Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
79,107 exploits
Metasploit400
Rconfig 3.x Chained Remote Code Execution
CVE-2020-1022011 Mar 2020
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open
Metasploit400
Rconfig 3.x Chained Remote Code Execution
CVE-2019-1950911 Mar 2020
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a
60RISK
open
VulnCheck XDB
infoleak
CVE-2020-0796CRITICALunder attackransomware11 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Metasploit300
CVE-2020-1170 Cloud Filter Arbitrary File Creation EOP
CVE-2020-17136HIGH10 Mar 2020
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
41RISK
open
Metasploit600
Background Intelligent Transfer Service Arbitrary File Move Privilege Elevation Vulnerability
CVE-2020-0787HIGHunder attackransomware10 Mar 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISK
open
Exploit-DB
Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution
CVE-2020-8518webappsphp10 Mar 2020
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execu
60RISK
open
GitHub PoC14
CVE-2020-2555
CVE-2020-2555CRITICALunder attack10 Mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
Exploit-DBVexDay Proof
Nagios XI - Authenticated Remote Command Execution (Metasploit)
CVE-2019-15949HIGHunder attackremotelinux10 Mar 2020
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RISK
open
GitHub PoC18
Weaponized PoC for SMBv3 TCP codec/compression vulnerability
CVE-2020-0796CRITICALunder attackransomware10 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC13
PoC of CVE-2019-15126 kr00k vulnerability
CVE-2019-1512609 Mar 2020
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal
23RISK
open
GitHub PoC1
exploit for sudo CVE-2019-18634
CVE-2019-1863409 Mar 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open
Exploit-DBVexDay Proof
OpenSMTPD - OOB Read Local Privilege Escalation (Metasploit)
CVE-2020-8794locallinux09 Mar 2020
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult
60RISK
open
Exploit-DBVexDay Proof
Google Chrome 72 and 73 - Array.map Out-of-Bounds Write (Metasploit)
CVE-2019-5825MEDIUMunder attackremotemultiple09 Mar 2020
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi
90RISK
open
Exploit-DBVexDay Proof
PHP-FPM - Underflow Remote Code Execution (Metasploit)
CVE-2019-11043HIGHunder attackransomwareremotephp09 Mar 2020
Underflow in PHP-FPM can lead to RCE
100RISK
open
Metasploit600
Pandora FMS Ping Authenticated Remote Code Execution
CVE-2025-34088HIGH09 Mar 2020
Pandora FMS Authenticated Remote Code Execution via Ping Module
36RISK
open
Exploit-DBVexDay Proof
Apache ActiveMQ 5.x-5.11.1 - Directory Traversal Shell Upload (Metasploit)
CVE-2015-1830remotewindows09 Mar 2020
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5
60RISK
open
Exploit-DBVexDay Proof
Google Chrome 80 - JSCreate Side-effect Type Confusion (Metasploit)
CVE-2020-6418HIGHunder attackremotemultiple09 Mar 2020
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISK
open
Exploit-DBVexDay Proof
Google Chrome 67_ 68 and 69 - Object.create Type Confusion (Metasploit)
CVE-2018-17463HIGHunder attackremotemultiple09 Mar 2020
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALunder attackransomware08 Mar 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC1
Gather a list of Citrix appliances in a country / state pair, and check if they're vulnerable to CVE-2019-19781
CVE-2019-19781CRITICALunder attackransomware08 Mar 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC47
CVE-2020-8597 pppd buffer overflow poc
CVE-2020-8597CRITICAL07 Mar 2020
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHunder attackransomware07 Mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
VulnCheck XDB
client-side
CVE-2017-7269CRITICALunder attack07 Mar 2020
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC
simple poc for CVE-2020-0069
CVE-2020-0069HIGHunder attack07 Mar 2020
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RISK
open
VulnCheck XDB
initial-access
CVE-2020-2555CRITICALunder attack07 Mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
GitHub PoC177
Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE
CVE-2020-2555CRITICALunder attack07 Mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-2555CRITICALunder attack06 Mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
GitHub PoC45
CVE-2020-2555 Python POC
CVE-2020-2555CRITICALunder attack06 Mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
GitHub PoC
CVE-2020-8597
CVE-2020-8597CRITICAL06 Mar 2020
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RISK
open
GitHub PoC6
A CVE-2019-11580 shell
CVE-2019-11580CRITICALunder attackransomware06 Mar 2020
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RISK
open
previouspage 784 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.