Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,526cataloged exploits
36,593CVEs with public exploitation
24,695lab-tested
24,460 exploits
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8656remotemultiple05 Mar 2020
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe
60RISK
open
Exploit-DB
Alfresco 5.2.4 - Persistent Cross-Site Scripting
CVE-2020-8776webappsphp03 Mar 2020
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a
23RISK
open
Exploit-DB
Microsoft Windows - 'WizardOpium' Local Privilege Escalation
CVE-2019-1458HIGHunder attackransomwarelocalwindows03 Mar 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
Exploit-DB
Alfresco 5.2.4 - Persistent Cross-Site Scripting
CVE-2020-8777webappsphp03 Mar 2020
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo,
23RISK
open
Exploit-DB
Alfresco 5.2.4 - Persistent Cross-Site Scripting
CVE-2020-8778webappsphp03 Mar 2020
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document,
23RISK
open
Exploit-DB
CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
CVE-2020-8012remotewindows02 Mar 2020
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerabi
60RISK
open
Exploit-DB
Joplin Desktop 1.0.184 - Cross-Site Scripting
CVE-2020-9038webappsmultiple02 Mar 2020
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
23RISK
open
Exploit-DB
Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
CVE-2020-0688HIGHunder attackransomwareremotewindows02 Mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
Exploit-DB
TP LINK TL-WR849N - Remote Code Execution
CVE-2020-9374webappshardware02 Mar 2020
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploit
35RISK
open
Exploit-DB
TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)
CVE-2019-19143webappshardware02 Mar 2020
TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi
23RISK
open
Exploit-DB
Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)
CVE-2019-19142webappshardware02 Mar 2020
Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmwa
23RISK
open
Exploit-DB
WordPress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
CVE-2020-8615webappsphp02 Mar 2020
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves a
38RISK
open
Exploit-DB
qdPM < 9.1 - Remote Code Execution
CVE-2020-7246webappsmultiple28 Feb 2020
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISK
open
Exploit-DB
OpenSMTPD 6.6.3 - Arbitrary File Read
CVE-2020-8793remotelinux26 Feb 2020
OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combi
23RISK
open
Exploit-DB
OpenSMTPD < 6.6.3p1 - Local Privilege Escalation + Remote Code Execution
CVE-2020-8794remoteopenbsd26 Feb 2020
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult
60RISK
open
Exploit-DB
Go SSH servers 0.0.2 - Denial of Service (PoC)
CVE-2020-9283doslinux24 Feb 2020
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the
28RISK
open
Exploit-DB
ManageEngine EventLog Analyzer 10.0 - Information Disclosure
CVE-2019-19774webappsjava24 Feb 2020
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetai
28RISK
open
Exploit-DBVexDay Proof
Apache James Server 2.3.2 - Insecure User Creation Arbitrary File Write (Metasploit)
CVE-2015-7611remotelinux24 Feb 2020
Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary syst
50RISK
open
Exploit-DB
Avaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site Scripting
CVE-2019-7004MEDIUMwebappshardware24 Feb 2020
Avaya IP Office XSS Vulnerability
33RISK
open
Exploit-DBVexDay Proof
Android Binder - Use-After-Free (Metasploit)
CVE-2019-2215HIGHunder attacklocalandroid24 Feb 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
Exploit-DB
Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
CVE-2020-1938CRITICALunder attackwebappsmultiple20 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
Exploit-DBVexDay Proof
Anviz CrossChex - Buffer Overflow (Metasploit)
CVE-2019-12518remotewindows17 Feb 2020
Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.
50RISK
open
Exploit-DB
MSI Packages Symbolic Links Processing - Windows 10 Privilege Escalation
CVE-2020-0683HIGHunder attacklocalwindows17 Feb 2020
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RISK
open
Exploit-DB
PANDORAFMS 7.0 - Authenticated Remote Code Execution
CVE-2020-8947webappsphp13 Feb 2020
functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metac
28RISK
open
Exploit-DBVexDay Proof
HP System Event Utility - Local Privilege Escalation
CVE-2019-18915localwindows12 Feb 2020
A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version
23RISK
open
Exploit-DB
CHIYU BF430 TCP IP Converter - Stored Cross-Site Scripting
CVE-2020-8839webappscgi11 Feb 2020
Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cg
23RISK
open
Exploit-DB
Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting
CVE-2020-8825webappsphp11 Feb 2020
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
23RISK
open
Exploit-DBVexDay Proof
OpenSMTPD 6.4.0 < 6.6.1 - Local Privilege Escalation + Remote Code Execution
CVE-2020-7247CRITICALunder attackremoteopenbsd11 Feb 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
Exploit-DB
Dota 2 7.23f - Denial of Service (PoC)
CVE-2020-7949doswindows10 Feb 2020
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by
23RISK
open
Exploit-DBVexDay Proof
Ricoh Driver - Privilege Escalation (Metasploit)
CVE-2019-19363localwindows10 Feb 2020
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.