Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
79,210 exploits
GitHub PoC108
Salt security backports for CVE-2020-11651 & CVE-2020-11652
CVE-2020-11651CRITICALunder attack01 May 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
Metasploit300
SaltStack Salt Master Server Root Key Disclosure
CVE-2020-11651CRITICALunder attack30 Apr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
Metasploit500
SaltStack Salt Master/Minion Unauthenticated RCE
CVE-2020-11652MEDIUMunder attack30 Apr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
Metasploit500
SaltStack Salt Master/Minion Unauthenticated RCE
CVE-2020-11651CRITICALunder attack30 Apr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
Metasploit300
SaltStack Salt Master Server Root Key Disclosure
CVE-2020-11652MEDIUMunder attack30 Apr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
Metasploit300
WebLogic Server Deserialization RCE BadAttributeValueExpException ExtComp
CVE-2020-2883CRITICALunder attack30 Apr 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-11882HIGHunder attackransomware30 Apr 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware30 Apr 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
Metasploit300
Wordpress LearnPress current_items Authenticated SQLi
CVE-2020-601029 Apr 2020
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
50RISK
open
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALunder attack29 Apr 2020
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
Metasploit600
TP-Link Cloud Cameras NCXXX Bonjour Command Injection
CVE-2020-1210929 Apr 2020
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220
40RISK
open
Exploit-DBVexDay Proof
Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
CVE-2019-3999localwindows29 Apr 2020
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, u
38RISK
open
GitHub PoC1
yukar1z0e/CVE-2018-14847
CVE-2018-14847CRITICALunder attack29 Apr 2020
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
Exploit-DBVexDay Proof
Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
CVE-2019-15752HIGHunder attacklocalwindows28 Apr 2020
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-c
98RISK
open
Metasploit600
Netsweeper WebAdmin unixlogin.php Python Code Injection
CVE-2020-1316728 Apr 2020
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain
40RISK
open
Metasploit600
GOG GalaxyClientService Privilege Escalation
CVE-2020-7352HIGH28 Apr 2020
GOG Galaxy GalaxyClientService Privilege Escalation
36RISK
open
Metasploit600
TrixBox CE endpoint_devicemap.php Authenticated Command Execution
CVE-2020-7351HIGH28 Apr 2020
Fonality Trixbox CE Post-Authentication Command Injection
48RISK
open
Metasploit400
WordPress Simple File List Unauthenticated Remote Code Execution
CVE-2020-36847CRITICAL27 Apr 2020
Simple File List < 4.2.3 - Remote Code Execution
75RISK
open
Exploit-DB
Source Engine CS:GO BuildID: 4937372 - Arbitrary Code Execution
CVE-2020-12242localmacos27 Apr 2020
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in
23RISK
open
GitHub PoC102
Hikvision camera CVE-2017-7921-EXP
CVE-2017-7921CRITICALunder attack27 Apr 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC1
wcxxxxx/CVE-2020-7961
CVE-2020-7961CRITICALunder attack27 Apr 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
GitHub PoC
CVE-2018-15133 (Webased)
CVE-2018-15133HIGHunder attack27 Apr 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-7921CRITICALunder attack27 Apr 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware26 Apr 2020
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC
Sudo Vulnerability CVE-2019-14287
CVE-2019-1428726 Apr 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC2
WordPress CVE-2017-5487 Exploit in Python
CVE-2017-548726 Apr 2020
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISK
open
GitHub PoC7
android-kernel-exploitation-ashfaq-CVE-2019-2215 docker setup for mac users
CVE-2019-2215HIGHunder attack25 Apr 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
GitHub PoC
JJSO12/Apache-Pluto-3.0.0--CVE-2018-1306
CVE-2018-130624 Apr 2020
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote a
35RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware23 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
section-c/CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware22 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
previouspage 775 / 2,641next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.