Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
13,960 exploits
GitHub PoC145
CVE-2020-14882_ALL综合利用工具,支持命令回显检测、批量命令回显、外置xml无回显命令执行等功能。
CVE-2020-14882CRITICALunder attack03 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC8
(CVE-2020-14882) Oracle Weblogic Unauthorized bypass RCE test script
CVE-2020-14882CRITICALunder attack01 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC13
Exploiting CVE-2014-3153, AKA Towelroot.
CVE-2014-3153HIGHunder attack31 Oct 2020
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
GitHub PoC12
CVE-2020-14882批量验证工具。
CVE-2020-14882CRITICALunder attack31 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC1
CuteNews Avatar 2.1.2 Remote Code Execution Vulnerability
CVE-2019-1144730 Oct 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
GitHub PoC
alexfrancow/CVE-2020-14882
CVE-2020-14882CRITICALunder attack30 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC7
CVE-2020-14882 EXP 回显
CVE-2020-14882CRITICALunder attack29 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC2
Bash script to exploit the Oracle's Weblogic Unauthenticated Remote Command Execution - CVE-2020-14882
CVE-2020-14882CRITICALunder attack29 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC2
Scans for Microsoft Exchange Versions with masscan
CVE-2020-0688HIGHunder attackransomware29 Oct 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC17
CVE-2020-14882 Weblogic-Exp
CVE-2020-14882CRITICALunder attack29 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
Un semplice exploit che sfrutta CVE-2015-7297, CVE-2015-7857 and CVE-2015-7858 per elencare gli utenti con la psw del db
CVE-2015-729729 Oct 2020
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISK
open
GitHub PoC29
CVE-2020–14882 by Jang
CVE-2020-14882CRITICALunder attack28 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC288
CVE-2020–14882、CVE-2020–14883
CVE-2020-14882CRITICALunder attack28 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
Windows 7 LPE
CVE-2020-1054HIGHunder attack28 Oct 2020
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
98RISK
open
GitHub PoC14
PoC for old Binder vulnerability (based on P0 exploit)
CVE-2019-2215HIGHunder attack27 Oct 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC8
POC For CVE-2020-1481 - Jira Username Enumerator/Validator
CVE-2020-1418126 Oct 2020
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
60RISK
open
GitHub PoC
datntsec/CVE-2019-12735
CVE-2019-1273526 Oct 2020
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RISK
open
GitHub PoC2
Python exploit for CVE-2012-2982
CVE-2012-298225 Oct 2020
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
GitHub PoC11
CVE-2020-0688 PoC
CVE-2020-0688HIGHunder attackransomware23 Oct 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC1
PoC for apache struts 2 vuln cve-2019-0230
CVE-2019-023022 Oct 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISK
open
GitHub PoC
puckiestyle/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware21 Oct 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
HYWZ36/CVE-2020-14645-code
CVE-2020-14645CRITICAL21 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISK
open
GitHub PoC
Elsfa7-110/CVE-2019-1579
CVE-2019-1579HIGHunder attackransomware21 Oct 2020
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RISK
open
GitHub PoC2
Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass Exploit/PoC
CVE-2019-17240LOW21 Oct 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
GitHub PoC2
cve-2020-14644 漏洞环境
CVE-2020-14644CRITICALunder attack20 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
GitHub PoC
Exploitable target to CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware19 Oct 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC7
ThinkAdmin CVE-2020-25540 poc
CVE-2020-2554019 Oct 2020
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISK
open
GitHub PoC
datntsec/CVE-2019-13272
CVE-2019-13272HIGHunder attack19 Oct 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC
stealth-ronin/CVE-2017-0199-PY-KIT
CVE-2017-0199HIGHunder attackransomware18 Oct 2020
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC
Exploits CuteNews 2.1.2 via poor file upload checks used when uploading an avatar image leading to RCE.
CVE-2019-1144718 Oct 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
previouspage 387 / 466next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.