Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
13,947 exploits
GitHub PoC6
CVE-2020-11652 & CVE-2020-11651
CVE-2020-11652MEDIUMunder attack25 Dec 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
GitHub PoC7
Weblogic Server CVE-2020-14645 EXP for Python (complete in one step)
CVE-2020-14645CRITICAL24 Dec 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISK
open
GitHub PoC
Insecure Folder permission that lead to privilege escalation
CVE-2020-2816924 Dec 2020
The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory
23RISK
open
GitHub PoC
wood03mm/CVE-2016-3088
CVE-2016-3088CRITICALunder attack24 Dec 2020
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC
SaharAttackit/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware23 Dec 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
Webmin Exploit Scanner CVE-2020-35606 CVE-2019-12840
CVE-2019-1284023 Dec 2020
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISK
open
GitHub PoC
Webmin Exploit Scanner CVE-2020-35606 CVE-2019-12840
CVE-2020-3560623 Dec 2020
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can ex
28RISK
open
GitHub PoC4
Supervisord远程命令执行漏洞脚本
CVE-2017-1161022 Dec 2020
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISK
open
GitHub PoC35
Laravel RCE exploit. CVE-2018-15133
CVE-2018-15133HIGHunder attack21 Dec 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC2
Collection of PoCs created for SmarterMail < Build 6985 RCE
CVE-2019-721420 Dec 2020
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RISK
open
GitHub PoC1
POC for CVE-2018-0114 written in Go
CVE-2018-011420 Dec 2020
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
GitHub PoC2
DirtyCOW Exploit for Android
CVE-2016-5195HIGHunder attack20 Dec 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
https://github.com/awakened1712/CVE-2019-11932://github.com/awakened1712/CVE-2019-11932
CVE-2019-1193220 Dec 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
GitHub PoC
(cve-2020-17530) struts2_s2-061 freemarker_RCE testscript
CVE-2020-17530CRITICALunder attack18 Dec 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
GitHub PoC2
edxsh/CVE-2019-0752
CVE-2019-0752HIGHunder attackransomware18 Dec 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISK
open
GitHub PoC
cve-2019-0708 vulnerablility scanner
CVE-2019-0708CRITICALunder attackransomware17 Dec 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
Apache Solr 1.4 Injection to get a shell
CVE-2019-17558HIGHunder attack15 Dec 2020
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RISK
open
GitHub PoC1
GuillaumePetit84/CVE-2020-35488
CVE-2020-3548815 Dec 2020
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of
23RISK
open
GitHub PoC7
CVE-2020-17530-strust2-061
CVE-2020-17530CRITICALunder attack14 Dec 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
GitHub PoC9
Fortinet FortiOS路径遍历漏洞 (CVE-2018-13379)批量检测脚本
CVE-2018-13379CRITICALunder attackransomware14 Dec 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
GitHub PoC26
cygenta/CVE-2020-3452
CVE-2020-3452HIGHunder attack13 Dec 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC2
CVE-2014-0160 OpenSSL Heartbleed Proof of Concept
CVE-2014-0160HIGHunder attack13 Dec 2020
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC29
S2-061 CVE-2020-17530
CVE-2020-17530CRITICALunder attack13 Dec 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
GitHub PoC
MasterSploit/CVE-2020-0787-BitsArbitraryFileMove-master
CVE-2020-0787HIGHunder attackransomware11 Dec 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISK
open
GitHub PoC9
S2-059(CVE-2019-0230)
CVE-2019-023011 Dec 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISK
open
GitHub PoC
MasterSploit/CVE-2020-0787
CVE-2020-0787HIGHunder attackransomware11 Dec 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISK
open
GitHub PoC46
S2-061 的payload,以及对应简单的PoC/Exp
CVE-2020-17530CRITICALunder attack10 Dec 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
GitHub PoC64
ka1n4t/CVE-2020-17530
CVE-2020-17530CRITICALunder attack09 Dec 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
GitHub PoC1
Apache Struts2框架是一个用于开发Java EE网络应用程序的Web框架。Apache Struts于2020年12月08日披露 S2-061 Struts 远程代码执行漏洞(CVE-2020-17530),在使用某些tag等情况下可能存在OGNL表达式注入漏洞,从而造成远程代码执行,风险极大。提醒我校Apache Struts用户尽快采取安全措施阻止漏洞攻击。
CVE-2020-17530CRITICALunder attack09 Dec 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
GitHub PoC
WildfootW/CVE-2018-15473_OpenSSH_7.7
CVE-2018-15473MEDIUM09 Dec 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
previouspage 383 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.