Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,309cataloged exploits
36,467CVEs with public exploitation
24,695lab-tested
79,305 exploits
Exploit-DB
CMS Made Simple < 2.2.10 - SQL Injection
CVE-2019-9053webappsphp02 Apr 2019
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
Exploit-DB
JioFi 4G M2S 1.0.2 - Cross-Site Request Forgery
CVE-2019-7440webappshardware02 Apr 2019
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_S
23RISK
open
Exploit-DB
LimeSurvey < 3.16 - Remote Code Execution
CVE-2018-17057webappsphp02 Apr 2019
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar://
28RISK
open
GitHub PoC
artofscripting-zz/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS
CVE-2014-0160HIGHunder attack02 Apr 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC2
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Print Archive System v2015 release 2.6
CVE-2019-1068502 Apr 2019
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
23RISK
open
Metasploit300
WordPress Google Maps Plugin SQL Injection
CVE-2019-1069202 Apr 2019
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize
40RISK
open
VulnCheck XDB
initial-access
CVE-2014-0160HIGHunder attack02 Apr 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-5418HIGHunder attack01 Apr 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC3
a demo for Ruby on Rails CVE-2019-5418
CVE-2019-5418HIGHunder attack01 Apr 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC4
Just a PoC tool to extract password using CVE-2019-1653.
CVE-2019-1653HIGHunder attack01 Apr 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-1653HIGHunder attack01 Apr 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2017-0261HIGHunder attack31 Mar 2019
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the softwar
93RISK
open
GitHub PoC10
eps漏洞(CVE-2017-0261)漏洞分析
CVE-2017-0261HIGHunder attack31 Mar 2019
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the softwar
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-9276HIGHunder attack31 Mar 2019
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
GitHub PoC36
CVE-2018-9276 PRTG < 18.2.39 Authenticated Command Injection (Reverse Shell)
CVE-2018-9276HIGHunder attack31 Mar 2019
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
GitHub PoC28
patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428
CVE-2019-1135830 Mar 2019
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISK
open
GitHub PoC3
IBM Lotus Domino <= R8 Password Hash Extraction Exploit
CVE-2005-242829 Mar 2019
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hid
60RISK
open
GitHub PoC23
ASUS SmartHome Exploit for CVE-2019-11061 and CVE-2019-11063
CVE-2019-11061CRITICAL29 Mar 2019
HG100 has a broken access control vulnerability in its Web API Server
48RISK
open
Exploit-DB
Fat Free CRM 0.19.0 - HTML Injection
CVE-2019-10226webappsruby28 Mar 2019
HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to th
23RISK
open
Exploit-DBVexDay Proof
CMS Made Simple (CMSMS) Showtime2 - File Upload Remote Code Execution (Metasploit)
CVE-2019-9692remotephp28 Mar 2019
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RISK
open
Exploit-DBVexDay Proof
Oracle Weblogic Server Deserialization RCE - Raw Object (Metasploit)
CVE-2015-4852CRITICALunder attackremotemultiple28 Mar 2019
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISK
open
Exploit-DB
i-doit 1.12 - 'qr.php' Cross-Site Scripting
CVE-2019-6965webappsphp28 Mar 2019
An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.
23RISK
open
Exploit-DB
Thomson Reuters Concourse & Firm Central < 2.13.0097 - Directory Traversal / Local File Inclusion
CVE-2019-8385webappswindows28 Mar 2019
An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and loca
28RISK
open
Metasploit600
AIS logistics ESEL-Server Unauth SQL Injection RCE
CVE-2019-1012327 Mar 2019
SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app)
50RISK
open
Metasploit600
AwindInc SNMP Service Command Injection
CVE-2017-1670927 Mar 2019
Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote
60RISK
open
GitHub PoC
cve-2016-9838
CVE-2016-983827 Mar 2019
An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of
28RISK
open
GitHub PoC
cve-2019-5420
CVE-2019-542027 Mar 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
GitHub PoC
stillan00b/CVE-2019-5736
CVE-2019-573627 Mar 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
Exploit-DB
Firefox < 66.0.1 - 'Array.prototype.slice' Buffer Overflow
CVE-2019-9810dosmultiple26 Mar 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISK
open
Exploit-DB
Microsoft Windows 7/2008 - 'Win32k' Denial of Service (PoC)
CVE-2019-0808HIGHunder attackdoswindows26 Mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
previouspage 844 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.