Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
79,386 exploits
Exploit-DB
ZTE MF65 BD_HDV6MF65V1.0.0B05 - Cross-Site Scripting
CVE-2018-7355webappshardware09 Jan 2019
All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scrip
23RISK
open
GitHub PoC678
ES File Explorer Open Port Vulnerability - CVE-2019-6447
CVE-2019-644709 Jan 2019
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2019-100300208 Jan 2019
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RISK
open
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2019-100300508 Jan 2019
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/
23RISK
open
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2018-1000861CRITICALunder attack08 Jan 2019
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISK
open
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2019-100300108 Jan 2019
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RISK
open
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2019-1003029CRITICALunder attack08 Jan 2019
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/
100RISK
open
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2019-100300008 Jan 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
Exploit-DB
Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal
CVE-2018-20526webappsphp07 Jan 2019
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
60RISK
open
GitHub PoC
poc for 0263
CVE-2017-0263HIGHunder attack07 Jan 2019
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
76RISK
open
Exploit-DB
MyBB OUGC Awards Plugin 1.8.3 - Persistent Cross-Site Scripting
CVE-2019-3501webappsphp07 Jan 2019
The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via a crafted award reason that is mishandled on the awards pag
23RISK
open
Exploit-DB
Ajera Timesheets 9.10.16 - Deserialization of Untrusted Data
CVE-2018-20221webappswindows07 Jan 2019
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserializ
28RISK
open
Exploit-DB
Huawei E5330 21.210.09.00.158 - Cross-Site Request Forgery (Send SMS)
CVE-2014-5395webappshardware07 Jan 2019
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13S
23RISK
open
GitHub PoC12
漏洞利用工具
CVE-2018-2628CRITICALunder attack07 Jan 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALunder attack07 Jan 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
Exploit-DB
Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal
CVE-2018-20525webappsphp07 Jan 2019
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
28RISK
open
Exploit-DB
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Scripting
CVE-2018-20326webappscgi07 Jan 2019
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage
23RISK
open
Exploit-DB
KioWare Server Version 4.9.6 - Weak Folder Permissions Privilege Escalation
CVE-2018-18435localwindows07 Jan 2019
KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any
23RISK
open
Exploit-DB
LayerBB 1.1.1 - Persistent Cross-Site Scripting
CVE-2018-17997webappsphp07 Jan 2019
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
23RISK
open
GitHub PoC
cve-2014-6271
CVE-2014-6271CRITICALunder attack06 Jan 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
cve-2018-11776
CVE-2018-11776HIGHunder attack06 Jan 2019
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
GitHub PoC
cve-2018-7600
CVE-2018-7600CRITICALunder attackransomware06 Jan 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
cve-2015-5602
CVE-2015-560206 Jan 2019
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d
23RISK
open
GitHub PoC
CVE-2018-6389 PoC node js multisite with proxy
CVE-2018-638906 Jan 2019
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC
cve-2015-1427
CVE-2015-1427CRITICALunder attack06 Jan 2019
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISK
open
GitHub PoC
cve-2016-7434
CVE-2016-743406 Jan 2019
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a craf
35RISK
open
GitHub PoC
cve-2016-6515
CVE-2016-651506 Jan 2019
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RISK
open
GitHub PoC
CVE-2009-1324 - ASX to MP3 Converter Local Buffer Overflow. Tested on Windows XP Professional SP3
CVE-2009-132406 Jan 2019
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RISK
open
GitHub PoC
cve-2015-3306
CVE-2015-330606 Jan 2019
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
GitHub PoC
cve-2014-0160
CVE-2014-0160HIGHunder attack06 Jan 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
previouspage 858 / 2,647next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.