Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
8,213 exploits
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALunder attack14 Jan 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-6207CRITICALunder attack14 Jan 2021
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-12615HIGHunder attackransomware12 Jan 2021
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware11 Jan 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack10 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1751810 Jan 2021
Apache Flink directory traversal attack: remote file writing through the REST API
50RISK
open
VulnCheck XDB
initial-access
CVE-2020-1751810 Jan 2021
Apache Flink directory traversal attack: remote file writing through the REST API
50RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack08 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack06 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack06 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack06 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
local
CVE-2017-16651HIGHunder attack06 Jan 2021
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RISK
open
VulnCheck XDB
initial-access
CVE-2020-1751806 Jan 2021
Apache Flink directory traversal attack: remote file writing through the REST API
50RISK
open
VulnCheck XDB
initial-access
CVE-2020-798006 Jan 2021
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-10148CRITICALunder attack05 Jan 2021
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-3452HIGHunder attack05 Jan 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-29583CRITICALunder attack04 Jan 2021
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The p
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHunder attackransomware04 Jan 2021
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware01 Jan 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-1040MEDIUM01 Jan 2021
Windows NTLM Tampering Vulnerability
45RISK
open
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALunder attackransomware31 Dec 2020
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-3161CRITICALunder attack31 Dec 2020
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALunder attack30 Dec 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
VulnCheck XDB
client-side
CVE-2020-15999CRITICALunder attack30 Dec 2020
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploi
90RISK
open
VulnCheck XDB
initial-access
CVE-2020-5902CRITICALunder attackransomware30 Dec 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-10148CRITICALunder attack29 Dec 2020
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-6308MEDIUM27 Dec 2020
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated at
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-11652MEDIUMunder attack25 Dec 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2016-3088CRITICALunder attack24 Dec 2020
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware23 Dec 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
previouspage 229 / 274next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.