Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,057 exploits
Exploit-DBVexDay Proof
Gitea 1.7.5 - Remote Code Execution
CVE-2019-11229webappsmultiple06 Jan 2021
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to rem
35RISK
open
GitHub PoC3
Python implementation of Roundcube LFI (CVE-2017-16651)
CVE-2017-16651HIGHunder attack06 Jan 2021
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RISK
open
Exploit-DB
IPeakCMS 3.5 - Boolean-based blind SQLi
CVE-2021-3018webappsmultiple06 Jan 2021
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the
43RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack06 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
Exploit-DBVexDay Proof
PaperStream IP (TWAIN) 1.42.0.5685 - Local Privilege Escalation
CVE-2018-16156localwindows06 Jan 2021
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes u
23RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack06 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
local
CVE-2017-16651HIGHunder attack06 Jan 2021
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack06 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1751806 Jan 2021
Apache Flink directory traversal attack: remote file writing through the REST API
50RISK
open
VulnCheck XDB
initial-access
CVE-2020-798006 Jan 2021
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RISK
open
GitHub PoC1
andyfeili/CVE-2014-4688
CVE-2014-468805 Jan 2021
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RISK
open
VulnCheck XDB
initial-access
CVE-2020-10148CRITICALunder attack05 Jan 2021
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISK
open
GitHub PoC10
SolarWinds Orion API 远程代码执行漏洞批量检测脚本
CVE-2020-10148CRITICALunder attack05 Jan 2021
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISK
open
Exploit-DB
IncomCMS 2.0 - Insecure File Upload
CVE-2020-29597webappsmultiple05 Jan 2021
IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows un
60RISK
open
Exploit-DB
Fluentd TD-agent plugin 4.0.1 - Insecure Folder Permission
CVE-2020-28169localwindows05 Jan 2021
The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory
23RISK
open
GitHub PoC99
CISCO CVE-2020-3452 Scanner & Exploiter
CVE-2020-3452HIGHunder attack05 Jan 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-3452HIGHunder attack05 Jan 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
Exploit-DBVexDay Proof
Klog Server 2.4.1 - Command Injection (Unauthenticated)
CVE-2020-35729webappsphp05 Jan 2021
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RISK
open
Metasploit300
Apache Flink JobManager Traversal
CVE-2020-17519CRITICALunder attack05 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
Exploit-DB
Subrion CMS 4.2.1 - 'avatar[path]' XSS
CVE-2020-35437webappsphp04 Jan 2021
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the
23RISK
open
Exploit-DB
Mantis Bug Tracker 2.24.3 - 'access' SQL Injection
CVE-2020-28413MEDIUMwebappsphp04 Jan 2021
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the A
33RISK
open
GitHub PoC21
Remote Code Execution on Microsoft Exchange Server through fixed cryptographic keys
CVE-2020-0688HIGHunder attackransomware04 Jan 2021
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHunder attackransomware04 Jan 2021
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-29583CRITICALunder attack04 Jan 2021
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The p
100RISK
open
GitHub PoC16
Scanner for Zyxel products which are potentially vulnerable due to an undocumented user account (CVE-2020-29583)
CVE-2020-29583CRITICALunder attack04 Jan 2021
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The p
100RISK
open
Exploit-DB
Wordpress Core 5.2.2 - 'post previews' XSS
CVE-2019-16223webappsphp04 Jan 2021
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
23RISK
open
Exploit-DB
Advanced Comment System 1.0 - 'ACS_path' Path Traversal
CVE-2020-35598webappsphp04 Jan 2021
ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=.
43RISK
open
GitHub PoC3
AzhariKun/CVE-2018-15133
CVE-2018-15133HIGHunder attack03 Jan 2021
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC2
python2.7 script for JWT generation
CVE-2018-011403 Jan 2021
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
GitHub PoC
andyfeili/CVE-2018-9276
CVE-2018-9276HIGHunder attack02 Jan 2021
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
previouspage 732 / 2,636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.