Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,385cataloged exploits
36,532CVEs with public exploitation
24,695lab-tested
79,305 exploits
Metasploit600
PostgreSQL COPY FROM PROGRAM Command Execution
CVE-2019-919320 Mar 2019
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
Exploit-DB
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Request Forgery
CVE-2019-6282webappshardware20 Mar 2019
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpag
23RISK
open
GitHub PoC6
CVE-2018-11686 - FlexPaper PHP Publish Service RCE <= 2.3.6
CVE-2018-1168620 Mar 2019
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_c
50RISK
open
GitHub PoC14
GUI版 EXP
CVE-2018-133520 Mar 2019
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
GitHub PoC255
FileReader Exploit
CVE-2019-5786MEDIUMunder attack20 Mar 2019
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISK
open
Exploit-DB
PLC Wireless Router GPN2.4P21-C-CN - Incorrect Access Control
CVE-2019-6279webappshardware20 Mar 2019
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnera
23RISK
open
GitHub PoC
Herramienta para revisar si es que un payload tiene componente malicioso de acuerdo a CVE-2018-20250
CVE-2018-20250HIGHunder attackransomware19 Mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
Exploit-DB
MyBB Upcoming Events Plugin 1.32 - Cross-Site Scripting
CVE-2019-9650webappsphp19 Mar 2019
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name
23RISK
open
Exploit-DBVexDay Proof
Microsoft VBScript - VbsErase Memory Corruption
CVE-2019-0667doswindows19 Mar 2019
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows
35RISK
open
Exploit-DBVexDay Proof
Google Chrome < M73 - FileSystemOperationRunner Use-After-Free
CVE-2019-5788dosmultiple19 Mar 2019
An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allo
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - VBScript Execution Policy Bypass in MSHTML
CVE-2019-0768doswindows19 Mar 2019
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restri
35RISK
open
Exploit-DBVexDay Proof
Google Chrome < M73 - Double-Destruction Race in StoragePartitionService
CVE-2019-5797HIGHdosmultiple19 Mar 2019
Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap c
41RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Flash click2play Bypass with CObjectElement::FinalCreateObject
CVE-2019-0612doswindows19 Mar 2019
A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash obj
28RISK
open
Exploit-DB
Gila CMS 1.9.1 - Cross-Site Scripting
CVE-2019-9647webappsphp19 Mar 2019
Gila CMS 1.9.1 has XSS.
23RISK
open
GitHub PoC36
A multi-threaded Golang scanner to identify Ruby endpoints vulnerable to CVE-2019-5418
CVE-2019-5418HIGHunder attack19 Mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
Exploit-DBVexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
CVE-2019-1003002remotejava19 Mar 2019
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RISK
open
Exploit-DBVexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
CVE-2019-1003001remotejava19 Mar 2019
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RISK
open
Exploit-DBVexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
CVE-2019-1003000remotejava19 Mar 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
Exploit-DBVexDay Proof
Google Chrome < M73 - MidiManagerWin Use-After-Free
CVE-2019-5789dosmultiple19 Mar 2019
An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed
23RISK
open
Exploit-DBVexDay Proof
Google Chrome < M73 - Data Race in ExtensionsGuestViewMessageFilter
CVE-2019-5796dosmultiple19 Mar 2019
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially explo
23RISK
open
Exploit-DBVexDay Proof
BMC Patrol Agent - Privilege Escalation Code Execution Execution (Metasploit)
CVE-2018-20735remotemultiple18 Mar 2019
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for l
38RISK
open
Metasploit300
IBM BigFix Relay Server Sites and Package Enum
CVE-2019-4061MEDIUM18 Mar 2019
IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the upd
33RISK
open
GitHub PoC5
File Content Disclosure on Rails Test Case - CVE-2019-5418
CVE-2019-5418HIGHunder attack18 Mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC7
xConsoIe/CVE-2019-0193
CVE-2019-0193HIGHunder attack18 Mar 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISK
open
GitHub PoC6
thinkphp5.*Rce CVE-2018-20062
CVE-2018-20062CRITICALunder attack17 Mar 2019
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-20062CRITICALunder attack17 Mar 2019
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-5418HIGHunder attack16 Mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC201
CVE-2019-5418 - File Content Disclosure on Ruby on Rails
CVE-2019-5418HIGHunder attack16 Mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC
cve-2019-9184
CVE-2019-918415 Mar 2019
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr
23RISK
open
GitHub PoC
cve-2019-9194
CVE-2019-919415 Mar 2019
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open
previouspage 846 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.