Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,894cataloged exploits
35,202CVEs with public exploitation
24,695lab-tested
13,960 exploits
GitHub PoC5
C# Vulnerability Checker for CVE-2020-1472 Aka Zerologon
CVE-2020-1472MEDIUMunder attackransomware17 Oct 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
Converted with tweaks from a metasploit module as an exercise for OSCP studying and exploit development
CVE-2015-330616 Oct 2020
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
GitHub PoC3
CVE-2019–15107 - Unauthenticated RCE Webmin <=1.920
CVE-2019-15107CRITICALunder attackransomware15 Oct 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC
Check for events that indicate non compatible devices -> CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware15 Oct 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC2
FancyDoesSecurity/CVE-2020-2883
CVE-2020-2883CRITICALunder attack14 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
GitHub PoC10
BlueBorne Exploits & Framework This repository contains a PoC code of various exploits for the BlueBorne vulnerabilities. Under 'android' exploits for the Android RCE vulnerability (CVE-2017-0781), and the SDP Information leak vulnerability (CVE-2017-0785) can be found. Under 'linux-bluez' exploits for the Linux-RCE vulnerability (CVE-2017-1000251) can be found (for Amazon Echo, and Samsung Gear S3). Under 'l2cap_infra' a general testing framework to send and receive raw l2cap messages (using scapy) can be found. Under 'nRF24_BDADDR_Sniffer' a tool to capture bluetooth mac addresses (BDADDR) over the air, using a nRF24L01 chip For more details on BlueBorne, you may read the full technical white paper available here: https://www.armis.com/blueborne/ In addition a several detailed blog posts on the exploitation of these vulnerability can be found here: https://www.armis.com/blog/ =============== Dependencies:
CVE-2017-078112 Oct 2020
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISK
open
GitHub PoC58
https://medium.com/@mansoorr/exploiting-cve-2020-25213-wp-file-manager-wordpress-plugin-6-9-3f79241f0cd8
CVE-2020-25213CRITICALunder attack10 Oct 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
GitHub PoC2
shanfenglan/cve-2020-1472
CVE-2020-1472MEDIUMunder attackransomware10 Oct 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC4
n3m1sys/CVE-2018-16763-Exploit-Python3
CVE-2018-1676310 Oct 2020
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC2
提供单个或批量URL扫描是否存在CVE-2022-22954功能
CVE-2022-22954CRITICALunder attackransomware09 Oct 2020
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
GitHub PoC5
Typesetter CMS文件上传漏洞环境
CVE-2020-2579009 Oct 2020
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archi
28RISK
open
GitHub PoC7
EternalBlue is a well-known SMB exploit created by the NSA to attack various versions of Windows, including Windows 7. Etern-Blue-Windows-7-Checker will basically send SMB packets to a host to see if that Windows host machine is vulnerable to the EternalBlue exploit (CVE-2017-0143).
CVE-2017-0143HIGHunder attackransomware07 Oct 2020
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
Bludit 3.9.2 - Remote command execution - CVE-2019-16113
CVE-2019-1611307 Oct 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISK
open
GitHub PoC2
coldfusion exploit based on https://cvedetails.com/cve/CVE-2009-2265/
CVE-2009-226502 Oct 2020
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISK
open
GitHub PoC
Ken-Abruzzi/CVE-2020-0674
CVE-2020-0674HIGHunder attack30 Sep 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISK
open
GitHub PoC2
Protect your domain controllers against Zerologon (CVE-2020-1472).
CVE-2020-1472MEDIUMunder attackransomware30 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC5
CVE-2019-18935
CVE-2019-18935CRITICALunder attackransomware30 Sep 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC
Ken-Abruzzi/cve-2020-1472
CVE-2020-1472MEDIUMunder attackransomware30 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC11
POC for checking multiple hosts for Zerologon vulnerability
CVE-2020-1472MEDIUMunder attackransomware29 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC22
Zerologon AutoExploit Tool | CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware29 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware28 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC24
Just basic scanner abusing CVE-2020-3452 to enumerate the standard files accessible in the Web Directory of the CISCO ASA applicances.
CVE-2020-3452HIGHunder attack28 Sep 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC3
To crash Windows-10 easily
CVE-2020-0796CRITICALunder attackransomware28 Sep 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
Fa1c0n35/CVE-2020-1472-02-
CVE-2020-1472MEDIUMunder attackransomware28 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC5
striveben/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware26 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC42
PoCs and technical analysis of three vulnerabilities found on Cisco AnyConnect for Windows: CVE-2020-3433, CVE-2020-3434 and CVE-2020-3435
CVE-2020-3433HIGHunder attackransomware25 Sep 2020
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
91RISK
open
GitHub PoC
This repository holds the advisory, exploits and vulnerable software of the CVE-2020-15492
CVE-2020-1549224 Sep 2020
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe we
28RISK
open
GitHub PoC
CVE 2020-1472 Script de validación
CVE-2020-1472MEDIUMunder attackransomware24 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, City
CVE-2020-2527023 Sep 2020
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, o
23RISK
open
GitHub PoC
t31m0/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware21 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
previouspage 388 / 466next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.