Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC90
Apache Solr DataImport Handler RCE
CVE-2019-0193HIGHunder attack09 Aug 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISK
open
GitHub PoC
ThanHuuTuan/CVE-2017-7269
CVE-2017-7269CRITICALunder attack09 Aug 2019
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
Exploit-DB
Open-School 3.0 / Community Edition 2.3 - Cross-Site Scripting
CVE-2019-14696webappsphp08 Aug 2019
Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.
43RISK
open
Exploit-DB
Adive Framework 2.0.7 - Cross-Site Request Forgery
CVE-2019-14346webappsphp08 Aug 2019
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
23RISK
open
Exploit-DB
Aptana Jaxer 1.0.3.4547 - Local File inclusion
CVE-2019-14312webappsmultiple08 Aug 2019
Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This v
43RISK
open
VulnCheck XDB
local
CVE-2019-13272HIGHunder attack07 Aug 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
Exploit-DB
WordPress Plugin JoomSport 3.3 - SQL Injection
CVE-2019-14348webappsphp07 Aug 2019
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via
28RISK
open
GitHub PoC4
linux 提权
CVE-2019-13272HIGHunder attack07 Aug 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC
Aquí está mi nuevo y primer exploit web, este exploit ataca a la vulnerabilidad de HeartBleed (CVE-2014-0160) espero que os guste.
CVE-2014-0160HIGHunder attack05 Aug 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
Lee-SungYoung/cve-2019-5736-study
CVE-2019-573605 Aug 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
Exploit-DBVexDay Proof
Apache Tika 1.15 - 1.17 - Header Command Injection (Metasploit)
CVE-2018-1335remotewindows05 Aug 2019
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
Exploit-DBVexDay Proof
macOS iMessage - Heap Overflow when Deserializing
CVE-2019-8661dosmacos05 Aug 2019
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.6. A rem
28RISK
open
GitHub PoC1
提权漏洞
CVE-2019-13272HIGHunder attack04 Aug 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC1
CVE-2018-16509 Docker Playground - Ghostscript command execution
CVE-2018-1650904 Aug 2019
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISK
open
GitHub PoC3
this is not stable
CVE-2013-202803 Aug 2019
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RISK
open
VulnCheck XDB
local
CVE-2018-8639HIGHunder attackransomware03 Aug 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RISK
open
GitHub PoC1
SSH account enumeration verification script(CVE-2018-15473)
CVE-2018-15473MEDIUM02 Aug 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
Exploit-DB
SilverSHielD 6.x - Local Privilege Escalation
CVE-2019-13069localmultiple01 Aug 2019
extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. The
23RISK
open
VulnCheck XDB
local
CVE-2019-13272HIGHunder attack31 Jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
VulnCheck XDB
local
CVE-2019-13272HIGHunder attack31 Jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC332
Linux 4.10 < 5.1.17 PTRACE_TRACEME local root
CVE-2019-13272HIGHunder attack31 Jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
Exploit-DBVexDay Proof
Oracle Hyperion Planning 11.1.2.3 - XML External Entity
CVE-2019-2861webappsmultiple31 Jul 2019
Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported versi
23RISK
open
GitHub PoC3
CVE-2019-1132
CVE-2019-1132HIGHunder attack31 Jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISK
open
VulnCheck XDB
local
CVE-2019-1132HIGHunder attack31 Jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISK
open
GitHub PoC5
The exploit for CVE-2019-13272
CVE-2019-13272HIGHunder attack31 Jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
Exploit-DBVexDay Proof
iMessage - NSArray Deserialization can Invoke Subclass that does not Retain References
CVE-2019-8647dosmultiple30 Jul 2019
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.4, tvOS 12.4, watchO
28RISK
open
Exploit-DBVexDay Proof
iMessage - NSKeyedUnarchiver Deserialization Allows file Backed NSData Objects
CVE-2019-8646dosmultiple30 Jul 2019
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.
28RISK
open
Exploit-DBVexDay Proof
Amcrest Cameras 2.520.AC00.18.R - Unauthenticated Audio Streaming
CVE-2019-3948webappshardware30 Jul 2019
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0
28RISK
open
Exploit-DBVexDay Proof
iMessage - Memory Corruption when Decoding NSKnownKeysDictionary1
CVE-2019-8660dosmultiple30 Jul 2019
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10
28RISK
open
Exploit-DBVexDay Proof
macOS / iOS JavaScriptCore - Loop-Invariant Code Motion (LICM) Leaves Object Property Access Unguarded
CVE-2019-8671dosmultiple30 Jul 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS M
23RISK
open
previouspage 823 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.