Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
8,216 exploits
VulnCheck XDB
initial-access
CVE-2020-3952CRITICALunder attack16 Apr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-10199HIGHunder attack16 Apr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-20085HIGHunder attack15 Apr 2020
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISK
open
VulnCheck XDB
infoleak
CVE-2016-6415HIGHunder attack15 Apr 2020
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALunder attack14 Apr 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
local
CVE-2019-3010HIGHunder attack13 Apr 2020
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RISK
open
VulnCheck XDB
initial-access
CVE-2017-0199HIGHunder attackransomware13 Apr 2020
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
VulnCheck XDB
client-side
CVE-2019-11707HIGHunder attack13 Apr 2020
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RISK
open
VulnCheck XDB
local
CVE-2018-19320HIGHunder attackransomware13 Apr 2020
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware12 Apr 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
client-side
CVE-2017-12149CRITICALunder attackransomware08 Apr 2020
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-10199HIGHunder attack08 Apr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-20699CRITICALunder attack08 Apr 2020
Cisco Small Business RV Series Routers Vulnerabilities
100RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware07 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALunder attackransomware07 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-10199HIGHunder attack07 Apr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack07 Apr 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware07 Apr 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
local
CVE-2019-1609807 Apr 2020
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user t
28RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware06 Apr 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
local
CVE-2019-1215HIGHunder attackransomware06 Apr 2020
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Win
76RISK
open
VulnCheck XDB
initial-access
CVE-2018-15133HIGHunder attack05 Apr 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALunder attack03 Apr 2020
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware03 Apr 2020
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
VulnCheck XDB
local
CVE-2018-8120HIGHunder attackransomware01 Apr 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-17558HIGHunder attack01 Apr 2020
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALunder attackransomware01 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware01 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack01 Apr 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-2725HIGHunder attackransomware31 Mar 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
previouspage 244 / 274next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.