Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,107 exploits
GitHub PoC
A powershell script to deploy the registry mitigation key for CVE-2020-1350
CVE-2020-1350CRITICALunder attack22 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
Exploit-DB
WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection
CVE-2020-15364webappsphp22 Jul 2020
The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.
23RISK
open
GitHub PoC28
Onapsis/CVE-2020-6287_RECON-scanner
CVE-2020-6287CRITICALunder attack21 Jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-6287CRITICALunder attack21 Jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-6287CRITICALunder attack20 Jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open
GitHub PoC80
Weblogic CVE-2020-14645 UniversalExtractor JNDI injection getDatabaseMetaData()
CVE-2020-14645CRITICAL20 Jul 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISK
open
GitHub PoC96
PoC for CVE-2020-6287 The PoC in python for add user only, no administrator permission set. Inspired by @zeroSteiner from metasploit. Original Metasploit PR module: https://github.com/rapid7/metasploit-framework/pull/13852/commits/d1e2c75b3eafa7f62a6aba9fbe6220c8da97baa8 This PoC only create user with unauthentication permission and no more administrator permission set. This project is created only for educational purposes and cannot be used for law violation or personal gain. The author of this project is not responsible for any possible harm caused by the materials of this project. Original finding: CVE-2020-6287: Pablo Artuso CVE-2020-6286: Yvan 'iggy' G. Usage: python sap-CVE-2020-6287-add-user.py <HTTP(s)://IP:Port
CVE-2020-6287CRITICALunder attack20 Jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open
GitHub PoC3
DaBoQuan/CVE-2020-14645
CVE-2020-14645CRITICAL20 Jul 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISK
open
GitHub PoC17
f5devcentral/cve-2020-5902-ioc-bigip-checker
CVE-2020-5902CRITICALunder attackransomware20 Jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
Metasploit400
Moodle Teacher Enrollment Privilege Escalation to RCE
CVE-2020-1432120 Jul 2020
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role wi
23RISK
open
GitHub PoC1
Ported Exploit From Python To Golang
CVE-2018-689220 Jul 2020
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISK
open
GitHub PoC
DNS Vulnerability - CVE-2020-1350
CVE-2020-1350CRITICALunder attack19 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
GitHub PoC4
Iamgublin/CVE-2020-1054
CVE-2020-1054HIGHunder attack19 Jul 2020
Win32k Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC2
Scanner and Mitigator for CVE 2020-1350
CVE-2020-1350CRITICALunder attack18 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
GitHub PoC4
Enviroment and exploit to rce test
CVE-2020-816318 Jul 2020
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RISK
open
GitHub PoC11
CVE-2020-1350 Proof-of-Concept
CVE-2020-1350CRITICALunder attack17 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
GitHub PoC
Bludit Exploitation Via upload Image.php
CVE-2019-1611317 Jul 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISK
open
GitHub PoC8
GUI
CVE-2020-5902CRITICALunder attackransomware17 Jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
GitHub PoC10
Citrix Unauthorized Remote Code Execution Attacker - CVE-2019-19781
CVE-2019-19781CRITICALunder attackransomware17 Jul 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC
Disables AJP connectors to remediate CVE-2020-1938!
CVE-2020-1938CRITICALunder attack17 Jul 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
Exploit-DB
CMSUno 1.6 - Cross-Site Request Forgery (Change Admin Password)
CVE-2020-15600webappsphp17 Jul 2020
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
23RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-1350CRITICALunder attack17 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-19781CRITICALunder attackransomware17 Jul 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-1350CRITICALunder attack16 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
GitHub PoC1
Environment for CVE_2019_17571
CVE-2019-17571CRITICAL16 Jul 2020
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be explo
60RISK
open
GitHub PoC18
Denial of Service PoC for CVE-2020-1350 (SIGRed)
CVE-2020-1350CRITICALunder attack16 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
GitHub PoC2
ctlyz123/CVE-2020-8193
CVE-2020-8193MEDIUMunder attack15 Jul 2020
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISK
open
Exploit-DB
Zyxel Armor X1 WAP6806 - Directory Traversal
CVE-2020-14461webappshardware15 Jul 2020
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
23RISK
open
GitHub PoC15
This Powershell Script is checking if your server is vulnerable for the CVE-2020-1350 Remote Code Execution flaw in the Windows DNS Service
CVE-2020-1350CRITICALunder attack15 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
GitHub PoC237
A denial-of-service proof-of-concept for CVE-2020-1350
CVE-2020-1350CRITICALunder attack15 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
previouspage 760 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.