Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC163
cve-2020-0688
CVE-2020-0688HIGHunder attackransomware25 Feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-15133HIGHunder attack25 Feb 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
Exploit-DBVexDay Proof
Android Binder - Use-After-Free (Metasploit)
CVE-2019-2215HIGHunder attacklocalandroid24 Feb 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
Metasploit200
OpenSMTPD OOB Read Local Privilege Escalation
CVE-2020-879424 Feb 2020
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult
60RISK
open
Exploit-DB
Avaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site Scripting
CVE-2019-7004MEDIUMwebappshardware24 Feb 2020
Avaya IP Office XSS Vulnerability
33RISK
open
Exploit-DB
Go SSH servers 0.0.2 - Denial of Service (PoC)
CVE-2020-9283doslinux24 Feb 2020
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the
28RISK
open
Exploit-DBVexDay Proof
Apache James Server 2.3.2 - Insecure User Creation Arbitrary File Write (Metasploit)
CVE-2015-7611remotelinux24 Feb 2020
Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary syst
50RISK
open
Exploit-DB
ManageEngine EventLog Analyzer 10.0 - Information Disclosure
CVE-2019-19774webappsjava24 Feb 2020
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetai
28RISK
open
VulnCheck XDB
local
CVE-2014-0160HIGHunder attack23 Feb 2020
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC67
The official exploit for Cacti v1.2.8 Remote Code Execution CVE-2020-8813
CVE-2020-881322 Feb 2020
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISK
open
GitHub PoC423
Ghostcat read file/code execute,CNVD-2020-10487(CVE-2020-1938)
CVE-2020-1938CRITICALunder attack22 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1938CRITICALunder attack22 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC6
PoC exploit for CVE-2015-2291
CVE-2015-2291HIGHunder attackransomware22 Feb 2020
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISK
open
GitHub PoC3
CNVD-2020-10487 OR CVE-2020-1938 批量验证脚本,批量验证,并自动截图,方便提交及复核
CVE-2020-1938CRITICALunder attack22 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC14
批量扫描TomcatAJP漏洞
CVE-2020-1938CRITICALunder attack21 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC7
fatal0/tomcat-cve-2020-1938-check
CVE-2020-1938CRITICALunder attack21 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
Metasploit600
WordPress wpDiscuz Unauthenticated File Upload Vulnerability
CVE-2020-24186CRITICAL21 Feb 2020
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISK
open
GitHub PoC11
在一定条件下可执行命令
CVE-2020-1938CRITICALunder attack21 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC2
h7hac9/CVE-2020-1938
CVE-2020-1938CRITICALunder attack21 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC9
dacade/CVE-2020-1938
CVE-2020-1938CRITICALunder attack21 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC38
CVE-2020-1938漏洞复现
CVE-2020-1938CRITICALunder attack21 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC56
Tomcat的文件包含及文件读取漏洞利用POC
CVE-2020-1938CRITICALunder attack21 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1938CRITICALunder attack21 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALunder attack20 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALunder attack20 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
Exploit-DB
Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
CVE-2020-1938CRITICALunder attackwebappsmultiple20 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC3
CVE-2020-1938
CVE-2020-1938CRITICALunder attack20 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
Metasploit300
Apache Tomcat AJP File Read
CVE-2020-1938CRITICALunder attack20 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC
Mass Exploit CVE-2019-16759
CVE-2019-16759CRITICALunder attack20 Feb 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
GitHub PoC294
Cnvd-2020-10487 / cve-2020-1938, scanner tool
CVE-2020-1938CRITICALunder attack20 Feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
previouspage 790 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.