- Exploit 2019 -

Exploit  List -  2024  2023  2021  2020  2019  2018


Date

Name

Category

Web

26.12.19

A flaw in Twitter App for Android could have been exploited to take over the account

Android   Exploit  Social

Securityaffairs
22.12.19Hackers Continue to Exploit Cisco ASA Vulnerability Patched Last YearExploit  Vulnerebility

Securityweek

21.12.19

Exploit Kit Starts Pushing Malware Via Fake Adult SitesExploit  Virus

Bleepingcomputer

17.12.19Understanding the Risk of Zero-Day ExploitsExploit

Threatpost

16.12.19New Echobot Variant Exploits 77 Remote Code Execution FlawsBotNet  Exploit

Bleepingcomputer

11.12.19

Microsoft Zaps Actively Exploited Zero-Day BugExploit

Threatpost

11.12.19Microsoft Patches Windows Zero-Day Exploited in Korea-Linked AttacksBigBrothers  Exploit  VulnerebilitySecurityweek
11.12.19Windows 0-day exploit CVE-2019-1458 used in Operation WizardOpiumExploitSecurelist

4.12.19

Actively Exploited StrandHogg Vulnerability Affects Android OSAndroid  Exploit

Bleepingcomputer

4.12.19Supply Chain Account Takeover: How Criminals Exploit Third-Party AccessCyberCrime  ExploitThreatpost
3.12.19StrandHogg Vulnerability exploited by tens of rogue Android AppsAndroid  Exploit  VulnerebilitySecurityaffairs
3.12.19'StrandHogg' Vulnerability Exploited by Malicious Android AppsAndroid  Exploit  Vulnerebility

Securityweek

3.12.19Unpatched Strandhogg Android Vulnerability Actively Exploited in the WildAndroid  ExploitThehackernews

26.11.19

PoC exploit code for Apache Solr RCE flaw is available onlineExploit  VulnerebilitySecurityaffairs

25.11.19

Apache Solr RCEs with public PoCs could soon be exploited

Exploit

Net-security

19.11.19

Cheap Chinese JAWS of DVR Exploitability on Port 60001

Exploit

SANS

13.11.19Microsoft Patches Another Internet Explorer Flaw Exploited in AttacksAttack  ExploitSecurityweek

12.11.19

Tech Support Scammers Exploiting Unpatched Firefox BugExploit  VulnerebilitySecurityweek

9.11.19

Legitimate TDS Platform Abused to Push Malware via Exploit KitsExploit

Bleepingcomputer

8.11.19Microsoft: BlueKeep Exploit Will Likely Deliver More Damaging PayloadsExploitSecurityweek
8.11.19Capesand is a new Exploit Kit that appeared in the threat landscapeExploitSecurityaffairs

8.11.19

Actively Developed Capesand Exploit Kit Emerges in AttacksExploitSecurityweek

5.11.19

PoC Exploits Published for Unpatched RCE Bugs in rConfigExploitSecurityweek

5.11.19

Bluekeep exploitation causing Bluekeep vulnerability scan to fail

Exploit

SANS
4.11.19

rConfig Install Directory Remote Code Execution Vulnerability Exploited

Exploit  Vulnerebility

SANS

3.11.19

First Cyber Attack ‘Mass Exploiting’ BlueKeep RDP Flaw Spotted in the WildAttack  ExploitSecurityaffairs

3.11.19

First Cyber Attack 'Mass Exploiting' BlueKeep RDP Flaw Spotted in the WildExploitThehackernews

3.11.19

BlueKeep Remote Code Execution Bug in RDP Exploited En MasseExploit

Bleepingcomputer

3.11.19

Chrome Zero-Day Bug with Exploit in the Wild Gets A PatchExploit  Vulnerebility

Bleepingcomputer

2.11.19

CVE-2019-13720 flaw in Chrome exploited in Operation WizardOpium attacks

Exploit

Securityaffairs

1.11.19

Chrome 0-day exploit CVE-2019-13720 used in Operation WizardOpiumExploit  VulnerebilitySecurelist
1.11.19Chrome Zero-Day Vulnerability Exploited in Korea-Linked AttacksExploit  VulnerebilitySecurityweek
1.11.19Kaspersky researchers found a Chrome 0-day exploited in attacks in the wildExploit  VulnerebilitySecurityaffairs

1.11.19

New Chrome 0-day Bug Under Active Attacks – Update Your Browser Now!Exploit  VulnerebilityThehackernews

28.10.19

PHP RCE flaw actively exploited to pop NGINX servers

Exploit

Net-security

28.10.19

Using scdbg to Find Shellcode

Exploit

SANS

23.10.19

Exploring the CPDoS attack on CDNs: Cache Poisoned Denial of ServiceAttack  ExploitSecurityaffairs

23.10.19

Maxthon Browser Vulnerability Can Help Attackers in Post-Exploitation PhaseExploit  VulnerebilitySecurityweek
18.10.19Researcher Publishes PoC Exploit for Recent Android Zero-DayAndroid  ExploitSecurityweek
18.10.19

As car manufacturers focus on connectivity, hackers begin to exploit flaws

Exploit  Vulnerebility

Net-security

11.10.19

Apple iTunes and iCloud for Windows 0-Day Exploited in Ransomware Attacks

Apple  Exploit  RansomwareThehackernews

10.10.19

HP Touchpoint Analytics Opens PCs to Code Execution Attack

Attack  Exploit

Threatpost

8.10.19

Hackers continue to exploit the Drupalgeddon2 flaw in attacks in the wild

Exploit  Hascking

Securityaffairs

6.10.19

A bug in Signal for Android could be exploited to spy on users

Android  Exploit

Securityaffairs

4.10.19

New 0-Day Flaw Affecting Most Android Phones Being Exploited in the Wild

Android  Exploit

Thehackernews

2.10.19

Malvertising Attack Hijacks 1B+ Sessions With Webkit Exploit

Exploit  Virus

Threatpost

1.10.19

Over A Billion Malicious Ad Impressions Exploit WebKit Flaw to Target Apple UsersExploit  VirusThehackernews

1.10.19

eGobbler Malvertiser Uses WebKit Exploit to Infect Over 1 Billion AdsExploit  Virus

Bleepingcomputer

29.9.19

Cloudflare Now Blocks the vBulletin RCE CVE-2019-16759 ExploitExploit

Bleepingcomputer

28.9.19

Botnet Uses Recent vBulletin Exploit to Block Other HackersBotNet  ExploitBleepingcomputer

27.9.19

Rash of Exploits Targets Critical vBulletin RCE Bug

Exploit

Threatpost

25.9.19Hacker discloses details and PoC exploit code for unpatched 0Day in vBulletinExploit  Vulnersebility

Securityaffairs

25.9.19

Older vulnerabilities and those with lower severity scores still being exploited by ransomware

Exploit Ransomware Vulnerebility

Net-security

24.9.19

1-Click iPhone and Android Exploits Target Tibetan Users via WhatsAppApple  ExploitThehackernews

24.9.19

Microsoft Patches Internet Explorer Vulnerability Exploited in AttacksExploit  Vulnerebility

Securityweek

19.9.19Massive Gaming DDoS Exploits Widespread TechnologyAttack  Exploit

Threatpost

16.9.19

Exploitation of IoT devices and Windows SMB attacks continue to escalate

Exploit  IoT

Net-security

13.9.19

Rig Exploit Kit Delivering VBScript

Exploit

SANS

10.9.19

Exploit Kits Target Windows Users with Ransomware and TrojansExploit  Ransomware

Bleepingcomputer

9.9.19

BlueKeep Exploit Added to MetasploitExploitSecurityweek
8.9.19Public BlueKeep Exploit Module Released by MetaSploitExploit

Bleepingcomputer

8.9.19

Experts add a BlueKeep exploit module to MetaSploit

Exploit

Securityaffairs

4.9.19

Exploit Reseller Offering Up To $2.5 Million For Android Zero-Days

Exploit

Thehackernews

4.9.19

Zerodium Offers Up to $2.5 Million for Android ExploitsExploit  SecuritySecurityweek

25.8.19

Buffer overflow exposes unpatched Squid servers to RCE and DoS attacks

Attack  Exploit

Securityaffairs

24.8.19

WordPress Plugins Exploited in Ongoing Attack, Researchers Warn

Exploit

Threatpost

23.8.19

A new variant of Asruex Trojan exploits very old Office, Adobe flaws

Exploit  Virus

Securityaffairs

23.8.19

Asruex Malware Exploits Old vulnerabilities to Infect PDF, Word Docs

Exploit  Virus

Securityweek

23.8.19

Remote Code Execution Flaws Impact Aspose APIs

Exploit

Securityweek

22.8.19

Cisco warns about public exploit code for critical flaws in its 220 Series smart switches

Exploit

Net-security

12.8.19

Gaining remote code execution using a tainted SQLite database

Exploit

Securityaffairs

9.8.19

New Lord Exploit Kit Pushes njRAT and ERIS Ransomware

Exploit  Ransomware

Bleepingcomputer

7.8.19

The number of exploits in the Echobot botnet reached 59

BotNet  Exploit

Securityaffairs

7.8.19

New Lord Exploit Kit appears in the threat landscape

Exploit

Securityaffairs

7.8.19

New 'Lord' Exploit Kit Emerges

Exploit

Securityweek

6.8.19

Microsoft Lab Offers $300K For Working Azure Exploits

Exploit

Threatpost

4.8.19

SystemBC, a new proxy malware is being distributed via Fallout and RIG EK

Exploit

Securityaffairs

27.7.19

BlueKeep RCE Exploit Module Added to Penetration Testing Tool

Exploit

Bleepingcomputer

24.7.19

Malvertising campaign exploits recently disclosed WordPress Plugin flaws

Exploit  Virus

Securityaffairs

24.7.19

WordPress Plugin Flaws Exploited in Ongoing Malvertising Campaign

Exploit  Virus

Threatpost

23.7.19

Hackers Exploit Recent WordPress Plugin Bugs for Malvertising

Exploit

Bleepingcomputer

23.7.19

Hackers Exploit Jira, Exim Linux Servers to "Keep the Internet Safe'

Exploit

Bleepingcomputer

11.7.19

Bad McAfee Exploit Prevention Update Blocked Windows Logins

Exploit  Hacking

Bleepingcomputer

10.7.19

Rig Exploit Kit Pushing Eris Ransomware in Drive-by Downloads

Exploit  Ransomware

Bleepingcomputer

10.7.19

Two Windows Privilege Escalation Vulnerabilities Exploited in Attacks

Attack  Exploit

Securityweek

29.6.19

New Exploit Kit Spelevo Carries Bag of Old Tricks

Exploit

Bleepingcomputer

28.6.19

New Spelevo Exploit Kit Spreads via B2B Website

Exploit

Securityweek

25.6.19

Rig Exploit Kit sends Pitou.B Trojan

Exploit

SANS

22.6.19

PoC Released for Outlook Flaw that Microsoft Patched 6 Month After Discovery

Exploit

Thehackernews

19.6.19

Firefox Zero-Day Vulnerability Exploited in Targeted Attacks

Exploit

Securityweek

19.6.19

Oracle Warns of New Actively-Exploited WebLogic Flaw

Exploit

Threatpost

19.6.19

Another Oracle WebLogic Server RCE under active exploitation

Exploit

Net-security

18.6.19

Mirai Offspring "Echobot" Uses 26 Different Exploits

Exploit

Securityweek

17.6.19

An infection from Rig exploit kit

Exploit

SANS

8.6.19

SandboxEscaper releases Byebear exploit to bypass patched EoP flaw

Exploit

Securityaffairs

7.6.19

BlackSquid Uses 7 Exploits to Infect Web Servers with Miners

Exploit

Bleepingcomputer

31.5.19

Researcher Exploits Microsoft’s Notepad to ‘Pop a Shell’

Exploit

Threatpost

29.5.19

Unpatched Flaw Affects All Docker Versions, Exploits Ready

Exploit

Bleepingcomputer

26.5.19

Two More Windows 10 Zero-Day PoC Exploits Released, Brings Total to 4

Exploit

Bleepingcomputer

26.5.19

PoC Exploits Released for Two More Windows Vulnerabilities

Exploit

Bleepingcomputer

26.5.19

Researchers Demo PoC For Remote Desktop BlueKeep RCE Exploit

Exploit

Bleepingcomputer

25.5.19

SandboxEscaper Drops Three More Windows Exploits, IE Zero-Day

Exploit

Threatpost

24.5.19

Researcher Drops 3 Separate 0-Day Windows Exploits in 24 Hours

Exploit

Securityweek

24.5.19

PoC Exploits Created for Wormable Windows RDS Flaw

Exploit

Securityweek

24.5.19

Researcher Drops Windows 10 Zero-Day Exploit

Exploit

Securityweek

24.5.19

Update: Hacker Disclosed 4 New Microsoft Zero-Day Exploits in Last 24 Hours

Exploit

Thehackernews

22.5.19

New Zero-Day Exploit for Bug in Windows 10 Task Scheduler

Exploit

Bleepingcomputer

22.5.19

PoC Exploit For Unpatched Windows 10 Zero-Day Flaw Published Online

Exploit

Thehackernews

22.5.19

Is your perimeter inventory leaving you exposed? Why it’s time to switch from IP to DNS

Exploit

Net-security

21.5.19

Faulty Database Script Exposed Salesforce Data to Wrong Users

Exploit

Securityweek

21.5.19

BlueKeep Remote Desktop Exploits Are Coming, Patch Now!

Exploit

Bleepingcomputer

20.5.19

Google Starts Tracking Zero-Days Exploited in the Wild

Exploit

Securityweek

17.5.19

Google ‘0Day In the Wild’ project tracks zero-days exploited in the Wild

Exploit

Securityaffairs

11.5.19

FIN7 Linked to Escalating Active Exploits for Microsoft SharePoint Bug

Exploit

Threatpost

3.5.19

Public 10KBLAZE Exploits May Impact 90% of SAP Production Systems

Exploit

Bleepingcomputer

3.5.19

AA19-122A : New Exploits for Unsecure SAP Systems

Exploit

CERT

3.5.19

10KBLAZE exploits could affect 9 out of 10 SAP installs of more than 50k customers

Exploit

Securityaffairs

3.5.19

PoC Exploits for Old SAP Configuration Flaws Increase Risk of Attacks

Exploit

Securityweek

2.5.19

50,000 companies running SAP installations open to attack via publicly released exploits

Exploit

Net-security

29.4.19

Oracle Patches WebLogic Zero-Day Exploited in Attacks

Exploit

Securityweek

28.4.19

Experts release PoC exploit for unpatched flaw in WordPress WooCommerce Extension

Exploit

Securityaffairs

27.4.19

Quick Tip for Dissecting CVE-2017-11882 Exploits

Exploit

SANS

26.4.19

Leaked Carbanak Source Code Reveals No New Exploits

Exploit

Securityweek

24.4.19

Hackers Actively Exploiting Widely-Used Social Share Plugin for WordPress

Exploit

Thehackernews

24.4.19

Exploits for Social Warfare WordPress Plugin Reach Critical Mass

Exploit

Threatpost

22.4.19

.rar Files and ACE Exploit CVE-2018-20250

Exploit

SANS

17.4.19

Windows Zero-Day Emerges in Active Exploits

Exploit

Threatpost

17.4.19

Researcher Took Control of Microsoft's Live Tile Service, Defacement PoC Demoed

Exploit

Bleepingcomputer

16.4.19

Adblock Plus filter can be exploited to execute arbitrary code in web pages

Exploit

Securityaffairs

16.4.19

CVE-2019-0803 Windows flaw exploited to deliver PowerShell Backdoor

Exploit

Securityaffairs

15.4.19

Windows Flaw Exploited to Deliver PowerShell Backdoor

Exploit

Securityweek

12.4.19

Zero-day in popular Yuzo Related Posts WordPress Plugin exploited in the wild

Exploit

Securityaffairs

12.4.19

WordPress Yellow Pencil Plugin Flaws Actively Exploited

Exploit

Threatpost

12.4.19

WordPress Urges Users to Uninstall Yuzo Plugin After Flaw Exploited

Exploit

Threatpost

12.4.19

Office 365 Team Discovers Phishing Email Pushing WinRAR Exploit

Exploit

Bleepingcomputer

12.4.19

Popular Yuzo WordPress Plugin Exploited to Redirect Users to Scams

Exploit

Bleepingcomputer

10.4.19

Demo Exploit Code Available for Privilege Escalation Bug in Windows

Exploit

Bleepingcomputer

10.4.19

Microsoft Patches Windows Privilege Escalation Flaws Exploited in Attacks

Exploit

Securityweek

9.4.19

Verizon Router Command Injection Flaw Impacts Millions

Exploit

Threatpost

9.4.19

PoC exploit for Carpe Diem Apache bug released

Exploit

Net-security

8.4.19

Magento sites under attack through easily exploitable SQLi flaw

Exploit

Net-security

7.4.19

DoS flaw in several MikroTik Routers exploited in attacks

Exploit

Securityaffairs

7.4.19

Magento Attacked Through Card Skimming Exploit

Exploit

Securityaffairs

6.4.19

Qt5-Based GUI Apps Susceptible to Remote Code Execution

Exploit

Bleepingcomputer

5.4.19

April Patch Tuesday Forecast: Be aware of end-of-service issues and browser exploits

Exploit

Net-security

2.4.19

Financial Apps are Ripe for Exploit via Reverse Engineering

Exploit

Threatpost

25.3.19

WordPress Social Warfare plugin zero-day exploited in attacks

Exploit

Securityaffairs

17.3.19

Over 100 Exploits Found for 19-Year Old WinRAR RCE Bug

Exploit

Bleepingcomputer

16.3.19

Details of Actively Exploited Windows Flaw Made Public

Exploit

Securityweek

14.3.19

Threat Groups SandCat, FruityArmor Exploiting Microsoft Win32k Flaw

Exploit

Threatpost

14.3.19

Windows Zero-Day Exploited by FruityArmor, SandCat Threat Groups

Exploit

Securityweek

13.3.19

Microsoft Patches Two Windows Flaws Exploited in Targeted Attacks

Exploit

Securityweek

9.3.19

How China Exploits Social Media to Influence American Public

Exploit

Securityweek

7.3.19

Hackers Revive Microsoft Office Equation Editor Exploit

Exploit

Bleepingcomputer

5.3.19

BSides SF 2019: Remote-Root Bug in Logitech Harmony Hub Patched and Explained

Exploit

Threatpost

5.3.19

RSAC 2019: Joomla! Mail Flaw Exploited to Create Mass Phishing Infrastructure

Exploit

Threatpost

4.3.19

Windows Exploit Suggester Lists Known Exploits for Your Windows Install

Exploit

Bleepingcomputer

2.3.19

Adobe Patches Critical ColdFusion Vulnerability With Active Exploit

Exploit

Threatpost

1.3.19

Cisco SOHO wireless VPN firewalls and routers open to attack

Exploit

Net-security

27.2.19

Chrome Zero-Day Exploited to Harvest User Data via PDF Files

Exploit

Securityweek

26.2.19

Latest WinRAR Flaw Being Exploited in the Wild to Hack Windows Computers

Exploit

Thehackernews

26.2.19

Critical WinRAR Flaw Found Actively Being Exploited

Exploit

Threatpost

26.2.19

Latest WinRAR, Drupal flaws under active exploitation

Exploit

Net-security

21.2.19

Expert released a PoC for a remote code execution flaw in mIRC App

Exploit

Securityaffairs

20.2.19

Exposed MongoDB revealed facial recognition abuse for tracking the Uyghur Muslim minority in China.

Exploit

Securityaffairs

20.2.19

Exploit Code Published for Recent Container Escape Vulnerability

Exploit

Securityweek

19.2.19

PoC Exploit Code for recent container escape flaw in runc published online

Exploit

Securityaffairs

4.2.19

Flaw Possibly Affecting 500,000 Ubiquity Devices Exploited in the Wild

Exploit

Securityweek

3.2.19

Scanning for WebDAV PROPFIND Exploiting CVE-2017-7269

Exploit

SANS

31.1.19

Researchers published the PoC exploit code for Linux SystemD bugs

Exploit

Securityaffairs

28.1.19

Hackers are targeting Cisco RV320/RV325, over 9K routers exposed online

Exploit

Securityaffairs

28.1.19

New Exploit Threatens Over 9,000 Hackable Cisco RV320/RV325 Routers Worldwide

Exploit

Thehackernews

28.1.19

Hackers Targeting Cisco RV320/RV325 Routers Using New Exploits

Exploit

Bleepingcomputer

27.1.19

Using steganography to obfuscate PDF exploits

Exploit

Securityaffairs

24.1.19

Attackers Use Steganography to Obfuscate PDF Exploits

Exploit

Securityweek

21.1.19

Websites Can Exploit Browser Extensions to Steal User Data

Exploit

Securityweek

20.1.19

Fallout Exploit Kit is Back with New Vulnerabilities and Payloads

Exploit

Bleepingcomputer

19.1.19

Fallout Exploit Kit now includes exploit for CVE-2018-15982 Flash zero-day

Exploit

Securityaffairs

19.1.19

Exploit for Recent Flash Zero-Day Added to Fallout Exploit Kit

Exploit

Securityweek

19.1.19

Fallout EK Retools for a Fresh New 2019 Look

Exploit

Threatpost

16.1.19

Unprotected VOIP Server Exposed Millions of SMS Messages, Call Logs

Exploit

Thehackernews

16.1.19

Radio frequency remote controller weaknesses have serious safety implications

Exploit

Net-security

15.1.19

Escaping Containers to Execute Commands on Play with Docker Servers

Exploit

Bleepingcomputer