Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
79,305 exploits
Exploit-DBVexDay Proof
CMS Made Simple Showtime2 Module 3.6.2 - (Authenticated) Arbitrary File Upload
CVE-2019-9692webappsphp15 Mar 2019
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RISK
open
Exploit-DB
Moodle 3.4.1 - Remote Code Execution
CVE-2018-1133webappsphp15 Mar 2019
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec
35RISK
open
GitHub PoC
cve-2019-9194
CVE-2019-919415 Mar 2019
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open
GitHub PoC
cve-2019-9184
CVE-2019-918415 Mar 2019
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr
23RISK
open
GitHub PoC
The exploit python script for CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware15 Mar 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware15 Mar 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
Exploit-DB
Vembu Storegrid Web Interface 4.4.0 - Multiple Vulnerabilities
CVE-2014-10079webappsphp15 Mar 2019
In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hid
23RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware15 Mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
Exploit-DB
Vembu Storegrid Web Interface 4.4.0 - Multiple Vulnerabilities
CVE-2014-10078webappsphp15 Mar 2019
Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfa
23RISK
open
GitHub PoC1
原创作者:Bearcat@secfree.com
CVE-2017-10271HIGHunder attackransomware15 Mar 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
Exploit-DB
FTPGetter Standard 5.97.0.177 - Remote Code Execution
CVE-2019-9760remotewindows14 Mar 2019
FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-cont
50RISK
open
Exploit-DB
Microsoft Windows MSHTML Engine - 'Edit' Remote Code Execution
CVE-2019-0541HIGHunder attacklocalwindows13 Mar 2019
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML E
83RISK
open
Exploit-DBVexDay Proof
Apache Tika-server < 1.18 - Command Injection
CVE-2018-1335remotewindows13 Mar 2019
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
Exploit-DBVexDay Proof
elFinder PHP Connector < 2.1.48 - 'exiftran' Command Injection (Metasploit)
CVE-2019-9194remotephp13 Mar 2019
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open
Exploit-DB
pfSense 2.4.4-p1 (HAProxy Package 0.59_14) - Persistent Cross-Site Scripting
CVE-2019-8953webappsphp13 Mar 2019
The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, re
35RISK
open
Exploit-DB
WordPress Plugin GraceMedia Media Player 1.0 - Local File Inclusion
CVE-2019-9618webappsphp13 Mar 2019
The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter.
50RISK
open
Metasploit600
Zimbra Collaboration Autodiscover Servlet XXE and ProxyServlet SSRF
CVE-2019-9670CRITICALunder attack13 Mar 2019
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open
Metasploit600
Zimbra Collaboration Autodiscover Servlet XXE and ProxyServlet SSRF
CVE-2019-9621HIGHunder attack13 Mar 2019
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RISK
open
Metasploit600
Ruby On Rails DoubleTap Development Mode secret_key_base Vulnerability
CVE-2019-542013 Mar 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
Metasploit300
Microsoft Windows NtUserMNDragOver Local Privilege Elevation
CVE-2019-0808HIGHunder attack12 Mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
GitHub PoC
Bits generated while analyzing CVE-2019-6340 Drupal RESTful RCE
CVE-2019-6340HIGHunder attack12 Mar 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
Exploit-DB
Flexpaper PHP Publish Service 2.3.6 - Remote Code Execution
CVE-2018-11686webappsphp11 Mar 2019
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_c
50RISK
open
GitHub PoC
AeolusTF/CVE-2018-20250
CVE-2018-20250HIGHunder attackransomware11 Mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
Exploit-DB
PRTG Network Monitor 18.2.38 - (Authenticated) Remote Code Execution
CVE-2018-9276HIGHunder attackwebappswindows11 Mar 2019
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
GitHub PoC16
CVE-2018-19276 - OpenMRS Insecure Object Deserialization RCE
CVE-2018-19276CRITICAL11 Mar 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware11 Mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-19276CRITICAL11 Mar 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISK
open
Exploit-DB
Linux Kernel 4.4 (Ubuntu 16.04) - 'snd_timer_user_ccallback()' Kernel Pointer Leak
CVE-2016-4578doslinux11 Mar 2019
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local us
23RISK
open
Metasploit300
Pimcore Unserialize RCE
CVE-2019-1086711 Mar 2019
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/c
50RISK
open
Metasploit300
CMS Made Simple (CMSMS) Showtime2 File Upload RCE
CVE-2019-969211 Mar 2019
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RISK
open
previouspage 847 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.