Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
14,014 exploits
GitHub PoC1
CVE-2019-5736 implemented in a self-written container runtime to understand the exploit.
CVE-2019-573604 Feb 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC1
PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall
CVE-2020-0601HIGHunder attack03 Feb 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC1
Resources related to CurveBall (CVE-2020-0601) detection
CVE-2020-0601HIGHunder attack03 Feb 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC68
CVE-2019-8449 Exploit for Jira v2.1 - v8.3.4
CVE-2019-844902 Feb 2020
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username
60RISK
open
GitHub PoC
A python implementation of CVE-2004-2271 targeting MiniShare 1.4.1.
CVE-2004-227102 Feb 2020
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RISK
open
GitHub PoC26
Temproot for Bravia TV via CVE-2019-2215.
CVE-2019-2215HIGHunder attack30 Jan 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC25
Python exploit of cve-2020-7247
CVE-2020-7247CRITICALunder attack30 Jan 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
GitHub PoC4
TheCyberGeek/CVE-2020-5844
CVE-2020-584429 Jan 2020
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators t
35RISK
open
GitHub PoC
ianxtianxt/CVE-2016-8735
CVE-2016-8735CRITICALunder attack29 Jan 2020
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8
100RISK
open
GitHub PoC1
proof of concept for CVE-2020-0601
CVE-2020-0601HIGHunder attack29 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC20
PoC for CVE-2020-0601 - CryptoAPI exploit
CVE-2020-0601HIGHunder attack28 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC1
*CVE-2014-6271* Unix Arbitrary Code Execution Exploit commonly know as Shell Shock. Examples, Docs, Incident Response and Vulnerability/Risk Assessment, and Additional Resources may be dumped here. Enjoy :) --- somhmxxghoul ---
CVE-2014-6271CRITICALunder attack28 Jan 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
Python CVE-2019-19781 exploit
CVE-2019-19781CRITICALunder attackransomware28 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC73
PoC script that shows RCE vulnerability over Intellian Satellite controller
CVE-2020-798028 Jan 2020
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RISK
open
GitHub PoC41
This repository contains the sources and documentation for the SWAPGS attack PoC (CVE-2019-1125)
CVE-2019-1125MEDIUM27 Jan 2020
Windows Kernel Information Disclosure Vulnerability
33RISK
open
GitHub PoC
PoC for "CurveBall" CVE-2020-0601
CVE-2020-0601HIGHunder attack25 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC2
Archi73ct/CVE-2020-0609
CVE-2020-060924 Jan 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISK
open
GitHub PoC68
A proof-of-concept scanner to check an RDG Gateway Server for vulnerabilities CVE-2020-0609 & CVE-2020-0610.
CVE-2020-060924 Jan 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISK
open
GitHub PoC
Citrix ADC (NetScaler) Honeypot. Supports detection for CVE-2019-19781 and login attempts
CVE-2019-19781CRITICALunder attackransomware24 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC78
PoC for the Remote Desktop Gateway vulnerability - CVE-2020-0609 & CVE-2020-0610
CVE-2020-060924 Jan 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISK
open
GitHub PoC
a script to look for CVE-2019-19781 Vulnerability within a domain and it's subdomains
CVE-2019-19781CRITICALunder attackransomware23 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC249
PoC (DoS + scanner) for CVE-2020-0609 & CVE-2020-0610 - RD Gateway RCE
CVE-2020-060923 Jan 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISK
open
GitHub PoC
My Citrix ADC NetScaler CVE-2019-19781 Vulnerability DFIR notes.
CVE-2019-19781CRITICALunder attackransomware23 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC
:microscope: Jupyter notebook to help automate some of the forensic analysis related to Citrix Netscalers compromised via CVE-2019-19781
CVE-2019-19781CRITICALunder attackransomware23 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC1
CVE-2020-0601: Windows CryptoAPI Vulnerability. (CurveBall/ChainOfFools)
CVE-2020-0601HIGHunder attack23 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC58
Indicator of Compromise Scanner for CVE-2019-19781
CVE-2019-19781CRITICALunder attackransomware21 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC317
CVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell
CVE-2019-0708CRITICALunder attackransomware21 Jan 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC94
Indicator of Compromise Scanner for CVE-2019-19781
CVE-2019-19781CRITICALunder attackransomware21 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC40
Scanning for Remote Desktop Gateways (Potentially unpatched CVE-2020-0609 and CVE-2020-0610)
CVE-2020-060921 Jan 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISK
open
GitHub PoC
Código desenvolvido para a verificação em massa da vulnerabilidade CVE-2019-19781 de hosts descobertos pelo Shodan. Pull requests são bem vindas.
CVE-2019-19781CRITICALunder attackransomware21 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
previouspage 409 / 468next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.