Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
Exploit-DB
UliCMS 2019.1 'Spitting Lama' - Persistent Cross-Site Scripting
CVE-2019-11398webappsphp10 Jun 2019
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitra
23RISK
open
VulnCheck XDB
initial-access
CVE-2019-2725HIGHunder attackransomware10 Jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
VulnCheck XDB
local
CVE-2019-0859HIGHunder attack07 Jun 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISK
open
Exploit-DB
Microsoft Windows - AppX Deployment Service Local Privilege Escalation (3)
CVE-2019-0841HIGHunder attackransomwarelocalwindows07 Jun 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RISK
open
GitHub PoC118
CVE-2019-0859 1day Exploit
CVE-2019-0859HIGHunder attack07 Jun 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISK
open
Exploit-DB
VMware WorkStation 12.5.3 - Virtual Machine Escape
CVE-2017-4905localwindows06 Jun 2019
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi
23RISK
open
VulnCheck XDB
initial-access
CVE-2020-1938CRITICALunder attack06 Jun 2019
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
Metasploit600
FusionPBX Operator Panel exec.php Command Execution
CVE-2019-1140906 Jun 2019
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerabili
60RISK
open
Exploit-DB
Supra Smart Cloud TV - 'openLiveURL()' Remote File Inclusion
CVE-2019-12477webappshardware06 Jun 2019
Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcas
43RISK
open
GitHub PoC9
Vim/Neovim Arbitrary Code Execution via Modelines (CVE-2019-12735)
CVE-2019-1273506 Jun 2019
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RISK
open
Exploit-DBVexDay Proof
IBM Websphere Application Server - Network Deployment Untrusted Data Deserialization Remote Code Execution (Metasploit)
CVE-2019-4279CRITICALremotewindows05 Jun 2019
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with
85RISK
open
GitHub PoC
799600966/CVE-2018-17456
CVE-2018-1745605 Jun 2019
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open
Exploit-DB
Zimbra < 8.8.11 - XML External Entity Injection / Server-Side Request Forgery
CVE-2019-9621HIGHunder attackwebappsjsp05 Jun 2019
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RISK
open
Exploit-DB
Exim 4.87 < 4.91 - (Local / Remote) Command Execution
CVE-2019-10149CRITICALunder attackremotelinux05 Jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
Exploit-DBVexDay Proof
LibreNMS - addhost Command Injection (Metasploit)
CVE-2018-20434remotelinux05 Jun 2019
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to htm
60RISK
open
Exploit-DBVexDay Proof
IBM Websphere Application Server - Network Deployment Untrusted Data Deserialization Remote Code Execution (Metasploit)
CVE-2019-8352remotewindows05 Jun 2019
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sen
23RISK
open
Metasploit600
Exim 4.87 - 4.91 Local Privilege Escalation
CVE-2019-10149CRITICALunder attack05 Jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
Metasploit600
Serv-U FTP Server prepareinstallation Privilege Escalation
CVE-2019-1218105 Jun 2019
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RISK
open
GitHub PoC
loudong
CVE-2015-754704 Jun 2019
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISK
open
VulnCheck XDB
initial-access
CVE-2015-754704 Jun 2019
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISK
open
Exploit-DB
Zoho ManageEngine ServiceDesk Plus 9.3 - 'SolutionSearch.do' Cross-Site Scripting
CVE-2019-12541webappsjava04 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText par
23RISK
open
GitHub PoC
tarantula-team/CVE-2019-12541
CVE-2019-1254104 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText par
23RISK
open
GitHub PoC
tarantula-team/CVE-2019-12542
CVE-2019-1254204 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID paramete
23RISK
open
Exploit-DB
Zoho ManageEngine ServiceDesk Plus 9.3 - 'SearchN.do' Cross-Site Scripting
CVE-2019-12542webappsjava04 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID paramete
23RISK
open
Exploit-DB
Zoho ManageEngine ServiceDesk Plus 9.3 - 'SiteLookup.do' Cross-Site Scripting
CVE-2019-12538webappsjava04 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
23RISK
open
Exploit-DB
IceWarp 10.4.4 - Local File Inclusion
CVE-2019-12593webappsphp04 Jun 2019
IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index
50RISK
open
GitHub PoC
tarantula-team/CVE-2019-12543
CVE-2019-1254304 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceReques
23RISK
open
Exploit-DB
NUUO NVRMini 2 3.9.1 - 'sscanf' Stack Overflow
CVE-2018-19864remotehardware04 Jun 2019
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a
28RISK
open
Exploit-DB
Cisco RV130W 1.0.3.44 - Remote Stack Overflow
CVE-2019-1663CRITICALremotehardware04 Jun 2019
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISK
open
GitHub PoC
tarantula-team/CVE-2019-12538
CVE-2019-1253804 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
23RISK
open
previouspage 831 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.