Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC22
CVE-2019-9978 - (PoC) RCE in Social WarFare Plugin (<=3.5.2)
CVE-2019-9978MEDIUMunder attack03 May 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
Exploit-DB
Crestron AM/Barco wePresent WiPG/Extron ShareLink/Teq AV IT/SHARP PN-L703WA/Optoma WPS-Pro/Blackbox HD WPS/InFocus LiteShow - Remote Command Injection
CVE-2019-3929CRITICALunder attackwebappshardware03 May 2019
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RISK
open
Exploit-DBVexDay Proof
Ruby On Rails - DoubleTap Development Mode secret_key_base Remote Code Execution (Metasploit)
CVE-2019-5420remotelinux02 May 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
GitHub PoC4
WordPress crop-image exploitation
CVE-2019-894202 May 2019
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISK
open
GitHub PoC1
davidmthomsen/CVE-2019-2725
CVE-2019-2725HIGHunder attackransomware02 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-894202 May 2019
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISK
open
GitHub PoC21
lasensio/cve-2019-2725
CVE-2019-2725HIGHunder attackransomware01 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
Exploit-DB
CentOS Web Panel 0.9.8.793 (Free) / v0.9.8.753 (Pro) / 0.9.8.807 (Pro) - Domain Field (Add DNS Zone) Cross-Site Scripting
CVE-2019-11429webappslinux01 May 2019
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro)
23RISK
open
GitHub PoC1
PoC command injection example for cve-2018-1002105 based off https://github.com/gravitational/cve-2018-1002105
CVE-2018-1002105CRITICAL30 Apr 2019
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISK
open
Exploit-DBVexDay Proof
Domoticz 4.10577 - Unauthenticated Remote Command Execution
CVE-2019-10664webappsmultiple30 Apr 2019
Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.
23RISK
open
Exploit-DB
Intelbras IWR 3000N - Denial of Service (Remote Reboot)
CVE-2019-11415doshardware30 Apr 2019
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. A malformed login request allows remote attackers to cause
28RISK
open
Exploit-DB
Intelbras IWR 3000N 1.5.0 - Cross-Site Request Forgery
CVE-2019-11416webappshardware30 Apr 2019
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstr
23RISK
open
Metasploit600
Barco WePresent file_transfer.cgi Command Injection
CVE-2019-3929CRITICALunder attack30 Apr 2019
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RISK
open
Exploit-DB
HumHub 1.3.12 - Cross-Site Scripting
CVE-2019-11564webappsphp30 Apr 2019
A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HT
23RISK
open
Exploit-DBVexDay Proof
Domoticz 4.10577 - Unauthenticated Remote Command Execution
CVE-2019-10678webappsmultiple30 Apr 2019
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
28RISK
open
Exploit-DB
DeviceViewer 3.12.0.1 - 'user' SEH Overflow
CVE-2019-11563localwindows30 Apr 2019
20RISK
open
Exploit-DBVexDay Proof
Linux - Missing Locking Between ELF coredump code and userfaultfd VMA Modification
CVE-2019-11599doslinux30 Apr 2019
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RISK
open
Exploit-DB
Moodle 3.6.3 - 'Install Plugin' Remote Command Execution (Metasploit)
CVE-2019-11631remotephp30 Apr 2019
35RISK
open
Exploit-DBVexDay Proof
Pimcore < 5.71 - Unserialize Remote Code Execution (Metasploit)
CVE-2019-10867remotephp30 Apr 2019
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/c
50RISK
open
Exploit-DB
Oracle Weblogic 10.3.6.0.0 / 12.1.3.0.0 - Remote Code Execution
CVE-2019-2725HIGHunder attackransomwarewebappswindows30 Apr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
Exploit-DB
Spring Cloud Config 2.1.x - Path Traversal (Metasploit)
CVE-2019-3799webappsjava30 Apr 2019
Directory Traversal with spring-cloud-config-server
60RISK
open
Exploit-DBVexDay Proof
AIS logistics ESEL-Server - Unauthenticated SQL Injection Remote Code Execution (Metasploit)
CVE-2019-10123remotewindows30 Apr 2019
SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app)
50RISK
open
GitHub PoC58
Spring Data Commons RCE 远程命令执行漏洞
CVE-2018-1273CRITICALunder attackransomware29 Apr 2019
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1273CRITICALunder attackransomware29 Apr 2019
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISK
open
Metasploit600
Moodle Admin Shell Upload
CVE-2019-1163128 Apr 2019
35RISK
open
Metasploit600
GetSimpleCMS Unauthenticated RCE
CVE-2019-1123128 Apr 2019
An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows
60RISK
open
GitHub PoC
Confluence Widget Connector path traversal (CVE-2019-3396)
CVE-2019-3396CRITICALunder attackransomware28 Apr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC
An intentionally vulnerable (CVE-2017-8046) SrpingData REST appl with Swagger Support for pentesting purposes
CVE-2017-804627 Apr 2019
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack27 Apr 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
shawntns/exploit-CVE-2014-6271
CVE-2014-6271CRITICALunder attack27 Apr 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
previouspage 839 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.