Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
13,974 exploits
GitHub PoC22
CVE-2020-2551 POC to use in Internet
CVE-2020-2551CRITICALunder attack24 May 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISK
open
GitHub PoC87
QNAP pre-auth root RCE Exploit (CVE-2019-7192 ~ CVE-2019-7195)
CVE-2019-7192CRITICALunder attackransomware24 May 2020
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
100RISK
open
GitHub PoC1
vulnerabilidad CVE-2019-0708 testing y explotacion
CVE-2019-0708CRITICALunder attackransomware23 May 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC5
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS)
CVE-2020-7961CRITICALunder attack23 May 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
GitHub PoC2
CVE-2017-17485:Jackson-databind RCE
CVE-2017-17485CRITICAL22 May 2020
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o
60RISK
open
GitHub PoC
HKirito/phpmyadmin4.4_cve-2016-5734
CVE-2016-573422 May 2020
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RISK
open
GitHub PoC
saltstack CVE-2020-11652
CVE-2020-11652MEDIUMunder attack22 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
GitHub PoC13
Checker for QNAP pre-auth root RCE (CVE-2019-7192 ~ CVE-2019-7195)
CVE-2019-7192CRITICALunder attackransomware21 May 2020
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
100RISK
open
GitHub PoC45
PoC for CVE-2020-8617 (BIND)
CVE-2020-8617HIGH20 May 2020
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RISK
open
GitHub PoC105
Cisco AnyConnect < 4.8.02042 privilege escalation through path traversal
CVE-2020-3153MEDIUMunder attackransomware19 May 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RISK
open
GitHub PoC30
Tool to try multiple paths for PHPunit RCE CVE-2017-9841
CVE-2017-9841CRITICALunder attack18 May 2020
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC
yukar1z0e/CVE-2018-13379
CVE-2018-13379CRITICALunder attackransomware18 May 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
GitHub PoC
TelerikUI Vulnerability Scanner (CVE-2019-18935)
CVE-2019-18935CRITICALunder attackransomware17 May 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC89
Weblogic Vuln POC EXP cve-2020-2551 cve-2020-2555 cve-2020-2883 ,。。。
CVE-2020-2551CRITICALunder attack16 May 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISK
open
GitHub PoC
cdedmondson/Modified-CVE-2015-3306-Exploit
CVE-2015-330615 May 2020
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
GitHub PoC
PoC for CVE-2020-3153 Cisco AnyConnect Secure Mobility Client EoP
CVE-2020-3153MEDIUMunder attackransomware15 May 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RISK
open
GitHub PoC31
CVE-2020-10199 回显版本
CVE-2020-10199HIGHunder attack15 May 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
GitHub PoC
CVE-2018-10933_Scanner
CVE-2018-10933CRITICAL15 May 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC
ES File Explorer Open Port Vulnerability - CVE-2019-6447
CVE-2019-644714 May 2020
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open
GitHub PoC
CVE-2018-20250漏洞利用
CVE-2018-20250HIGHunder attackransomware13 May 2020
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC
teddy47/CVE-2019-13272---Documentation
CVE-2019-13272HIGHunder attack13 May 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC
Microsoft Windows - 'afd.sys' Local Kernel Privilege Escalation Exploit Report (CVE-2011-1249)
CVE-2011-124913 May 2020
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis
23RISK
open
GitHub PoC15
Proof of concept for Weblogic CVE-2020-2883
CVE-2020-2883CRITICALunder attack13 May 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
GitHub PoC1
CVE-2004-1769 // Mass cPanel Reset password
CVE-2004-176913 May 2020
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x,
35RISK
open
GitHub PoC
CVE-2017-8759 | .NET Framework Remote Code Execution Vulnerability
CVE-2017-8759HIGHunder attack12 May 2020
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
GitHub PoC
lalishasanduwara/CVE-2018-10933
CVE-2018-10933CRITICAL12 May 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC1
BimsaraMalinda/Linux-Kernel-4.4.0-Ubuntu---DCCP-Double-Free-Privilege-Escalation-CVE-2017-6074
CVE-2017-607412 May 2020
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RISK
open
GitHub PoC
This is my SNP project where my ID is IT19366128
CVE-2015-132812 May 2020
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
GitHub PoC3
Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287/Google Android - 'Stagefright' Remote Code Execution - CVE-2015-1538
CVE-2015-153812 May 2020
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISK
open
GitHub PoC
This is an individual assignment for secure network programming
CVE-2014-6271CRITICALunder attack12 May 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
previouspage 398 / 466next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.