Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,044cataloged exploits
35,296CVEs with public exploitation
24,695lab-tested
14,014 exploits
GitHub PoC11
HumanSecurity/CVE-2019-18426
CVE-2019-18426HIGHunder attack29 Feb 2020
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.
83RISK
open
GitHub PoC337
Weblogic IIOP CVE-2020-2551
CVE-2020-2551CRITICALunder attack28 Feb 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISK
open
GitHub PoC10
CVE-2020-0688
CVE-2020-0688HIGHunder attackransomware28 Feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC1
I made this script for conducting CVE-2020-0688 more rapidly. It helps to improve checking the vuln, reducing hugely steps for that
CVE-2020-0688HIGHunder attackransomware28 Feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC37
Quick tool for checking CVE-2020-0688 on multiple hosts with a non-intrusive method.
CVE-2020-0688HIGHunder attackransomware28 Feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC2
Exchange Scanner CVE-2020-0688
CVE-2020-0688HIGHunder attackransomware27 Feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC328
cve-2020-0688
CVE-2020-0688HIGHunder attackransomware27 Feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC144
CVE-2020-0688_EXP Auto trigger payload & encrypt method
CVE-2020-0688HIGHunder attackransomware27 Feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC5
Disclosure report of CVE-2020-9038
CVE-2020-903827 Feb 2020
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
23RISK
open
GitHub PoC
Materials for the second Rijeka secuity meetup. We will be discussing Microsoft cryptoapi vulnerability dubbed CurveBall (CVE-2020-0601)
CVE-2020-0601HIGHunder attack26 Feb 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC66
CVE-2020-0688 - Exchange
CVE-2020-0688HIGHunder attackransomware26 Feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC1
Learnings on how to verify if vulnerable to Ghostcat (aka CVE-2020-1938)
CVE-2020-1938CRITICALunder attack26 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC
Cette exploit en python va vous permettre de créer des listes de sites et les exploiter rapidement.
CVE-2018-15133HIGHunder attack25 Feb 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC163
cve-2020-0688
CVE-2020-0688HIGHunder attackransomware25 Feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC
cve-2015-3306 docker image
CVE-2015-330625 Feb 2020
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
GitHub PoC3
CNVD-2020-10487 OR CVE-2020-1938 批量验证脚本,批量验证,并自动截图,方便提交及复核
CVE-2020-1938CRITICALunder attack22 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC5
PoC exploit for CVE-2015-2291
CVE-2015-2291HIGHunder attackransomware22 Feb 2020
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISK
open
GitHub PoC422
Ghostcat read file/code execute,CNVD-2020-10487(CVE-2020-1938)
CVE-2020-1938CRITICALunder attack22 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC67
The official exploit for Cacti v1.2.8 Remote Code Execution CVE-2020-8813
CVE-2020-881322 Feb 2020
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISK
open
GitHub PoC38
CVE-2020-1938漏洞复现
CVE-2020-1938CRITICALunder attack21 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC54
Tomcat的文件包含及文件读取漏洞利用POC
CVE-2020-1938CRITICALunder attack21 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC7
fatal0/tomcat-cve-2020-1938-check
CVE-2020-1938CRITICALunder attack21 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC14
批量扫描TomcatAJP漏洞
CVE-2020-1938CRITICALunder attack21 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC9
dacade/CVE-2020-1938
CVE-2020-1938CRITICALunder attack21 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC11
在一定条件下可执行命令
CVE-2020-1938CRITICALunder attack21 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC2
h7hac9/CVE-2020-1938
CVE-2020-1938CRITICALunder attack21 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC3
CVE-2020-1938
CVE-2020-1938CRITICALunder attack20 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC45
xindongzhuaizhuai/CVE-2020-1938
CVE-2020-1938CRITICALunder attack20 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC
Mass Exploit CVE-2019-16759
CVE-2019-16759CRITICALunder attack20 Feb 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
GitHub PoC294
Cnvd-2020-10487 / cve-2020-1938, scanner tool
CVE-2020-1938CRITICALunder attack20 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
previouspage 407 / 468next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.