Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
79,211 exploits
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALunder attackransomware22 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC35
Whatsapp Automatic Payload Generator [CVE-2019-11932]
CVE-2019-1193222 Apr 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
GitHub PoC3
PoC RCE Reverse Shell for CVE-2020-0688
CVE-2020-0688HIGHunder attackransomware22 Apr 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC1
3x1t1um/CVE-2007-2447
CVE-2007-244722 Apr 2020
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC
section-c/CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware22 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC11
PoC RCE Reverse Shell for CVE-2020-0796 (SMBGhost)
CVE-2020-0796CRITICALunder attackransomware22 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC2
snappyJack/pdfresurrect_CVE-2019-14267
CVE-2019-1426722 Apr 2020
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is misha
23RISK
open
Metasploit600
IBM Data Risk Manager Unauthenticated Remote Code Execution
CVE-2020-4428CRITICALunder attack21 Apr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary co
85RISK
open
Metasploit600
IBM Data Risk Manager Unauthenticated Remote Code Execution
CVE-2020-4429CRITICAL21 Apr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ
65RISK
open
Metasploit600
IBM Data Risk Manager a3user Default Password
CVE-2020-4429CRITICAL21 Apr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ
65RISK
open
Metasploit600
IBM Data Risk Manager Unauthenticated Remote Code Execution
CVE-2020-4427CRITICALunder attack21 Apr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security rest
95RISK
open
Metasploit300
IBM Data Risk Manager Arbitrary File Download
CVE-2020-4427CRITICALunder attack21 Apr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security rest
95RISK
open
Metasploit300
IBM Data Risk Manager Arbitrary File Download
CVE-2020-4429CRITICAL21 Apr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ
65RISK
open
GitHub PoC2
CVE-2004-1769 cPanel Resetpass Remote Command Execution
CVE-2004-176921 Apr 2020
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x,
35RISK
open
Exploit-DB
Neowise CarbonFTP 1.4 - Insecure Proprietary Password Encryption
CVE-2020-6857remotewindows21 Apr 2020
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FT
23RISK
open
Exploit-DB
Oracle Solaris Common Desktop Environment 1.6 - Local Privilege Escalation
CVE-2020-2944HIGHlocalsolaris21 Apr 2020
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported version
41RISK
open
Exploit-DBVexDay Proof
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
CVE-2020-5849HIGHunder attackremotelinux20 Apr 2020
Unraid 6.8.0 allows authentication bypass.
100RISK
open
Exploit-DBVexDay Proof
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
CVE-2020-5847CRITICALunder attackremotelinux20 Apr 2020
Unraid through 6.8.0 allows Remote Code Execution.
100RISK
open
GitHub PoC
darren646/CVE-2019-19781POC
CVE-2019-19781CRITICALunder attackransomware20 Apr 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC571
CVE-2020-0796 Remote Code Execution POC
CVE-2020-0796CRITICALunder attackransomware20 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALunder attackransomware20 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-3952CRITICALunder attack19 Apr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
GitHub PoC4
Exploit for CVE-2020-3952 in vCenter 6.7 https://www.guardicore.com/2020/04/pwning-vmware-vcenter-cve-2020-3952/
CVE-2020-3952CRITICALunder attack19 Apr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
GitHub PoC
kristyna-mlcakova/CVE-2018-10933
CVE-2018-10933CRITICAL19 Apr 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC1
D-LINK ROUTER "MODEL NO: DIR-615" with "FIRMWARE VERSION:20.10" & "HARDWARE VERSION:T1
CVE-2019-1752518 Apr 2020
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and
23RISK
open
Metasploit0
Kibana Upgrade Assistant Telemetry Collector Prototype Pollution
CVE-2020-701217 Apr 2020
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authen
23RISK
open
Metasploit300
SpamTitan Unauthenticated RCE
CVE-2020-1169817 Apr 2020
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-3952CRITICALunder attack17 Apr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
GitHub PoC2
VMWare vmdir missing access control exploit checker
CVE-2020-3952CRITICALunder attack17 Apr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
Exploit-DB
Cisco IP Phone 11.7 - Denial of service (PoC)
CVE-2020-3161CRITICALunder attackdoshardware17 Apr 2020
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
100RISK
open
previouspage 776 / 2,641next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.