Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,107 exploits
GitHub PoC5
CVE-2019-18935
CVE-2019-18935CRITICALunder attackransomware30 Sep 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
VulnCheck XDB
client-side
CVE-2020-0674HIGHunder attack30 Sep 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISK
open
GitHub PoC
Ken-Abruzzi/cve-2020-1472
CVE-2020-1472MEDIUMunder attackransomware30 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC11
POC for checking multiple hosts for Zerologon vulnerability
CVE-2020-1472MEDIUMunder attackransomware29 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC22
Zerologon AutoExploit Tool | CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware29 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware29 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware29 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware28 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware28 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
Exploit-DB
Joplin 1.0.245 - Arbitrary Code Execution (PoC)
CVE-2020-15930webappsmultiple28 Sep 2020
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
23RISK
open
Exploit-DB
MSI Ambient Link Driver 1.0.0.8 - Local Privilege Escalation
CVE-2020-17382localwindows28 Sep 2020
The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).
23RISK
open
Metasploit600
OpenMediaVault rpc.php Authenticated PHP Code Injection
CVE-2020-2612428 Sep 2020
openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield PO
30RISK
open
Exploit-DB
Mida eFramework 2.8.9 - Remote Code Execution
CVE-2020-15922webappshardware28 Sep 2020
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE)
35RISK
open
GitHub PoC3
To crash Windows-10 easily
CVE-2020-0796CRITICALunder attackransomware28 Sep 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Metasploit600
FlexDotnetCMS Arbitrary ASP File Upload
CVE-2020-2738628 Sep 2020
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and e
40RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware28 Sep 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-3452HIGHunder attack28 Sep 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC24
Just basic scanner abusing CVE-2020-3452 to enumerate the standard files accessible in the Web Directory of the CISCO ASA applicances.
CVE-2020-3452HIGHunder attack28 Sep 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC
Fa1c0n35/CVE-2020-1472-02-
CVE-2020-1472MEDIUMunder attackransomware28 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware28 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC5
striveben/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware26 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware26 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware25 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2020-3433HIGHunder attackransomware25 Sep 2020
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
91RISK
open
GitHub PoC42
PoCs and technical analysis of three vulnerabilities found on Cisco AnyConnect for Windows: CVE-2020-3433, CVE-2020-3434 and CVE-2020-3435
CVE-2020-3433HIGHunder attackransomware25 Sep 2020
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
91RISK
open
VulnCheck XDB
local
CVE-2019-0808HIGHunder attack25 Sep 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack25 Sep 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
This repository holds the advisory, exploits and vulnerable software of the CVE-2020-15492
CVE-2020-1549224 Sep 2020
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe we
28RISK
open
Metasploit600
HorizontCMS Arbitrary PHP File Upload
CVE-2020-2738724 Sep 2020
An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access
23RISK
open
GitHub PoC
CVE 2020-1472 Script de validación
CVE-2020-1472MEDIUMunder attackransomware24 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
previouspage 748 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.