Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,107 exploits
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALunder attackransomware19 Aug 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-2555CRITICALunder attack19 Aug 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
GitHub PoC532
WebLogic利用CVE-2020-2883打Shiro rememberMe反序列化漏洞,一键注册蚁剑filter内存shell
CVE-2020-2883CRITICALunder attack19 Aug 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
GitHub PoC16
[CVE-2019-18935] Telerik UI for ASP.NET AJAX (RadAsyncUpload Handler) .NET JSON Deserialization
CVE-2019-18935CRITICALunder attackransomware19 Aug 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-2883CRITICALunder attack19 Aug 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack18 Aug 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
client-side
CVE-2020-0796CRITICALunder attackransomware18 Aug 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
Logeirs/CVE-2018-0114
CVE-2018-011418 Aug 2020
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
GitHub PoC
superzerosec/cve-2020-5902
CVE-2020-5902CRITICALunder attackransomware18 Aug 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
VulnCheck XDB
local
CVE-2019-573618 Aug 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-5902CRITICALunder attackransomware18 Aug 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
Exploit-DBVexDay Proof
Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass
CVE-2019-17240LOWwebappsphp17 Aug 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
Exploit-DB
Microsoft SharePoint Server 2019 - Remote Code Execution
CVE-2020-1147HIGHunder attackwebappsaspx17 Aug 2020
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
100RISK
open
GitHub PoC4
[CVE-2020-0688] Microsoft Exchange Server Fixed Cryptographic Key Remote Code Execution (RCE)
CVE-2020-0688HIGHunder attackransomware17 Aug 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware17 Aug 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC1
cyberharsh/PHP_CVE-2012-1823
CVE-2012-1823CRITICALunder attack17 Aug 2020
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHunder attackransomware17 Aug 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
Metasploit300
Jira Users Enumeration
CVE-2020-1418116 Aug 2020
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
60RISK
open
GitHub PoC6
This tools will extracts and dumps Email + SMTP from vBulletin database server
CVE-2019-16759CRITICALunder attack16 Aug 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-16759CRITICALunder attack16 Aug 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
GitHub PoC3
dwisiswant0/CVE-2020-9496
CVE-2020-949615 Aug 2020
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
GitHub PoC13
[CVE-2020-6287] SAP NetWeaver AS JAVA (LM Configuration Wizard) Authentication Bypass (Create Simple & Administrator Java User)
CVE-2020-6287CRITICALunder attack13 Aug 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open
GitHub PoC1
Vbulletin RCE Exploit
CVE-2019-16759CRITICALunder attack13 Aug 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
Exploit-DB
Artica Proxy 4.3.0 - Authentication Bypass
CVE-2020-17506webappshardware13 Aug 2020
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator p
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-6287CRITICALunder attack13 Aug 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open
GitHub PoC8
[CVE-2020-3452] Cisco Adaptive Security Appliance (ASA) & Cisco Firepower Threat Defense (FTD) Web Service Read-Only Directory Traversal
CVE-2020-3452HIGHunder attack13 Aug 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC2
[CVE-2020-5902] F5 BIG-IP Remote Code Execution (RCE)
CVE-2020-5902CRITICALunder attackransomware13 Aug 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
VulnCheck XDB
infoleak
CVE-2016-2386CRITICALunder attack13 Aug 2020
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16759CRITICALunder attack13 Aug 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-5902CRITICALunder attackransomware13 Aug 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
previouspage 754 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.