Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
14,014 exploits
GitHub PoC6
NVMS 1000 - Directory Traversal Attack Exploit for CVE-2019-20085
CVE-2019-20085HIGHunder attack15 Apr 2020
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISK
open
GitHub PoC37
A HTTP PoC Endpoint for cve-2020-5260 which can be deployed to Heroku
CVE-2020-5260CRITICAL15 Apr 2020
malicious URLs may cause Git to present stored credentials to the wrong server
53RISK
open
GitHub PoC4
Vuln Check
CVE-2020-3952CRITICALunder attack15 Apr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
GitHub PoC
https://bugs.chromium.org/p/project-zero/issues/detail?id=2021
CVE-2020-5260CRITICAL15 Apr 2020
malicious URLs may cause Git to present stored credentials to the wrong server
53RISK
open
GitHub PoC
This tool helps scan large subnets for cve-2020-0796 vulnerable systems
CVE-2020-0796CRITICALunder attackransomware14 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC27
patches for SNYK-JS-JQUERY-565129, SNYK-JS-JQUERY-567880, CVE-2020-1102, CVE-2020-11023, includes the patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428
CVE-2019-1135814 Apr 2020
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISK
open
GitHub PoC19
Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)
CVE-2018-19320HIGHunder attackransomware13 Apr 2020
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISK
open
GitHub PoC
Reproduction of privilege escalation breach CVE-2019-3010
CVE-2019-3010HIGHunder attack13 Apr 2020
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RISK
open
GitHub PoC2
https://bugs.chromium.org/p/project-zero/issues/detail?id=1820
CVE-2019-11707HIGHunder attack13 Apr 2020
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RISK
open
GitHub PoC8
CVE-2018-7600【Drupal7】批量扫描工具。
CVE-2018-7600CRITICALunder attackransomware12 Apr 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC1
Code execution for CVE-2017-11176
CVE-2017-1117610 Apr 2020
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISK
open
GitHub PoC
This Repository use to test Apache Killer (cve-2011-3192).
CVE-2011-319209 Apr 2020
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISK
open
GitHub PoC25
CVE-2020-10199、CVE-2020-10204漏洞一键检测工具,图形化界面。CVE-2020-10199 and CVE-2020-10204 Vul Tool with GUI.
CVE-2020-10199HIGHunder attack08 Apr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
GitHub PoC35
CVE-2020-10199、CVE-2020-10204、CVE-2020-11444
CVE-2020-10199HIGHunder attack08 Apr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
GitHub PoC19
CVE-2020-10199 CVE-2020-10204 Python POC
CVE-2020-10199HIGHunder attack07 Apr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
GitHub PoC7
CVE-2020-0796 (SMBGhost) LPE
CVE-2020-0796CRITICALunder attackransomware07 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC8
CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本
CVE-2018-7600CRITICALunder attackransomware07 Apr 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC75
Cobalt Strike AggressorScripts CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware06 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
CVE-2017-10271
CVE-2017-10271HIGHunder attackransomware06 Apr 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC
Known security vulnerabilities detected. CVE-2022-21831 Critical severity CVE-2025-24293 Critical severity CVE-2020-8162 High severity CVE-2024-26144 Moderate severity
CVE-2025-24293CRITICAL05 Apr 2020
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote
48RISK
open
GitHub PoC2
CVE-2020-0688 "Microsoft Exchange default MachineKeySection deserialize vulnerability"
CVE-2020-0688HIGHunder attackransomware05 Apr 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC4
XAMPP - CVE-2020-11107
CVE-2020-1110705 Apr 2020
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged
28RISK
open
GitHub PoC6
Laravel-PHP-Unit-RCE (CVE-2018-15133) Auto Exploiter and Shell Uploader
CVE-2018-15133HIGHunder attack05 Apr 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC27
PoCs for CVE-2020-11108; an RCE and priv esc in Pi-hole
CVE-2020-1110804 Apr 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISK
open
GitHub PoC2
rhbb/CVE-2019-17671
CVE-2019-1767103 Apr 2020
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is m
50RISK
open
GitHub PoC31
This is a writeup for CVE-2020-11107 reported by Maximilian Barz
CVE-2020-1110703 Apr 2020
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged
28RISK
open
GitHub PoC1
rhbb/CVE-2019-7609
CVE-2019-7609CRITICALunder attack03 Apr 2020
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
GitHub PoC33
该资源为CVE-2020-0796漏洞复现,包括Python版本和C++版本。主要是集合了github大神们的资源,希望您喜欢~
CVE-2020-0796CRITICALunder attackransomware02 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC1
CVE-2020-0796-EXP
CVE-2020-0796CRITICALunder attackransomware02 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
A simple dos-tool
CVE-1999-001601 Apr 2020
Land IP denial of service.
45RISK
open
previouspage 403 / 468next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.