Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
79,207 exploits
VulnCheck XDB
initial-access
CVE-2020-2555CRITICALunder attack06 May 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-0796CRITICALunder attackransomware06 May 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware06 May 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Exploit-DB
Saltstack 3000.1 - Remote Code Execution
CVE-2020-11652MEDIUMunder attackremotemultiple05 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
GitHub PoC14
This repository provides a dockerized infrastructure and a python implementation of the CVE-2019-11043 exploit.
CVE-2019-11043HIGHunder attackransomware05 May 2020
Underflow in PHP-FPM can lead to RCE
100RISK
open
Exploit-DB
Saltstack 3000.1 - Remote Code Execution
CVE-2020-11651CRITICALunder attackremotemultiple05 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-11043HIGHunder attackransomware05 May 2020
Underflow in PHP-FPM can lead to RCE
100RISK
open
GitHub PoC122
PoC exploit of CVE-2020-11651 and CVE-2020-11652
CVE-2020-11651CRITICALunder attack04 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-11652MEDIUMunder attack04 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
GitHub PoC106
dozernz/cve-2020-11651
CVE-2020-11651CRITICALunder attack04 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
GitHub PoC40
CVE-2020-11651: Proof of Concept
CVE-2020-11651CRITICALunder attack04 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
VulnCheck XDB
local
CVE-2020-3153MEDIUMunder attackransomware04 May 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RISK
open
GitHub PoC5
CVE-2020-11651&&CVE-2020-11652 EXP
CVE-2020-11651CRITICALunder attack04 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
GitHub PoC6
PoC for CVE-2020-11651
CVE-2020-11651CRITICALunder attack04 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
GitHub PoC5
POC code for CVE-2020-3153 - Cisco anyconnect path traversal vulnerability
CVE-2020-3153MEDIUMunder attackransomware04 May 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALunder attack04 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALunder attack04 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-11651CRITICALunder attack04 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALunder attack04 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
VulnCheck XDB
local
CVE-2018-8639HIGHunder attackransomware02 May 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RISK
open
GitHub PoC
sumedhaDharmasena/-Kernel-ptrace-c-mishandles-vulnerability-CVE-2019-13272
CVE-2019-13272HIGHunder attack02 May 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
Exploit-DB
Apache OFBiz 17.12.03 - Cross-Site Request Forgery (Account Takeover)
CVE-2019-0235webappsjava01 May 2020
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
35RISK
open
GitHub PoC6
Checks for CVE-2020-11651 and CVE-2020-11652
CVE-2020-11651CRITICALunder attack01 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
Exploit-DBVexDay Proof
Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
CVE-2016-4437CRITICALunder attackremotemultiple01 May 2020
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISK
open
GitHub PoC108
Salt security backports for CVE-2020-11651 & CVE-2020-11652
CVE-2020-11651CRITICALunder attack01 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
GitHub PoC
Billith/CVE-2019-5736-PoC
CVE-2019-573601 May 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALunder attack01 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
VulnCheck XDB
local
CVE-2019-573601 May 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
Metasploit300
WebLogic Server Deserialization RCE BadAttributeValueExpException ExtComp
CVE-2020-2883CRITICALunder attack30 Apr 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-11882HIGHunder attackransomware30 Apr 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
previouspage 774 / 2,641next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.