Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
79,212 exploits
GitHub PoC2
VMWare vmdir missing access control exploit checker
CVE-2020-3952CRITICALunder attack17 Apr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
Metasploit300
SpamTitan Unauthenticated RCE
CVE-2020-1169817 Apr 2020
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp
60RISK
open
Exploit-DBVexDay Proof
PlaySMS - index.php Unauthenticated Template Injection Code Execution (Metasploit)
CVE-2020-8644CRITICALunder attackremotephp16 Apr 2020
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
100RISK
open
Exploit-DBVexDay Proof
ThinkPHP - Multiple PHP Injection RCEs (Metasploit)
CVE-2019-9082HIGHunder attackremotelinux16 Apr 2020
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RISK
open
Exploit-DBVexDay Proof
TP-Link Archer A7/C7 - Unauthenticated LAN Remote Code Execution (Metasploit)
CVE-2020-10884HIGHremotelinux_mips16 Apr 2020
This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer
61RISK
open
Exploit-DBVexDay Proof
Apache Solr - Remote Code Execution via Velocity Template (Metasploit)
CVE-2019-17558HIGHunder attackremotemultiple16 Apr 2020
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RISK
open
Exploit-DBVexDay Proof
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
CVE-2018-15811HIGHunder attackremotewindows16 Apr 2020
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
100RISK
open
Exploit-DBVexDay Proof
TP-Link Archer A7/C7 - Unauthenticated LAN Remote Code Execution (Metasploit)
CVE-2020-10883MEDIUMremotelinux_mips16 Apr 2020
This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware
48RISK
open
Exploit-DBVexDay Proof
Liferay Portal - Java Unmarshalling via JSONWS RCE (Metasploit)
CVE-2020-7961CRITICALunder attackremotejava16 Apr 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
GitHub PoC11
CVE-2020-5260演示记录
CVE-2020-5260CRITICAL16 Apr 2020
malicious URLs may cause Git to present stored credentials to the wrong server
53RISK
open
Exploit-DBVexDay Proof
ThinkPHP - Multiple PHP Injection RCEs (Metasploit)
CVE-2018-20062CRITICALunder attackremotelinux16 Apr 2020
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-10199HIGHunder attack16 Apr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
Exploit-DBVexDay Proof
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
CVE-2018-15812remotewindows16 Apr 2020
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expect
50RISK
open
Exploit-DBVexDay Proof
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
CVE-2018-18325HIGHunder attackremotewindows16 Apr 2020
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue ex
100RISK
open
Exploit-DBVexDay Proof
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
CVE-2018-18326remotewindows16 Apr 2020
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expect
50RISK
open
GitHub PoC28
This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.
CVE-2019-11510CRITICALunder attackransomware16 Apr 2020
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open
Exploit-DBVexDay Proof
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
CVE-2017-9822HIGHunder attackransomwareremotewindows16 Apr 2020
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RISK
open
Exploit-DBVexDay Proof
TP-Link Archer A7/C7 - Unauthenticated LAN Remote Code Execution (Metasploit)
CVE-2020-10882HIGHremotelinux_mips16 Apr 2020
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Arch
68RISK
open
Exploit-DBVexDay Proof
VMware Fusion - USB Arbitrator Setuid Privilege Escalation (Metasploit)
CVE-2020-3950HIGHunder attacklocalmacos16 Apr 2020
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for
86RISK
open
VulnCheck XDB
initial-access
CVE-2020-3952CRITICALunder attack16 Apr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
GitHub PoC42
CVE-2020-10199 Nexus <= 3.21.1 远程代码执行脚本(有回显)
CVE-2020-10199HIGHunder attack16 Apr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
GitHub PoC274
Exploit for CVE-2020-3952 in vCenter 6.7
CVE-2020-3952CRITICALunder attack16 Apr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
VulnCheck XDB
infoleak
CVE-2016-6415HIGHunder attack15 Apr 2020
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-20085HIGHunder attack15 Apr 2020
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISK
open
GitHub PoC4
Vuln Check
CVE-2020-3952CRITICALunder attack15 Apr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
GitHub PoC37
A HTTP PoC Endpoint for cve-2020-5260 which can be deployed to Heroku
CVE-2020-5260CRITICAL15 Apr 2020
malicious URLs may cause Git to present stored credentials to the wrong server
53RISK
open
GitHub PoC
https://bugs.chromium.org/p/project-zero/issues/detail?id=2021
CVE-2020-5260CRITICAL15 Apr 2020
malicious URLs may cause Git to present stored credentials to the wrong server
53RISK
open
GitHub PoC6
NVMS 1000 - Directory Traversal Attack Exploit for CVE-2019-20085
CVE-2019-20085HIGHunder attack15 Apr 2020
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISK
open
Metasploit300
Veeam ONE Agent .NET Deserialization
CVE-2020-10915CRITICAL15 Apr 2020
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.
85RISK
open
Metasploit300
Veeam ONE Agent .NET Deserialization
CVE-2020-10914CRITICAL15 Apr 2020
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.
75RISK
open
previouspage 777 / 2,641next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.