Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
79,196 exploits
Metasploit600
Plesk/myLittleAdmin ViewState .NET Deserialization
CVE-2020-1316615 May 2020
The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcod
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-10199HIGHunder attack15 May 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-0193HIGHunder attack14 May 2020
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISK
open
GitHub PoC
ES File Explorer Open Port Vulnerability - CVE-2019-6447
CVE-2019-644714 May 2020
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open
GitHub PoC
CVE-2018-20250漏洞利用
CVE-2018-20250HIGHunder attackransomware13 May 2020
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC15
Proof of concept for Weblogic CVE-2020-2883
CVE-2020-2883CRITICALunder attack13 May 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
GitHub PoC
teddy47/CVE-2019-13272---Documentation
CVE-2019-13272HIGHunder attack13 May 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC
Microsoft Windows - 'afd.sys' Local Kernel Privilege Escalation Exploit Report (CVE-2011-1249)
CVE-2011-124913 May 2020
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis
23RISK
open
GitHub PoC1
CVE-2004-1769 // Mass cPanel Reset password
CVE-2004-176913 May 2020
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x,
35RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware13 May 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
CVE-2019-5736
CVE-2019-573612 May 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC
This is about CVE-2020-1938
CVE-2020-1938CRITICALunder attack12 May 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC
CVE-2020-1938 exploit
CVE-2020-1938CRITICALunder attack12 May 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
Metasploit300
WordPress ChopSlider3 id SQLi Scanner
CVE-2020-1153012 May 2020
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RISK
open
GitHub PoC
dinidhu96/IT19013756_-CVE-2016-4971-
CVE-2016-497112 May 2020
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RISK
open
GitHub PoC
Dilith006/CVE-2014-6271
CVE-2014-6271CRITICALunder attack12 May 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
alokaranasinghe/cve-2019-11043
CVE-2019-11043HIGHunder attackransomware12 May 2020
Underflow in PHP-FPM can lead to RCE
100RISK
open
GitHub PoC
This is an individual assignment for secure network programming
CVE-2014-6271CRITICALunder attack12 May 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
sachinthaBS/Spectre-Vulnerability-CVE-2017-5753-
CVE-2017-5753MEDIUM12 May 2020
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISK
open
GitHub PoC
This is my SNP project where my ID is IT19366128
CVE-2015-132812 May 2020
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
GitHub PoC1
Exploit work Privilege Escalation CVE-2017-1000112
CVE-2017-100011212 May 2020
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISK
open
GitHub PoC
DewmiApsara/CVE-2019-14287
CVE-2019-1428712 May 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC
Dilan-Diaz/Point-to-Point-Protocol-Daemon-RCE-Vulnerability-CVE-2020-8597-
CVE-2020-8597CRITICAL12 May 2020
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RISK
open
GitHub PoC
This document explain Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [CVE-2019-19781]
CVE-2019-19781CRITICALunder attackransomware12 May 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC
SNP Assignment 1 Report - Linux box exploitation ( Vulnerability CVE-2014-0038)
CVE-2014-003812 May 2020
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RISK
open
GitHub PoC4
CVE-2019-6111 vulnerability exploitation
CVE-2019-6111MEDIUM12 May 2020
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh
45RISK
open
GitHub PoC
SMBGhost CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware12 May 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Exploit-DB
WordPress Plugin ChopSlider 3.4 - 'id' SQL Injection
CVE-2020-11530webappsphp12 May 2020
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RISK
open
Exploit-DB
Cisco Digital Network Architecture Center 1.3.1.4 - Persistent Cross-Site Scripting
CVE-2019-15253MEDIUMwebappsjava12 May 2020
Cisco Digital Network Architecture Center Stored Cross-Site Scripting Vulnerability
33RISK
open
GitHub PoC
janod313/-CVE-2019-14287-SUDO-bypass-vulnerability
CVE-2019-1428712 May 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
previouspage 771 / 2,640next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.