Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
8,216 exploits
VulnCheck XDB
local
CVE-2020-1054HIGHunder attack09 Aug 2020
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
98RISK
open
VulnCheck XDB
local
CVE-2020-106609 Aug 2020
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privileg
23RISK
open
VulnCheck XDB
local
CVE-2018-8120HIGHunder attackransomware09 Aug 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-0143HIGHunder attackransomware09 Aug 2020
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
VulnCheck XDB
local
CVE-2020-0787HIGHunder attackransomware09 Aug 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISK
open
VulnCheck XDB
local
CVE-2016-322509 Aug 2020
The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
50RISK
open
VulnCheck XDB
local
CVE-2019-1458HIGHunder attackransomware09 Aug 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
VulnCheck XDB
local
CVE-2019-062309 Aug 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
23RISK
open
VulnCheck XDB
local
CVE-2020-0683HIGHunder attack09 Aug 2020
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware09 Aug 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
local
CVE-2015-2546HIGHunder attackransomware09 Aug 2020
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
76RISK
open
VulnCheck XDB
local
CVE-2019-0803HIGHunder attack09 Aug 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
83RISK
open
VulnCheck XDB
local
CVE-2016-0099HIGHunder attackransomware09 Aug 2020
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open
VulnCheck XDB
local
CVE-2016-005109 Aug 2020
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISK
open
VulnCheck XDB
local
CVE-2021-33739HIGHunder attack09 Aug 2020
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
local
CVE-2011-124909 Aug 2020
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis
23RISK
open
VulnCheck XDB
local
CVE-2016-009509 Aug 2020
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RISK
open
VulnCheck XDB
local
CVE-2015-000309 Aug 2020
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
23RISK
open
VulnCheck XDB
local
CVE-2011-2005HIGHunder attack09 Aug 2020
afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly valid
98RISK
open
VulnCheck XDB
local
CVE-2014-4113HIGHunder attack09 Aug 2020
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISK
open
VulnCheck XDB
local
CVE-2019-0808HIGHunder attack09 Aug 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
VulnCheck XDB
local
CVE-2017-0213HIGHunder attackransomware09 Aug 2020
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISK
open
VulnCheck XDB
local
CVE-2015-237009 Aug 2020
The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP
23RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware08 Aug 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-11882HIGHunder attackransomware08 Aug 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALunder attack07 Aug 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
client-side
CVE-2016-9079HIGHunder attack06 Aug 2020
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RISK
open
VulnCheck XDB
client-side
CVE-2017-8570HIGHunder attack06 Aug 2020
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-8816CRITICALunder attack06 Aug 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware06 Aug 2020
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
previouspage 238 / 274next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.