Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,381cataloged exploits
36,530CVEs with public exploitation
24,695lab-tested
79,305 exploits
Exploit-DB
Rukovoditel ERP & CRM 2.4.1 - 'path' Cross-Site Scripting
CVE-2019-7400webappsphp26 Mar 2019
Rukovoditel before 2.4.1 allows XSS.
23RISK
open
Exploit-DB
Firefox < 66.0.1 - 'Array.prototype.slice' Buffer Overflow
CVE-2019-9810dosmultiple26 Mar 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISK
open
Exploit-DBVexDay Proof
Spidermonkey - IonMonkey Type Inference is Incorrect for Constructors Entered via OSR
CVE-2019-9791dosmultiple26 Mar 2019
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects w
28RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0808HIGHunder attack25 Mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
VulnCheck XDB
client-side
CVE-2019-9978MEDIUMunder attack25 Mar 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC8
CVE-2019-9978 - RCE on a Wordpress plugin: Social Warfare < 3.5.3
CVE-2019-9978MEDIUMunder attack25 Mar 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC47
cve-2019-0808-poc
CVE-2019-0808HIGHunder attack25 Mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
Exploit-DBVexDay Proof
VMware Workstation 14.1.5 / VMware Player 15.0.2 - Host VMX Process Impersonation Hijack Privilege Escalation
CVE-2018-5511localwindows25 Mar 2019
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Manageme
28RISK
open
GitHub PoC67
Array.prototype.slice wrong alias information.
CVE-2019-981025 Mar 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISK
open
Metasploit600
Atlassian Confluence Widget Connector Macro Velocity Template Injection
CVE-2019-3396CRITICALunder attackransomware25 Mar 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
Exploit-DBVexDay Proof
VMware Workstation 14.1.5 / VMware Player 15 - Host VMX Process COM Class Hijack Privilege Escalation
CVE-2019-5512localwindows25 Mar 2019
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately
23RISK
open
Metasploit600
Horde Form File Upload Vulnerability
CVE-2019-985824 Mar 2019
Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulner
23RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware24 Mar 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC1
CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware24 Mar 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC129
CVE-2019-0604
CVE-2019-0604CRITICALunder attackransomware23 Mar 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-5418HIGHunder attack23 Mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC132
RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)
CVE-2019-5418HIGHunder attack23 Mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware22 Mar 2019
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
PoC Scan. (cve-2011-3368)
CVE-2011-336822 Mar 2019
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does
60RISK
open
GitHub PoC
CVE-2017-5638 (PoC Exploits)
CVE-2017-5638CRITICALunder attackransomware22 Mar 2019
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
Exploit-DB
Canarytokens 2019-03-01 - Detection Bypass
CVE-2019-9768doswindows21 Mar 2019
Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timesta
28RISK
open
Exploit-DB
DVD X Player 5.5.3 - '.plf' Buffer Overflow
CVE-2018-9128localwindows21 Mar 2019
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISK
open
Metasploit0
Chrome 72.0.3626.119 FileReader UaF exploit for Windows 7 x86
CVE-2019-5786MEDIUMunder attack21 Mar 2019
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISK
open
VulnCheck XDB
initial-access
CVE-2016-009521 Mar 2019
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RISK
open
Exploit-DB
Rails 5.2.1 - Arbitrary File Content Disclosure
CVE-2019-5418HIGHunder attackwebappsmultiple21 Mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC8
CVE-2019-5420 (Ruby on Rails)
CVE-2019-542021 Mar 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
GitHub PoC255
FileReader Exploit
CVE-2019-5786MEDIUMunder attack20 Mar 2019
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISK
open
GitHub PoC14
GUI版 EXP
CVE-2018-133520 Mar 2019
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
Exploit-DB
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Request Forgery
CVE-2019-6282webappshardware20 Mar 2019
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpag
23RISK
open
GitHub PoC6
CVE-2018-11686 - FlexPaper PHP Publish Service RCE <= 2.3.6
CVE-2018-1168620 Mar 2019
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_c
50RISK
open
previouspage 845 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.