Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
79,107 exploits
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALunder attack17 Mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
Exploit-DBVexDay Proof
Rconfig 3.x - Chained Remote Code Execution (Metasploit)
CVE-2019-19509remotelinux17 Mar 2020
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a
60RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware17 Mar 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-0796CRITICALunder attackransomware16 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware16 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC3
CVE-2020-0796_CoronaBlue_SMBGhost
CVE-2020-0796CRITICALunder attackransomware16 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC1
Lightweight PoC and Scanner for CVE-2020-0796 without authentication.
CVE-2020-0796CRITICALunder attackransomware16 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC1
Scanner for CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware16 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC9
CVE-2020-0796-Scanner
CVE-2020-0796CRITICALunder attackransomware15 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC22
An unauthenticated PoC for CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware15 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC148
CVE-2019-0708 (BlueKeep) proof of concept allowing pre-auth RCE on Windows7
CVE-2019-0708CRITICALunder attackransomware15 Mar 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware15 Mar 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DB
Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC)
CVE-2020-0796CRITICALunder attackransomwaredoswindows14 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC15
基于asyncio(协程)的CVE-2020-0796 速度还是十分可观的,方便运维师傅们对内网做下快速检测。
CVE-2020-0796CRITICALunder attackransomware14 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
CVE-2020-0796 Python POC buffer overflow
CVE-2020-0796CRITICALunder attackransomware14 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC14
Advanced scanner for CVE-2020-0796 - SMBv3 RCE
CVE-2020-0796CRITICALunder attackransomware14 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack14 Mar 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC1
Little scanner to know if a machine is runnig SMBv3 (possible vulnerability CVE-2020-0796)
CVE-2020-0796CRITICALunder attackransomware13 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC5
CVE-2020-0796 - Working PoC - 20200313
CVE-2020-0796CRITICALunder attackransomware13 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
qq1515406085/CVE-2019-19356
CVE-2019-19356HIGHunder attack13 Mar 2020
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page.
76RISK
open
Metasploit400
SMBv3 Compression Buffer Overflow
CVE-2020-0796CRITICALunder attackransomware13 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
A POC remote buffer overflow for CVE-2003-0264 - SLMail 5.5
CVE-2003-026413 Mar 2020
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISK
open
Metasploit200
SMBv3 Compression Buffer Overflow
CVE-2020-0796CRITICALunder attackransomware13 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC224
PoC exploit for the CVE-2019-15126 kr00k vulnerability
CVE-2019-1512613 Mar 2020
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal
23RISK
open
Exploit-DB
WordPress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
CVE-2020-9371webappsphp12 Mar 2020
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php
23RISK
open
Metasploit300
vBulletin /ajax/api/content_infraction/getIndexableContent nodeid Parameter SQL Injection
CVE-2020-1272012 Mar 2020
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
40RISK
open
Exploit-DB
WordPress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
CVE-2020-9372webappsphp12 Mar 2020
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or
23RISK
open
GitHub PoC1
SMBGhost (CVE-2020-0796) threaded scanner
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
Check system is vulnerable CVE-2020-0796 (SMB v3)
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
previouspage 782 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.