Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,107 exploits
Exploit-DB
Foxit Reader 9.0.1.1049 - Arbitrary Code Execution
CVE-2018-9958localwindows27 Nov 2020
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RISK
open
GitHub PoC5
CVE-2020-2883
CVE-2020-2883CRITICALunder attack26 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
GitHub PoC
openssh<7.7 用户名枚举
CVE-2018-15473MEDIUM26 Nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-17087HIGHunder attack26 Nov 2020
Windows Kernel Local Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2020-2687926 Nov 2020
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacke
50RISK
open
VulnCheck XDB
initial-access
CVE-2020-2883CRITICALunder attack26 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-2687826 Nov 2020
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (
28RISK
open
GitHub PoC4
A CVE-2020-17087 PoC.
CVE-2020-17087HIGHunder attack26 Nov 2020
Windows Kernel Local Elevation of Privilege Vulnerability
71RISK
open
Exploit-DBVexDay Proof
Razer Chroma SDK Server 3.16.02 - Race Condition Remote File Execution
CVE-2020-16602remotewindows26 Nov 2020
Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a ra
23RISK
open
VulnCheck XDB
initial-access
CVE-2020-1197524 Nov 2020
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the J
43RISK
open
GitHub PoC1
www201001/https-github.com-iBearcat-CVE-2018-8174_EXP
CVE-2018-8174HIGHunder attackransomware24 Nov 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
GitHub PoC1
www201001/https-github.com-iBearcat-CVE-2018-8174_EXP.git-
CVE-2018-8174HIGHunder attackransomware24 Nov 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
VulnCheck XDB
initial-access
CVE-2020-1394224 Nov 2020
Remote Code Execution in Apache Unomi
50RISK
open
Exploit-DB
Apache OpenMeetings 5.0.0 - 'hostname' Denial of Service
CVE-2020-13951webappsmultiple24 Nov 2020
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
45RISK
open
Exploit-DBVexDay Proof
ZeroShell 3.9.0 - 'cgi-bin/kerbynet' Remote Root Command Injection (Metasploit)
CVE-2019-12725webappslinux24 Nov 2020
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
Exploit-DB
TP-Link TL-WA855RE V5_200415 - Device Reset Auth Bypass
CVE-2020-24363HIGHunder attackwebappshardware23 Nov 2020
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP
76RISK
open
GitHub PoC
1stPeak/CVE-2018-15473
CVE-2018-15473MEDIUM23 Nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
Exploit-DB
LifeRay 7.2.1 GA2 - Stored XSS
CVE-2020-7934webappsmultiple23 Nov 2020
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA
23RISK
open
GitHub PoC1
This container was made to explain and demonstrate how CVE-2019-15813 (Sentrifugo works)
CVE-2019-1581322 Nov 2020
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arb
35RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware22 Nov 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1394221 Nov 2020
Remote Code Execution in Apache Unomi
50RISK
open
Metasploit600
qdPM 9.1 Authenticated Arbitrary PHP File Upload (RCE)
CVE-2020-724621 Nov 2020
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISK
open
VulnCheck XDB
infoleak
CVE-2019-11043HIGHunder attackransomware21 Nov 2020
Underflow in PHP-FPM can lead to RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1394220 Nov 2020
Remote Code Execution in Apache Unomi
50RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware20 Nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC2
MasterSploit/LPE---CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware20 Nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Exploit-DB
Gemtek WVRTM-127ACN 01.01.02.141 - Authenticated Arbitrary Command Injection
CVE-2020-24365webappscgi19 Nov 2020
An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic n
28RISK
open
Exploit-DB
Fortinet FortiOS 6.0.4 - Unauthenticated SSL VPN User Password Modification
CVE-2018-13382CRITICALunder attackransomwarewebappshardware19 Nov 2020
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISK
open
VulnCheck XDB
infoleak
CVE-2018-13379CRITICALunder attackransomware19 Nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
GitHub PoC6
FortiVuln
CVE-2018-13379CRITICALunder attackransomware19 Nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
previouspage 739 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.