Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
8,216 exploits
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware17 Aug 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHunder attackransomware17 Aug 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-16759CRITICALunder attack16 Aug 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-3452HIGHunder attack13 Aug 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-5902CRITICALunder attackransomware13 Aug 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
VulnCheck XDB
info-leak
CVE-2020-4463HIGH13 Aug 2020
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when proc
68RISK
open
VulnCheck XDB
infoleak
CVE-2016-2386CRITICALunder attack13 Aug 2020
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16759CRITICALunder attack13 Aug 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-6286MEDIUM13 Aug 2020
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuratio
38RISK
open
VulnCheck XDB
initial-access
CVE-2020-6287CRITICALunder attack13 Aug 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-16759CRITICALunder attack12 Aug 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
VulnCheck XDB
local
CVE-2020-104811 Aug 2020
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writin
43RISK
open
VulnCheck XDB
local
CVE-2020-0041HIGHunder attack10 Aug 2020
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISK
open
VulnCheck XDB
initial-access
CVE-2015-4852CRITICALunder attack10 Aug 2020
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware10 Aug 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
local
CVE-2015-2387HIGHunder attack09 Aug 2020
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server
83RISK
open
VulnCheck XDB
local
CVE-2016-0099HIGHunder attackransomware09 Aug 2020
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open
VulnCheck XDB
local
CVE-2017-8464HIGHunder attack09 Aug 2020
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISK
open
VulnCheck XDB
local
CVE-2015-237009 Aug 2020
The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP
23RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack09 Aug 2020
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2018-8639HIGHunder attackransomware09 Aug 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RISK
open
VulnCheck XDB
local
CVE-2015-2546HIGHunder attackransomware09 Aug 2020
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
76RISK
open
VulnCheck XDB
local
CVE-2020-0683HIGHunder attack09 Aug 2020
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RISK
open
VulnCheck XDB
local
CVE-2016-005109 Aug 2020
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISK
open
VulnCheck XDB
local
CVE-2014-407609 Aug 2020
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware09 Aug 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
local
CVE-2011-2005HIGHunder attack09 Aug 2020
afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly valid
98RISK
open
VulnCheck XDB
local
CVE-2017-0101HIGHunder attackransomware09 Aug 2020
The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7
83RISK
open
VulnCheck XDB
local
CVE-2010-333809 Aug 2020
The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7
43RISK
open
VulnCheck XDB
local
CVE-2021-1732HIGHunder attackransomware09 Aug 2020
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
previouspage 237 / 274next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.