Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
79,201 exploits
Exploit-DB
WordPress Plugin ChopSlider 3.4 - 'id' SQL Injection
CVE-2020-11530webappsphp12 May 2020
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RISK
open
GitHub PoC
SMBGhost CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware12 May 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC3
Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287/Google Android - 'Stagefright' Remote Code Execution - CVE-2015-1538
CVE-2019-13272HIGHunder attack12 May 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC
This document explain Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [CVE-2019-19781]
CVE-2019-19781CRITICALunder attackransomware12 May 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC
ShianTrish/sudo-Security-Bypass-vulnerability-CVE-2019-14287
CVE-2019-1428712 May 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
Exploit-DB
Cisco Digital Network Architecture Center 1.3.1.4 - Persistent Cross-Site Scripting
CVE-2019-15253MEDIUMwebappsjava12 May 2020
Cisco Digital Network Architecture Center Stored Cross-Site Scripting Vulnerability
33RISK
open
GitHub PoC
This is the exploitation of sudo security bypass vulnerability
CVE-2019-1428712 May 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC4
CVE-2019-6111 vulnerability exploitation
CVE-2019-6111MEDIUM12 May 2020
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh
45RISK
open
GitHub PoC
DewmiApsara/CVE-2019-14287
CVE-2019-1428712 May 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC
SNP Assignment on a Linux vulnerability
CVE-2019-10149CRITICALunder attack12 May 2020
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC
CVE-2017-8759 || report related with execute code vulnerability
CVE-2017-8759HIGHunder attack12 May 2020
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
GitHub PoC
CVE-2019-5736
CVE-2019-573612 May 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC
lalishasanduwara/CVE-2018-10933
CVE-2018-10933CRITICAL12 May 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC3
Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287/Google Android - 'Stagefright' Remote Code Execution - CVE-2015-1538
CVE-2015-153812 May 2020
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISK
open
GitHub PoC
alokaranasinghe/cve-2019-11043
CVE-2019-11043HIGHunder attackransomware12 May 2020
Underflow in PHP-FPM can lead to RCE
100RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack12 May 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
sachinthaBS/Spectre-Vulnerability-CVE-2017-5753-
CVE-2017-5753MEDIUM12 May 2020
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISK
open
GitHub PoC1
BimsaraMalinda/Linux-Kernel-4.4.0-Ubuntu---DCCP-Double-Free-Privilege-Escalation-CVE-2017-6074
CVE-2017-607412 May 2020
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RISK
open
GitHub PoC
SachinThanushka/CVE-2018-1160
CVE-2018-1160CRITICAL12 May 2020
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RISK
open
GitHub PoC
Dilith006/CVE-2014-6271
CVE-2014-6271CRITICALunder attack12 May 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
This is an individual assignment for secure network programming
CVE-2014-6271CRITICALunder attack12 May 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
CVE-2017-8759 | .NET Framework Remote Code Execution Vulnerability
CVE-2017-8759HIGHunder attack12 May 2020
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
GitHub PoC
AvishkaSenadheera/CVE-2017-9805---Documentation---IT19143378
CVE-2017-9805HIGHunder attack12 May 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
GitHub PoC
Sudo Security Policy bypass Vulnerability
CVE-2019-1428711 May 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
Exploit-DB
SolarWinds MSP PME Cache Service 1.1.14 - Insecure File Permissions
CVE-2020-12608localwindows11 May 2020
An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Moni
28RISK
open
GitHub PoC1
Google Android - 'Stagefright' Remote Code Execution - CVE-2015-1538
CVE-2015-153811 May 2020
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISK
open
GitHub PoC
Documentation for Sudo Security Bypass - CVE 2019-14287
CVE-2019-1428711 May 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC1
Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287
CVE-2019-13272HIGHunder attack11 May 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC
Exploit code for CVE-2015-5477 POC
CVE-2015-547711 May 2020
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-1040MEDIUM11 May 2020
Windows NTLM Tampering Vulnerability
45RISK
open
previouspage 772 / 2,641next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.