Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,107 exploits
VulnCheck XDB
initial-access
CVE-2019-11510CRITICALunder attackransomware17 Sep 2020
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open
GitHub PoC1
pwn3z/CVE-2019-11510-PulseVPN
CVE-2019-11510CRITICALunder attackransomware17 Sep 2020
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open
GitHub PoC70
rsmudge/CVE-2020-0796-BOF
CVE-2020-0796CRITICALunder attackransomware17 Sep 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Exploit-DB
Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
CVE-2020-0618CRITICALunder attackransomwareremotewindows17 Sep 2020
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISK
open
GitHub PoC1
pwn3z/CVE-2018-13379-FortinetVPN
CVE-2018-13379CRITICALunder attackransomware17 Sep 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
GitHub PoC1
https://github.com/dirkjanm/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
Fa1c0n35/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
Fa1c0n35/SecuraBV-CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC111
cve-2020-1472 复现利用及其exp
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
[CVE-2020-1472] Netlogon Remote Protocol Call (MS-NRPC) Privilege Escalation (Zerologon)
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
FaFcFF41/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC2
cve-2020-1472_Tool collection
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
victim10wq3/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
Exploit-DB
Piwigo 2.10.1 - Cross Site Scripting
CVE-2020-9467webappsphp16 Sep 2020
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
28RISK
open
GitHub PoC2
CVE-2020-1472 - Zero Logon vulnerability Python implementation
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
Zabbix Template to monitor for Windows Event Viewer event's related to Netlogon Elevation of Privilege Vulnerability - CVE-2020-1472. Monitors event ID's 5827, 5828 & 5829. See: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware16 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware15 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware15 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware15 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware15 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
Exploit-DB
ThinkAdmin 6 - Arbitrarily File Read
CVE-2020-25540webappsphp15 Sep 2020
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISK
open
GitHub PoC8
PoC for Zerologon (CVE-2020-1472) - Exploit
CVE-2020-1472MEDIUMunder attackransomware15 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware15 Sep 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
previouspage 750 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.