Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC18
Weaponized PoC for SMBv3 TCP codec/compression vulnerability
CVE-2020-0796CRITICALunder attackransomware10 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Exploit-DB
Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution
CVE-2020-8518webappsphp10 Mar 2020
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execu
60RISK
open
Exploit-DBVexDay Proof
Google Chrome 67_ 68 and 69 - Object.create Type Confusion (Metasploit)
CVE-2018-17463HIGHunder attackremotemultiple09 Mar 2020
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RISK
open
Exploit-DBVexDay Proof
Apache ActiveMQ 5.x-5.11.1 - Directory Traversal Shell Upload (Metasploit)
CVE-2015-1830remotewindows09 Mar 2020
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5
60RISK
open
Exploit-DBVexDay Proof
OpenSMTPD - OOB Read Local Privilege Escalation (Metasploit)
CVE-2020-8794locallinux09 Mar 2020
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult
60RISK
open
Exploit-DBVexDay Proof
Google Chrome 80 - JSCreate Side-effect Type Confusion (Metasploit)
CVE-2020-6418HIGHunder attackremotemultiple09 Mar 2020
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISK
open
GitHub PoC13
PoC of CVE-2019-15126 kr00k vulnerability
CVE-2019-1512609 Mar 2020
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal
23RISK
open
Exploit-DBVexDay Proof
PHP-FPM - Underflow Remote Code Execution (Metasploit)
CVE-2019-11043HIGHunder attackransomwareremotephp09 Mar 2020
Underflow in PHP-FPM can lead to RCE
100RISK
open
Exploit-DBVexDay Proof
Google Chrome 72 and 73 - Array.map Out-of-Bounds Write (Metasploit)
CVE-2019-5825MEDIUMunder attackremotemultiple09 Mar 2020
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi
90RISK
open
GitHub PoC1
exploit for sudo CVE-2019-18634
CVE-2019-1863409 Mar 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open
Metasploit600
Pandora FMS Ping Authenticated Remote Code Execution
CVE-2025-34088HIGH09 Mar 2020
Pandora FMS Authenticated Remote Code Execution via Ping Module
36RISK
open
GitHub PoC1
Gather a list of Citrix appliances in a country / state pair, and check if they're vulnerable to CVE-2019-19781
CVE-2019-19781CRITICALunder attackransomware08 Mar 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALunder attackransomware08 Mar 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC177
Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE
CVE-2020-2555CRITICALunder attack07 Mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-2555CRITICALunder attack07 Mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
VulnCheck XDB
client-side
CVE-2017-7269CRITICALunder attack07 Mar 2020
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC
simple poc for CVE-2020-0069
CVE-2020-0069HIGHunder attack07 Mar 2020
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RISK
open
GitHub PoC47
CVE-2020-8597 pppd buffer overflow poc
CVE-2020-8597CRITICAL07 Mar 2020
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHunder attackransomware07 Mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC45
CVE-2020-2555 Python POC
CVE-2020-2555CRITICALunder attack06 Mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
VulnCheck XDB
initial-access
CVE-2012-268806 Mar 2020
Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.
28RISK
open
GitHub PoC6
A CVE-2019-11580 shell
CVE-2019-11580CRITICALunder attackransomware06 Mar 2020
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RISK
open
GitHub PoC
CVE-2020-8597
CVE-2020-8597CRITICAL06 Mar 2020
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RISK
open
VulnCheck XDB
initial-access
CVE-2020-2555CRITICALunder attack06 Mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
GitHub PoC3
Hu3sky/CVE-2020-2555
CVE-2020-2555CRITICALunder attack06 Mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-11580CRITICALunder attackransomware06 Mar 2020
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RISK
open
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8657CRITICALunder attackremotemultiple05 Mar 2020
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include
100RISK
open
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8655HIGHunder attackremotemultiple05 Mar 2020
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RISK
open
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8654remotemultiple05 Mar 2020
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD
60RISK
open
Exploit-DBVexDay Proof
Exchange Control Panel - Viewstate Deserialization (Metasploit)
CVE-2020-0688HIGHunder attackransomwareremotewindows05 Mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
previouspage 787 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.