Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,107 exploits
GitHub PoC11
CVE-2020-0688 PoC
CVE-2020-0688HIGHunder attackransomware23 Oct 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
Exploit-DBVexDay Proof
Bludit 3.9.2 - Auth Bruteforce Bypass
CVE-2019-17240LOWwebappsphp23 Oct 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
GitHub PoC1
PoC for apache struts 2 vuln cve-2019-0230
CVE-2019-023022 Oct 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISK
open
GitHub PoC2
Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass Exploit/PoC
CVE-2019-17240LOW21 Oct 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
GitHub PoC
HYWZ36/CVE-2020-14645-code
CVE-2020-14645CRITICAL21 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISK
open
GitHub PoC
Elsfa7-110/CVE-2019-1579
CVE-2019-1579HIGHunder attackransomware21 Oct 2020
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware21 Oct 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
Metasploit300
WordPress Loginizer log SQLi Scanner
CVE-2020-2761521 Oct 2020
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_fa
30RISK
open
VulnCheck XDB
infoleak
CVE-2019-1579HIGHunder attackransomware21 Oct 2020
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RISK
open
GitHub PoC
puckiestyle/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware21 Oct 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
Metasploit600
NSClient++ 0.5.2.35 - ExternalScripts Authenticated Remote Code Execution
CVE-2025-34079HIGH20 Oct 2020
NSClient++ Authenticated Remote Code Execution via ExternalScripts API
36RISK
open
GitHub PoC2
cve-2020-14644 漏洞环境
CVE-2020-14644CRITICALunder attack20 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
Metasploit600
Nagios XI 5.5.0-5.7.3 - Snmptrap Authenticated Remote Code Exection
CVE-2020-579220 Oct 2020
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user
30RISK
open
Metasploit600
Oracle WebLogic Server Administration Console Handle RCE
CVE-2020-14882CRITICALunder attack20 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Metasploit600
Oracle WebLogic Server Administration Console Handle RCE
CVE-2020-14883HIGHunder attack20 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Metasploit300
Oracle Solaris SunSSH PAM parse_user_name() Buffer Overflow
CVE-2020-14871CRITICALunder attack20 Oct 2020
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISK
open
Metasploit600
Oracle WebLogic Server Administration Console Handle RCE
CVE-2020-14750CRITICALunder attack20 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Metasploit600
Nagios XI 5.6.0-5.7.3 - Mibs.php Authenticated Remote Code Exection
CVE-2020-579120 Oct 2020
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RISK
open
Metasploit600
NSClient++ 0.5.2.35 - Privilege escalation
CVE-2025-34078HIGH20 Oct 2020
NSClient++ 0.5.2.35 Local Privilege Escalation via ExternalScripts and Web Interface
36RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware19 Oct 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
datntsec/CVE-2019-13272
CVE-2019-13272HIGHunder attack19 Oct 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
Exploit-DB
Typesetter CMS 5.1 - Arbitrary Code Execution (Authenticated)
CVE-2020-25790webappsphp19 Oct 2020
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archi
28RISK
open
Exploit-DB
HiSilicon Video Encoders - Full admin access via backdoor password
CVE-2020-24215webappshardware19 Oct 2020
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use har
28RISK
open
Exploit-DB
HiSilicon Video Encoders - Unauthenticated file disclosure via path traversal
CVE-2020-24219webappshardware19 Oct 2020
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthentic
28RISK
open
GitHub PoC7
ThinkAdmin CVE-2020-25540 poc
CVE-2020-2554019 Oct 2020
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISK
open
Exploit-DB
Hostel Management System 2.1 - Cross Site Scripting (Multiple Fields)
CVE-2020-25270webappsphp19 Oct 2020
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, o
23RISK
open
Exploit-DB
HiSilicon video encoders - RCE via unauthenticated upload of malicious firmware
CVE-2020-24217webappshardware19 Oct 2020
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpo
35RISK
open
Exploit-DB
HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow (DoS)
CVE-2020-24214webappshardware19 Oct 2020
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a
35RISK
open
Exploit-DB
HiSilicon Video Encoders - RCE via unauthenticated command injection
CVE-2020-24217webappshardware19 Oct 2020
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpo
35RISK
open
GitHub PoC
Exploitable target to CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware19 Oct 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
previouspage 745 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.