Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
14,014 exploits
GitHub PoC4,291
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340
CVE-2019-17558HIGHunder attack01 Apr 2020
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RISK
open
GitHub PoC64
jiansiting/CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware01 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC4,291
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340
CVE-2020-14882CRITICALunder attack01 Apr 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC3
nmap script to detect CVE-2020-8515 on Draytek Devices
CVE-2020-8515CRITICALunder attack31 Mar 2020
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RISK
open
GitHub PoC2
SMBGHOST local privilege escalation
CVE-2020-0796CRITICALunder attackransomware31 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
codecat007/CVE-2019-2215
CVE-2019-2215HIGHunder attack31 Mar 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC257
Exploits for Android Binder bug CVE-2020-0041
CVE-2020-0041HIGHunder attack31 Mar 2020
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISK
open
GitHub PoC4
Coronablue exploit
CVE-2020-0796CRITICALunder attackransomware31 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC11
Exploitation Script for CVE-2020-0688 "Microsoft Exchange default MachineKeySection deserialize vulnerability"
CVE-2020-0688HIGHunder attackransomware31 Mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC17
Windows SMBv3 LPE exploit 已编译版
CVE-2020-0796CRITICALunder attackransomware31 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC1,357
CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost
CVE-2020-0796CRITICALunder attackransomware30 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC244
CVE-2020-0796 Local Privilege Escalation POC
CVE-2020-0796CRITICALunder attackransomware30 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
Exploit for the CVE-2019-16278 vulnerability
CVE-2019-16278CRITICALunder attack30 Mar 2020
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC
tripledd/cve-2020-0796-vuln
CVE-2020-0796CRITICALunder attackransomware30 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC14
CVE-2020-8515-PoC
CVE-2020-8515CRITICALunder attack30 Mar 2020
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RISK
open
GitHub PoC1
CVE-2019-17558 Solr模板注入漏洞图形化一键检测工具。CVE-2019-17558 Solr Velocity Template Vul POC Tool.
CVE-2019-17558HIGHunder attack27 Mar 2020
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RISK
open
GitHub PoC7
Icecast Header Overwrite buffer overflow RCE < 2.0.1 (Win32)
CVE-2004-156127 Mar 2020
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISK
open
GitHub PoC8
CVE-2020-1938 / CNVD-2020-1048 Detection Tools
CVE-2020-1938CRITICALunder attack27 Mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC1
CVE 2018-16763
CVE-2018-1676326 Mar 2020
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC118
mzer0one/CVE-2020-7961-POC
CVE-2020-7961CRITICALunder attack26 Mar 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
GitHub PoC20
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.
CVE-2020-937525 Mar 2020
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a
28RISK
open
GitHub PoC
A check for GHOST; cve-2015-0235
CVE-2015-023524 Mar 2020
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RISK
open
GitHub PoC109
quarkslab/CVE-2020-0069_poc
CVE-2020-0069HIGHunder attack24 Mar 2020
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RISK
open
GitHub PoC6
CVE-2017-12636|exploit Couchdb
CVE-2017-1263623 Mar 2020
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISK
open
GitHub PoC1
DoS PoC for CVE-2020-0796 (SMBGhost)
CVE-2020-0796CRITICALunder attackransomware21 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC3
批量检测幽灵猫漏洞
CVE-2020-1938CRITICALunder attack20 Mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC8
Vulnerability scanner for CVE-2020-0688
CVE-2020-0688HIGHunder attackransomware19 Mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC66
An experimental script PoC for Kr00k vulnerability (CVE-2019-15126)
CVE-2019-1512618 Mar 2020
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal
23RISK
open
GitHub PoC1
Scanner CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware17 Mar 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
Lightweight PoC and Scanner for CVE-2020-0796 without authentication.
CVE-2020-0796CRITICALunder attackransomware16 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
previouspage 404 / 468next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.