Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
79,305 exploits
Exploit-DB
WordPress Plugin Wisechat 2.6.3 - Reverse Tabnabbing
CVE-2019-6780webappsphp25 Jan 2019
The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPost
23RISK
open
Exploit-DB
Zyxel NBG-418N v2 Modem 1.00(AAXM.6)C0 - Cross-Site Request Forgery
CVE-2019-6710webappshardware24 Jan 2019
Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.
23RISK
open
Exploit-DBVexDay Proof
Ghostscript 9.26 - Pseudo-Operator Remote Code Execution
CVE-2019-6116remotelinux24 Jan 2019
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to
35RISK
open
Exploit-DB
SirsiDynix e-Library 3.5.x - Cross-Site Scripting
CVE-2018-20503webappscgi24 Jan 2019
Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter.
23RISK
open
GitHub PoC228
CVE-2019-1652 /CVE-2019-1653 Exploits For Dumping Cisco RV320 Configurations & Debugging Data AND Remote Root Exploit!
CVE-2019-1652HIGHunder attack24 Jan 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RISK
open
Metasploit300
Cisco RV320/RV326 Configuration Disclosure
CVE-2019-1653HIGHunder attack24 Jan 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
GitHub PoC370
CVE-2018-8581
CVE-2018-8581HIGHunder attackransomware24 Jan 2019
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RISK
open
VulnCheck XDB
infoleak
CVE-2019-1653HIGHunder attack24 Jan 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-1652HIGHunder attack24 Jan 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-8581HIGHunder attackransomware24 Jan 2019
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RISK
open
GitHub PoC1
This is a exp of CVE-2018-15473
CVE-2018-15473MEDIUM23 Jan 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
Exploit-DB
Nagios XI 5.5.6 - Remote Code Execution / Privilege Escalation
CVE-2018-15710webappslinux23 Jan 2019
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
50RISK
open
Exploit-DB
Nagios XI 5.5.6 - Remote Code Execution / Privilege Escalation
CVE-2018-15708webappslinux23 Jan 2019
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RISK
open
GitHub PoC1
Writeup for CVE-2017-16995 Linux BPF Local Privilege Escalation
CVE-2017-1699522 Jan 2019
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
Exploit-DB
Linux Kernel 4.13 - 'compat_get_timex()' Leak Kernel Pointer
CVE-2018-11508doslinux21 Jan 2019
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitiv
23RISK
open
GitHub PoC1
cve-2018-15961
CVE-2018-15961CRITICALunder attack21 Jan 2019
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open
Metasploit300
Microsoft Exchange Privilege Escalation Exploit
CVE-2019-072421 Jan 2019
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of
23RISK
open
Exploit-DB
GattLib 0.2 - Stack Buffer Overflow
CVE-2019-6498remotelinux21 Jan 2019
GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused.
23RISK
open
GitHub PoC
CVE-2015-2794 auto finder
CVE-2015-279420 Jan 2019
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain S
60RISK
open
VulnCheck XDB
client-side
CVE-2018-4878HIGHunder attackransomware20 Jan 2019
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open
VulnCheck XDB
initial-access
CVE-2018-10562CRITICALunder attackransomware20 Jan 2019
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-8174HIGHunder attackransomware20 Jan 2019
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALunder attackransomware20 Jan 2019
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'NewScObjectNoCtor' or 'InitProto' Type Confusion
CVE-2019-0539doswindows18 Jan 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISK
open
GitHub PoC2
cve-2018-8453 exp
CVE-2018-8453HIGHunder attackransomware18 Jan 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
GitHub PoC119
cve-2018-8453 exp
CVE-2018-8453HIGHunder attackransomware18 Jan 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'InitClass' Type Confusion
CVE-2019-0539doswindows18 Jan 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISK
open
Exploit-DB
Joomla! Core 3.9.1 - Persistent Cross-Site Scripting in Global Configuration Textfilter Settings
CVE-2019-6263webappsphp18 Jan 2019
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allo
23RISK
open
Exploit-DB
Pydio / AjaXplorer < 5.0.4 - (Unauthenticated) Arbitrary File Upload
CVE-2013-6227webappsphp18 Jan 2019
Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly
23RISK
open
GitHub PoC6
praveensutar/CVE-2019-6263-Joomla-POC
CVE-2019-626318 Jan 2019
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allo
23RISK
open
previouspage 854 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.