Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
13,960 exploits
GitHub PoC7
Detection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750
CVE-2020-14882CRITICALunder attack12 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC5
xfiftyone/CVE-2020-14882
CVE-2020-14882CRITICALunder attack12 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC36
海康威视未授权访问检测poc及口令爆破
CVE-2017-7921CRITICALunder attack12 Nov 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC2
A very simple buffer overflow using CVE-2013-4730 against PCman's FTP server
CVE-2013-473012 Nov 2020
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open
GitHub PoC
MuirlandOracle/CVE-2014-6271-IPFire
CVE-2014-6271CRITICALunder attack12 Nov 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC2
基于qt的图形化CVE-2020-14882漏洞回显测试工具.
CVE-2020-14882CRITICALunder attack11 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC7
Weblogic 身份认证绕过漏洞批量检测脚本
CVE-2020-14883HIGHunder attack11 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
The following is the outcome of playing with CVE-2020-1472 and attempting to automate the process of gaining a shell on the DC
CVE-2020-1472MEDIUMunder attackransomware10 Nov 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
datntsec/CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware10 Nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
Dicha vulnerabilidad se presentaba en la funcionalidad mc_project_get_users, y su detección es tan solo modificando y enviando el parámetro “access” sin ningún valor y cambiando el tipo de valor a String.
CVE-2020-28413MEDIUM10 Nov 2020
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the A
33RISK
open
GitHub PoC
HaoJame/CVE-2017-11882
CVE-2017-11882HIGHunder attackransomware10 Nov 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC
Frivolous-scholar/CVE-2017-5941-NodeJS-RCE
CVE-2017-594110 Nov 2020
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISK
open
GitHub PoC7
QmF0c3UK/CVE-2020-14882
CVE-2020-14882CRITICALunder attack09 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC3
[CVE-2020-14882] Oracle WebLogic Server Authentication Bypass
CVE-2020-14882CRITICALunder attack09 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
An automated PoC for CVE 2018-15133
CVE-2018-15133HIGHunder attack09 Nov 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC
kkhacklabs/CVE-2020-14750
CVE-2020-14750CRITICALunder attack09 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC13
[CVE-2020-14882] Oracle WebLogic Server Authenticated Remote Code Execution (RCE)
CVE-2020-14883HIGHunder attack09 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC56
MuirlandOracle/CVE-2019-15107
CVE-2019-15107CRITICALunder attackransomware09 Nov 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC2
Writeup on CVE-2020-28328: SuiteCRM Log File Remote Code Execution plus some bonus Cross-Site Scripting
CVE-2020-2832806 Nov 2020
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain
50RISK
open
GitHub PoC48
PoC para las vulnerabilidades CVE-2020-14750 y cve-2020-14882
CVE-2020-14750CRITICALunder attack06 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
CVE-2020-0796-POC
CVE-2020-0796CRITICALunder attackransomware06 Nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC3
CVE-2020-28351 - Reflected Cross-Site Scripting attack in ShoreTel version 19.46.1802.0.
CVE-2020-2835106 Nov 2020
The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a r
43RISK
open
GitHub PoC
AaronCaiii/CVE-2019-0708-POC
CVE-2019-0708CRITICALunder attackransomware06 Nov 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
mingchen-script/CVE-2020-1472-visualizer
CVE-2020-1472MEDIUMunder attackransomware05 Nov 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC3
mmioimm/cve-2020-14882
CVE-2020-14882CRITICALunder attack05 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC19
CVE-2020-14882/14883/14750
CVE-2020-14882CRITICALunder attack04 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC11
Re-implementation of VirtueSecurity's benigncertain-monitor
CVE-2016-6415HIGHunder attack04 Nov 2020
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RISK
open
GitHub PoC3
CVE-2020-15999
CVE-2020-15999CRITICALunder attack04 Nov 2020
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploi
90RISK
open
GitHub PoC1
CVE-2020-14882 detection script
CVE-2020-14882CRITICALunder attack03 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC13
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to be opened to an arbitrary process.
CVE-2017-976903 Nov 2020
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpe
60RISK
open
previouspage 386 / 466next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.