Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,106cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,057 exploits
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALunder attack14 Jan 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
GitHub PoC82
PoC for CVE-2020-6207 (Missing Authentication Check in SAP Solution Manager)
CVE-2020-6207CRITICALunder attack14 Jan 2021
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RISK
open
Exploit-DB
Nagios XI 5.7.X - Remote Code Execution RCE (Authenticated)
CVE-2020-35578webappsphp14 Jan 2021
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RISK
open
Exploit-DB
Laravel 8.4.2 debug mode - Remote code execution
CVE-2021-3129CRITICALunder attackransomwarewebappsphp14 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC18
Exploit script for CVE-2020-7961
CVE-2020-7961CRITICALunder attack14 Jan 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-6207CRITICALunder attack14 Jan 2021
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RISK
open
GitHub PoC
CVE-2020-17519 EXP
CVE-2020-17519CRITICALunder attack14 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
Metasploit600
Unauthenticated remote code execution in Ignition
CVE-2021-3129CRITICALunder attackransomware13 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC289
Exploit for CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware13 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
Starry-lord/CVE-2018-0114
CVE-2018-011413 Jan 2021
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
Metasploit600
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
CVE-2020-17132CRITICAL12 Jan 2021
Microsoft Exchange Remote Code Execution Vulnerability
65RISK
open
Metasploit600
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
CVE-2020-16875HIGH12 Jan 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
48RISK
open
GitHub PoC1
CVE-2017-12615 任意文件写入exp,写入webshell
CVE-2017-12615HIGHunder attackransomware12 Jan 2021
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-12615HIGHunder attackransomware12 Jan 2021
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware11 Jan 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
AnasTaoutaou/CVE-2019-5420
CVE-2019-542011 Jan 2021
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-1751810 Jan 2021
Apache Flink directory traversal attack: remote file writing through the REST API
50RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack10 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1751810 Jan 2021
Apache Flink directory traversal attack: remote file writing through the REST API
50RISK
open
GitHub PoC8
[CVE-2020-17519] Apache Flink RESTful API Arbitrary File Read
CVE-2020-17519CRITICALunder attack10 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
GitHub PoC5
ElmouradiAmine/CVE-2020-7048
CVE-2020-7048CRITICAL09 Jan 2021
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any
53RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack08 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
GitHub PoC
CVE-2020-17519
CVE-2020-17519CRITICALunder attack08 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
Exploit-DBVexDay Proof
Apache Flink 1.11.0 - Unauthenticated Arbitrary File Read (Metasploit)
CVE-2020-17519CRITICALunder attackwebappsjava08 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
GitHub PoC7
quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual exploitation of CVE-2020-1472. requires admin access to the DCs
CVE-2020-1472MEDIUMunder attackransomware07 Jan 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC5
uzzzval/CVE-2020-17530
CVE-2020-17530CRITICALunder attack07 Jan 2021
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
VulnCheck XDB
local
CVE-2017-16651HIGHunder attack06 Jan 2021
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack06 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1751806 Jan 2021
Apache Flink directory traversal attack: remote file writing through the REST API
50RISK
open
VulnCheck XDB
initial-access
CVE-2020-798006 Jan 2021
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RISK
open
previouspage 731 / 2,636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.