Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
Exploit-DB
DameWare Remote Support 12.0.0.509 - 'Host' Buffer Overflow (SEH)
CVE-2018-12897localwindows16 Jul 2019
SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.
23RISK
open
VulnCheck XDB
initial-access
CVE-2019-11581CRITICALunder attack16 Jul 2019
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-11581CRITICALunder attack16 Jul 2019
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 10 < build 17763 - AppXSvc Hard Link Privilege Escalation (Metasploit)
CVE-2019-0841HIGHunder attackransomwarelocalwindows16 Jul 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RISK
open
Exploit-DB
CentOS Control Web Panel 0.9.8.836 - Privilege Escalation
CVE-2019-13359webappslinux16 Jul 2019
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and uploa
28RISK
open
GitHub PoC92
Atlassian JIRA Template injection vulnerability RCE
CVE-2019-11581CRITICALunder attack16 Jul 2019
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISK
open
Exploit-DB
CentOS Control Web Panel 0.9.8.838 - User Enumeration
CVE-2019-13383webappslinux16 Jul 2019
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a usern
28RISK
open
Exploit-DBVexDay Proof
PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Command Execution (Metasploit)
CVE-2017-16894remotelinux16 Jul 2019
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwo
60RISK
open
Exploit-DB
CentOS Control Web Panel 0.9.8.836 - Authentication Bypass
CVE-2019-13360webappslinux16 Jul 2019
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login pro
28RISK
open
Exploit-DB
Android 7 - 9 VideoPlayer - 'ihevcd_parse_pps' Out-of-Bounds Write
CVE-2019-2107dosandroid15 Jul 2019
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RISK
open
Exploit-DB
FlightPath < 4.8.2 / < 5.0-rc2 - Local File Inclusion
CVE-2019-13396webappsphp15 Jul 2019
FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an in
50RISK
open
Exploit-DB
Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service (Metasploit)
CVE-2019-0708CRITICALunder attackransomwaredoswindows15 Jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DB
CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities
CVE-2019-1943MEDIUMwebappshardware15 Jul 2019
Cisco Small Business Series Switches Open Redirect Vulnerability
48RISK
open
GitHub PoC
Proof of concept tool to exploit the directory traversal and local file inclusion vulnerability that resides in the Sahi-pro web application CVE-2019-13063
CVE-2019-1306315 Jul 2019
Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the sc
28RISK
open
Metasploit600
LibreNMS Collectd Command Injection
CVE-2019-1066915 Jul 2019
An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/dev
60RISK
open
GitHub PoC23
Metasploit module for massive Denial of Service using #Bluekeep vector.
CVE-2019-0708CRITICALunder attackransomware14 Jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
CVE-2019-9766 React
CVE-2019-976614 Jul 2019
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware14 Jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 10.0.17134.648 - HTTP -> SMB NTLM Reflection Leads to Privilege Elevation
CVE-2019-1019HIGHlocalwindows12 Jul 2019
Microsoft Windows Security Feature Bypass Vulnerability
46RISK
open
Exploit-DB
Jenkins Dependency Graph View Plugin 0.13 - Persistent Cross-Site Scripting
CVE-2019-10349webappsjava12 Jul 2019
A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers
23RISK
open
GitHub PoC4
R/W
CVE-2019-053912 Jul 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISK
open
Exploit-DBVexDay Proof
Citrix SD-WAN Appliance 10.2.2 - Authentication Bypass / Remote Command Execution
CVE-2019-12991HIGHunder attackwebappscgi12 Jul 2019
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of
93RISK
open
Exploit-DBVexDay Proof
Xymon 4.3.25 - useradm Command Execution (Metasploit)
CVE-2016-2056remotemultiple12 Jul 2019
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via
50RISK
open
Exploit-DBVexDay Proof
Citrix SD-WAN Appliance 10.2.2 - Authentication Bypass / Remote Command Execution
CVE-2019-12989CRITICALunder attackwebappscgi12 Jul 2019
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
100RISK
open
Exploit-DB
SNMPc Enterprise Edition 9/10 - Mapping Filename Buffer Overflow
CVE-2019-13494localwindows11 Jul 2019
nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long var
23RISK
open
Exploit-DB
Sitecore 9.0 rev 171002 - Persistent Cross-Site Scripting
CVE-2019-13493webappsaspx11 Jul 2019
In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged u
23RISK
open
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling due to Out-of-Bounds cubeStackDepth
CVE-2019-1117doswindows10 Jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RISK
open
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow in OpenType Font Handling in readFDSelect
CVE-2019-1120doswindows10 Jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RISK
open
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Out-of-Bounds Read/Write in OpenType Font Handling Due to Unbounded iFD
CVE-2019-1121doswindows10 Jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RISK
open
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow in OpenType Font Handling in readCharset
CVE-2019-1128doswindows10 Jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RISK
open
previouspage 826 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.