Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8657CRITICALunder attackremotemultiple05 Mar 2020
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include
100RISK
open
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8654remotemultiple05 Mar 2020
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD
60RISK
open
Exploit-DBVexDay Proof
Exchange Control Panel - Viewstate Deserialization (Metasploit)
CVE-2020-0688HIGHunder attackransomwareremotewindows05 Mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-8655HIGHunder attack05 Mar 2020
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RISK
open
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8656remotemultiple05 Mar 2020
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe
60RISK
open
GitHub PoC
CVE-2019-13272
CVE-2019-13272HIGHunder attack05 Mar 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC5
PoC for Forgot2kEyXCHANGE (CVE-2020-0688) written in PowerShell
CVE-2020-0688HIGHunder attackransomware04 Mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
Metasploit600
Metasploit Libnotify Plugin Arbitrary Command Execution
CVE-2020-7350MEDIUM04 Mar 2020
Metasploit Framework Plugin Libnotify Command Injection
28RISK
open
Exploit-DB
Alfresco 5.2.4 - Persistent Cross-Site Scripting
CVE-2020-8777webappsphp03 Mar 2020
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo,
23RISK
open
GitHub PoC17
reversing mtk-su
CVE-2020-0069HIGHunder attack03 Mar 2020
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RISK
open
VulnCheck XDB
local
CVE-2019-1458HIGHunder attackransomware03 Mar 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
GitHub PoC
CVE-2020-1938
CVE-2020-1938CRITICALunder attack03 Mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
Exploit-DB
Alfresco 5.2.4 - Persistent Cross-Site Scripting
CVE-2020-8778webappsphp03 Mar 2020
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document,
23RISK
open
Exploit-DB
Microsoft Windows - 'WizardOpium' Local Privilege Escalation
CVE-2019-1458HIGHunder attackransomwarelocalwindows03 Mar 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
Exploit-DB
Alfresco 5.2.4 - Persistent Cross-Site Scripting
CVE-2020-8776webappsphp03 Mar 2020
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a
23RISK
open
GitHub PoC
PoC of CVE
CVE-2020-6418HIGHunder attack03 Mar 2020
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISK
open
GitHub PoC
exploitblizzard/CVE-2020-0601-spoofkey
CVE-2020-0601HIGHunder attack03 Mar 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC181
POC for cve-2019-1458
CVE-2019-1458HIGHunder attackransomware03 Mar 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
Exploit-DB
CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
CVE-2020-8012remotewindows02 Mar 2020
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerabi
60RISK
open
VulnCheck XDB
denial-of-service
CVE-2018-6789CRITICALunder attackransomware02 Mar 2020
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open
Exploit-DB
TP LINK TL-WR849N - Remote Code Execution
CVE-2020-9374webappshardware02 Mar 2020
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploit
35RISK
open
Exploit-DB
Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
CVE-2020-0688HIGHunder attackransomwareremotewindows02 Mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
Exploit-DB
TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)
CVE-2019-19143webappshardware02 Mar 2020
TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi
23RISK
open
GitHub PoC1
CVE-2019-5096(UAF in upload handler) exploit cause Denial of Service
CVE-2019-5096CRITICAL02 Mar 2020
An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base Go
60RISK
open
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALunder attack02 Mar 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
Exploit-DB
Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)
CVE-2019-19142webappshardware02 Mar 2020
Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmwa
23RISK
open
VulnCheck XDB
initial-access
CVE-2020-2551CRITICALunder attack02 Mar 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISK
open
GitHub PoC132
CVE-2020-2546,CVE-2020-2915 CVE-2020-2801 CVE-2020-2798 CVE-2020-2883 CVE-2020-2884 CVE-2020-2950 WebLogic T3 payload exploit poc python3,
CVE-2020-2546CRITICAL02 Mar 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - Java
48RISK
open
Exploit-DB
WordPress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
CVE-2020-8615webappsphp02 Mar 2020
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves a
38RISK
open
Exploit-DB
Joplin Desktop 1.0.184 - Cross-Site Scripting
CVE-2020-9038webappsmultiple02 Mar 2020
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
23RISK
open
previouspage 788 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.