Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
Exploit-DB
Apache Pluto 3.0.0 / 3.0.1 - Persistent Cross-Site Scripting
CVE-2019-0186webappsjava26 Apr 2019
The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XS
28RISK
open
Exploit-DBVexDay Proof
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process
CVE-2019-3843MEDIUMdoslinux26 Apr 2019
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allo
33RISK
open
Exploit-DBVexDay Proof
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process
CVE-2019-3844MEDIUMdoslinux26 Apr 2019
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of
33RISK
open
Exploit-DB
JioFi 4G M2S 1.0.2 - 'mask' Cross-Site Scripting
CVE-2019-7438webappshardware25 Apr 2019
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.
23RISK
open
Exploit-DB
JioFi 4G M2S 1.0.2 - Denial of Service
CVE-2019-7439doshardware25 Apr 2019
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.
23RISK
open
GitHub PoC1
WebLogic CNVD-C-2019_48814 CVE-2017-10271
CVE-2017-10271HIGHunder attackransomware25 Apr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC105
CVE-2019-2725poc汇总 更新绕过CVE-2017-10271补丁POC
CVE-2017-10271HIGHunder attackransomware25 Apr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC
likekabin/CVE-2018-20250
CVE-2018-20250HIGHunder attackransomware25 Apr 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
Exploit-DBVexDay Proof
RARLAB WinRAR 5.61 - ACE Format Input Validation Remote Code Execution (Metasploit)
CVE-2018-20250HIGHunder attackransomwarelocalwindows25 Apr 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC9
The official exploit code for LibreNMS v1.46 Remote Code Execution CVE-2018-20434
CVE-2018-2043425 Apr 2019
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to htm
60RISK
open
GitHub PoC105
CVE-2019-2725poc汇总 更新绕过CVE-2017-10271补丁POC
CVE-2019-2725HIGHunder attackransomware25 Apr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware25 Apr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC114
WebLogic CNVD-C-2019_48814 CVE-2017-10271 Scan By 7kbstorm
CVE-2017-10271HIGHunder attackransomware25 Apr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC4
A C# module to detect if a Jenkins server is vulnerable to the RCE vulnerability found in CVE-2019-1003000 (chained with CVE-2018-1000861 for pre-auth RCE)
CVE-2018-1000861CRITICALunder attack24 Apr 2019
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-100300024 Apr 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
Metasploit300
Pulse Secure VPN Arbitrary File Disclosure
CVE-2019-11510CRITICALunder attackransomware24 Apr 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open
Exploit-DBVexDay Proof
VirtualBox 6.0.4 r128413 - COM RPC Interface Code Injection Host Privilege Escalation
CVE-2019-2721localwindows24 Apr 2019
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISK
open
GitHub PoC
KeyStrOke95/nfsen_1.3.7_CVE-2017-6971
CVE-2017-697124 Apr 2019
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
28RISK
open
VulnCheck XDB
initial-access
CVE-2018-1000861CRITICALunder attack24 Apr 2019
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISK
open
GitHub PoC4
A C# module to detect if a Jenkins server is vulnerable to the RCE vulnerability found in CVE-2019-1003000 (chained with CVE-2018-1000861 for pre-auth RCE)
CVE-2019-100300024 Apr 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
Metasploit600
WP Database Backup RCE
CVE-2019-25224CRITICAL24 Apr 2019
WP Database Backup < 5.2 - Unauthenticated OS Command Injection
68RISK
open
Metasploit600
Pulse Secure VPN Arbitrary Command Execution
CVE-2019-11539HIGHunder attackransomware24 Apr 2019
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISK
open
Metasploit600
Oracle Weblogic Server Deserialization RCE - AsyncResponseService
CVE-2019-2725HIGHunder attackransomware23 Apr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
Exploit-DBVexDay Proof
systemd - Lack of Seat Verification in PAM Module Permits Spoofing Active Session to polkit
CVE-2019-3842MEDIUMdoslinux23 Apr 2019
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using t
33RISK
open
Exploit-DB
Msvod 10 - Cross-Site Request Forgery (Change User Information)
CVE-2019-11375webappsphp22 Apr 2019
Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.
23RISK
open
Exploit-DB
74CMS 5.0.1 - Cross-Site Request Forgery (Add New Admin User)
CVE-2019-11374webappsphp22 Apr 2019
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
23RISK
open
Exploit-DB
QNAP myQNAPcloud Connect 1.3.4.0317 - 'Username/Password' Denial of Service
CVE-2019-7181doshardware22 Apr 2019
Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the pr
23RISK
open
Exploit-DB
UliCMS 2019.2 / 2019.1 - Multiple Cross-Site Scripting
CVE-2019-11398webappsphp22 Apr 2019
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitra
23RISK
open
GitHub PoC
cve-2017-17485 PoC
CVE-2017-17485CRITICAL21 Apr 2019
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o
60RISK
open
GitHub PoC1
rakesh143/CVE-2019-0808
CVE-2019-0808HIGHunder attack21 Apr 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
previouspage 840 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.