Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
14,014 exploits
GitHub PoC5
POC code for CVE-2020-3153 - Cisco anyconnect path traversal vulnerability
CVE-2020-3153MEDIUMunder attackransomware04 May 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RISK
open
GitHub PoC
sumedhaDharmasena/-Kernel-ptrace-c-mishandles-vulnerability-CVE-2019-13272
CVE-2019-13272HIGHunder attack02 May 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC
Billith/CVE-2019-5736-PoC
CVE-2019-573601 May 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC108
Salt security backports for CVE-2020-11651 & CVE-2020-11652
CVE-2020-11651CRITICALunder attack01 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
GitHub PoC6
Checks for CVE-2020-11651 and CVE-2020-11652
CVE-2020-11651CRITICALunder attack01 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
GitHub PoC1
yukar1z0e/CVE-2018-14847
CVE-2018-14847CRITICALunder attack29 Apr 2020
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
GitHub PoC102
Hikvision camera CVE-2017-7921-EXP
CVE-2017-7921CRITICALunder attack27 Apr 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC1
wcxxxxx/CVE-2020-7961
CVE-2020-7961CRITICALunder attack27 Apr 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
GitHub PoC
CVE-2018-15133 (Webased)
CVE-2018-15133HIGHunder attack27 Apr 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC
Sudo Vulnerability CVE-2019-14287
CVE-2019-1428726 Apr 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC2
WordPress CVE-2017-5487 Exploit in Python
CVE-2017-548726 Apr 2020
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISK
open
GitHub PoC7
android-kernel-exploitation-ashfaq-CVE-2019-2215 docker setup for mac users
CVE-2019-2215HIGHunder attack25 Apr 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC
JJSO12/Apache-Pluto-3.0.0--CVE-2018-1306
CVE-2018-130624 Apr 2020
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote a
35RISK
open
GitHub PoC3
PoC RCE Reverse Shell for CVE-2020-0688
CVE-2020-0688HIGHunder attackransomware22 Apr 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC2
snappyJack/pdfresurrect_CVE-2019-14267
CVE-2019-1426722 Apr 2020
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is misha
23RISK
open
GitHub PoC1
3x1t1um/CVE-2007-2447
CVE-2007-244722 Apr 2020
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC
section-c/CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware22 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC11
PoC RCE Reverse Shell for CVE-2020-0796 (SMBGhost)
CVE-2020-0796CRITICALunder attackransomware22 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC36
Whatsapp Automatic Payload Generator [CVE-2019-11932]
CVE-2019-1193222 Apr 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
GitHub PoC2
CVE-2004-1769 cPanel Resetpass Remote Command Execution
CVE-2004-176921 Apr 2020
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x,
35RISK
open
GitHub PoC573
CVE-2020-0796 Remote Code Execution POC
CVE-2020-0796CRITICALunder attackransomware20 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
darren646/CVE-2019-19781POC
CVE-2019-19781CRITICALunder attackransomware20 Apr 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC
kristyna-mlcakova/CVE-2018-10933
CVE-2018-10933CRITICAL19 Apr 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC4
Exploit for CVE-2020-3952 in vCenter 6.7 https://www.guardicore.com/2020/04/pwning-vmware-vcenter-cve-2020-3952/
CVE-2020-3952CRITICALunder attack19 Apr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
GitHub PoC1
D-LINK ROUTER "MODEL NO: DIR-615" with "FIRMWARE VERSION:20.10" & "HARDWARE VERSION:T1
CVE-2019-1752518 Apr 2020
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and
23RISK
open
GitHub PoC2
VMWare vmdir missing access control exploit checker
CVE-2020-3952CRITICALunder attack17 Apr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
GitHub PoC42
CVE-2020-10199 Nexus <= 3.21.1 远程代码执行脚本(有回显)
CVE-2020-10199HIGHunder attack16 Apr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
GitHub PoC11
CVE-2020-5260演示记录
CVE-2020-5260CRITICAL16 Apr 2020
malicious URLs may cause Git to present stored credentials to the wrong server
53RISK
open
GitHub PoC274
Exploit for CVE-2020-3952 in vCenter 6.7
CVE-2020-3952CRITICALunder attack16 Apr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
GitHub PoC28
This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.
CVE-2019-11510CRITICALunder attackransomware16 Apr 2020
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open
previouspage 402 / 468next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.