Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
79,305 exploits
Exploit-DB
Cisco WebEx Meetings < 33.6.6 / < 33.9.1 - Privilege Escalation
CVE-2019-1674HIGHlocalwindows01 Mar 2019
Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools Update Service Command Injection Vulnerability
46RISK
open
Exploit-DB
WebKitGTK 2.23.90 / WebKitGTK+ 2.22.6 - Denial of Service
CVE-2019-8375doslinux28 Feb 2019
The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products
28RISK
open
GitHub PoC2
STP5940/CVE-2018-20250
CVE-2018-20250HIGHunder attackransomware28 Feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
Exploit-DBVexDay Proof
Joomla! Component J2Store < 3.3.7 - SQL Injection
CVE-2019-9184webappsphp28 Feb 2019
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr
23RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware28 Feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC
yyqs2008/CVE-2019-5736-PoC-2
CVE-2019-573628 Feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
Exploit-DB
Alcatel-Lucent (Nokia) GPON I-240W-Q - Buffer Overflow
CVE-2019-3921remotehardware28 Feb 2019
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via
28RISK
open
Metasploit400
Cisco RV110W/RV130(W)/RV215W Routers Management Interface Remote Command Execution
CVE-2019-1663CRITICAL27 Feb 2019
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISK
open
Exploit-DB
PHP 7.2 - 'imagecolormatch()' Out of Band Heap Write
CVE-2019-6977remotephp27 Feb 2019
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch funct
45RISK
open
GitHub PoC2
Demonstration of the Heartbleed Bug CVE-2014-0160
CVE-2014-0160HIGHunder attack27 Feb 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
Metasploit600
elFinder PHP Connector exiftran Command Injection
CVE-2019-919426 Feb 2019
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open
GitHub PoC
cve-2019-6340
CVE-2019-6340HIGHunder attack26 Feb 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
Exploit-DB
zzzphp CMS 1.6.1 - Remote Code Execution
CVE-2019-9041webappsphp25 Feb 2019
An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filter
50RISK
open
GitHub PoC73
A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.
CVE-2019-894225 Feb 2019
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISK
open
GitHub PoC12
CVE-2019-6340 POC Drupal rce
CVE-2019-6340HIGHunder attack25 Feb 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
GitHub PoC2
CVE-2019-6340 Drupal 8.6.9 REST Auth Bypass examples
CVE-2019-6340HIGHunder attack25 Feb 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
Exploit-DB
Drupal < 8.6.9 - REST Module Remote Code Execution
CVE-2019-6340HIGHunder attackwebappsphp25 Feb 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
Exploit-DB
Jenkins Plugin Script Security 1.49/Declarative 1.3.4/Groovy 2.60 - Remote Code Execution
CVE-2018-1999002webappsjava25 Feb 2019
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewor
45RISK
open
Exploit-DB
Jenkins Plugin Script Security 1.49/Declarative 1.3.4/Groovy 2.60 - Remote Code Execution
CVE-2019-1003000webappsjava25 Feb 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
GitHub PoC153
🐱‍💻 Poc of CVE-2019-7238 - Nexus Repository Manager 3 Remote Code Execution 🐱‍💻
CVE-2019-7238CRITICALunder attack24 Feb 2019
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-7238CRITICALunder attack24 Feb 2019
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-6340HIGHunder attack23 Feb 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware23 Feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC21
Proof of concept code in C# to exploit the WinRAR ACE file extraction path (CVE-2018-20250).
CVE-2018-20250HIGHunder attackransomware23 Feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
Exploit-DB
Drupal < 8.6.10 / < 8.5.11 - REST Module Remote Code Execution
CVE-2019-6340HIGHunder attackwebappsphp23 Feb 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
GitHub PoC42
Environment for CVE-2019-6340 (Drupal)
CVE-2019-6340HIGHunder attack23 Feb 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
Exploit-DBVexDay Proof
Micro Focus Filr 3.4.0.217 - Path Traversal / Local Privilege Escalation
CVE-2019-3474MEDIUMwebappslinux22 Feb 2019
Path traversal vulnerability in Filr web application
33RISK
open
Exploit-DB
WebKit JSC - reifyStaticProperty Needs to set the PropertyAttribute::CustomAccessor flag for CustomGetterSetter
CVE-2019-6215dosmultiple22 Feb 2019
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safa
23RISK
open
Exploit-DBVexDay Proof
Nuuo Central Management - (Authenticated) SQL Server SQL Injection (Metasploit)
CVE-2018-18982remotewindows22 Feb 2019
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can b
50RISK
open
Exploit-DBVexDay Proof
Micro Focus Filr 3.4.0.217 - Path Traversal / Local Privilege Escalation
CVE-2019-3475HIGHwebappslinux22 Feb 2019
Local privilege escalation in Filr famtd
41RISK
open
previouspage 849 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.