Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,107 exploits
Metasploit600
WordPress AIT CSV Import Export Unauthenticated Remote Code Execution
CVE-2020-36849CRITICAL14 Nov 2020
AIT CSV import/export <= 3.0.3 - Unauthenticated Arbitrary File Upload
43RISK
open
GitHub PoC12
Hikvision IP camera access bypass exploit, developed by golang.
CVE-2017-7921CRITICALunder attack13 Nov 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
Exploit-DB
OpenCart Theme Journal 3.1.0 - Sensitive Data Exposure
CVE-2020-15478webappsphp13 Nov 2020
The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
23RISK
open
Exploit-DB
October CMS Build 465 - Arbitrary File Read Exploit (Authenticated)
CVE-2020-5295MEDIUMwebappsphp13 Nov 2020
Local File read vulnerability in OctoberCMS
33RISK
open
Exploit-DB
Touchbase.io 1.10 - Stored Cross Site Scripting
CVE-2020-26218HIGHwebappsmultiple13 Nov 2020
HTML Injection in touchbase.ai
41RISK
open
GitHub PoC57
Exploit for Laravel Remote Code Execution with API_KEY (CVE-2018-15133)
CVE-2018-15133HIGHunder attack13 Nov 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-15133HIGHunder attack13 Nov 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC
rvermeulen/apache-struts-cve-2017-9805
CVE-2017-9805HIGHunder attack13 Nov 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALunder attack13 Nov 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
Exploit-DBVexDay Proof
Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
CVE-2020-1938CRITICALunder attackwebappsmultiple13 Nov 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC1
CVE-2020-25213 Wordpress File Manager 6.7 Plugin 0day exploit
CVE-2020-25213CRITICALunder attack13 Nov 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
GitHub PoC2
A very simple buffer overflow using CVE-2013-4730 against PCman's FTP server
CVE-2013-473012 Nov 2020
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open
GitHub PoC7
Detection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750
CVE-2020-14882CRITICALunder attack12 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC5
xfiftyone/CVE-2020-14882
CVE-2020-14882CRITICALunder attack12 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack12 Nov 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-7921CRITICALunder attack12 Nov 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC
MuirlandOracle/CVE-2014-6271-IPFire
CVE-2014-6271CRITICALunder attack12 Nov 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC3
zavke/CVE-2020-10189-ManageEngine
CVE-2020-10189CRITICALunder attack12 Nov 2020
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RISK
open
GitHub PoC36
海康威视未授权访问检测poc及口令爆破
CVE-2017-7921CRITICALunder attack12 Nov 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-10189CRITICALunder attack12 Nov 2020
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack11 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14883HIGHunder attack11 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC2
基于qt的图形化CVE-2020-14882漏洞回显测试工具.
CVE-2020-14882CRITICALunder attack11 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC7
Weblogic 身份认证绕过漏洞批量检测脚本
CVE-2020-14883HIGHunder attack11 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Metasploit600
Acronis TrueImage XPC Privilege Escalation
CVE-2020-2573611 Nov 2020
Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC
18RISK
open
GitHub PoC
Dicha vulnerabilidad se presentaba en la funcionalidad mc_project_get_users, y su detección es tan solo modificando y enviando el parámetro “access” sin ningún valor y cambiando el tipo de valor a String.
CVE-2020-28413MEDIUM10 Nov 2020
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the A
33RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware10 Nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
Frivolous-scholar/CVE-2017-5941-NodeJS-RCE
CVE-2017-594110 Nov 2020
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISK
open
Exploit-DB
ShoreTel Conferencing 19.46.1802.0 - Reflected Cross-Site Scripting
CVE-2020-28351webappsphp10 Nov 2020
The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a r
43RISK
open
GitHub PoC
The following is the outcome of playing with CVE-2020-1472 and attempting to automate the process of gaining a shell on the DC
CVE-2020-1472MEDIUMunder attackransomware10 Nov 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
previouspage 741 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.