1310115 Aug 2019
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without
50RISK
open
Exploit-DBVexDay Proof
NSKeyedUnarchiver - Info Leak in Decoding SGBigUTF8String
CVE-2019-8663dosmultiple15 Aug 2019
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6. A remote attacker
23RISK
open
GitHub PoC
Simple Python script for D-Link vulnerability scan and test [CVE-2019-13101]
CVE-2019-1310115 Aug 2019
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without
50RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in MakeFormat12MergedGlyphList
CVE-2019-1152HIGHdoswindows15 Aug 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in FixSbitSubTableFormat1
CVE-2019-1153MEDIUMdoswindows15 Aug 2019
Microsoft Graphics Component Information Disclosure Vulnerability
33RISK
open
previouspage 821 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.