Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Double Free in MergeFormat12Cmap / MakeFormat12MergedGlyphList
CVE-2019-1144HIGHdoswindows15 Aug 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Returning a Dangling Pointer via MergeFontPackage
CVE-2019-1145HIGHdoswindows15 Aug 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
GitHub PoC5
CVE-2017-11882(通杀Office 2003到2016)
CVE-2017-11882HIGHunder attackransomware14 Aug 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
Exploit-DB
TortoiseSVN 1.12.1 - Remote Code Execution
CVE-2019-14422webappswindows14 Aug 2019
An issue was discovered in in TortoiseSVN 1.12.1. The Tsvncmd: URI handler allows a customised diff operation on Excel w
28RISK
open
Exploit-DB
D-Link DIR-600M - Authentication Bypass (Metasploit)
CVE-2019-13101webappshardware14 Aug 2019
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without
50RISK
open
GitHub PoC1
CVE-2017-16995 ubuntun本地提权 POC
CVE-2017-1699514 Aug 2019
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
GitHub PoC
major203/cve-2019-1181
CVE-2019-1181CRITICAL14 Aug 2019
Remote Desktop Services Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware14 Aug 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
Metasploit300
Grafana 2.0 through 5.2.2 authentication bypass for LDAP and OAuth
CVE-2018-1572714 Aug 2019
Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generat
30RISK
open
GitHub PoC
OpenEMR security issue
CVE-2019-1453013 Aug 2019
An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can
50RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack13 Aug 2019
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC7
Linux 本地提权漏洞
CVE-2016-5195HIGHunder attack13 Aug 2019
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
Exploit-DB
VxWorks 6.8 - TCP Urgent Pointer = 0 Integer Underflow
CVE-2019-12255dosvxworks12 Aug 2019
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TC
45RISK
open
Exploit-DB
Mitsubishi Electric smartRTU / INEA ME-RTU - Unauthenticated OS Command Injection Bind Shell
CVE-2019-14931webappsphp12 Aug 2019
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3
35RISK
open
Exploit-DB
Mitsubishi Electric smartRTU / INEA ME-RTU - Unauthenticated Configuration Download
CVE-2019-14927webappsphp12 Aug 2019
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3
35RISK
open
GitHub PoC65
Apache Solr远程代码执行漏洞(CVE-2019-0193) Exploit
CVE-2019-0193HIGHunder attack12 Aug 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISK
open
Exploit-DBVexDay Proof
Ghidra (Linux) 9.0.4 - .gar Arbitrary Code Execution
CVE-2019-13623locallinux12 Aug 2019
In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive)
23RISK
open
Exploit-DB
UNA 10.0.0 RC1 - 'polyglot.php' Persistent Cross-Site Scripting
CVE-2019-14804webappsphp12 Aug 2019
studio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template
23RISK
open
Exploit-DB
Cisco Adaptive Security Appliance - Path Traversal (Metasploit)
CVE-2018-0296HIGHunder attackwebappshardware12 Aug 2019
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISK
open
Exploit-DBVexDay Proof
WebKit - UXSS via XSLT and Nested Document Replacements
CVE-2019-8690dosmultiple12 Aug 2019
A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This i
23RISK
open
Exploit-DB
BSI Advance Hotel Booking System 2.0 - 'booking_details.php Persistent Cross-Site Scripting
CVE-2014-4035webappsphp12 Aug 2019
Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0
23RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-0193HIGHunder attack12 Aug 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-13379CRITICALunder attackransomware11 Aug 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
GitHub PoC146
CVE-2018-13382
CVE-2018-13382CRITICALunder attackransomware11 Aug 2019
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-13382CRITICALunder attackransomware11 Aug 2019
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISK
open
GitHub PoC253
CVE-2018-13379
CVE-2018-13379CRITICALunder attackransomware11 Aug 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
Metasploit600
Webmin password_change.cgi Backdoor
CVE-2019-15107CRITICALunder attackransomware10 Aug 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
Metasploit300
URGENT/11 Scanner, Based on Detection Tool by Armis
CVE-2019-1225809 Aug 2019
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: Do
23RISK
open
GitHub PoC
ThanHuuTuan/CVE-2017-7269
CVE-2017-7269CRITICALunder attack09 Aug 2019
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
VulnCheck XDB
client-side
CVE-2017-7269CRITICALunder attack09 Aug 2019
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
previouspage 822 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.