Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
13,947 exploits
GitHub PoC157
Exchange2010 authorized RCE
CVE-2020-17144HIGHunder attack09 Dec 2020
Microsoft Exchange Remote Code Execution Vulnerability
83RISK
open
GitHub PoC157
weaponized tool for CVE-2020-17144
CVE-2020-17144HIGHunder attack09 Dec 2020
Microsoft Exchange Remote Code Execution Vulnerability
83RISK
open
GitHub PoC
WildfootW/CVE-2018-15473_OpenSSH_7.7
CVE-2018-15473MEDIUM09 Dec 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC
WildfootW/CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed
CVE-2014-0160HIGHunder attack09 Dec 2020
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
Remote code execution in Mediawiki Score
CVE-2020-29007CRITICAL08 Dec 2020
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of
48RISK
open
GitHub PoC
Exploit for the vulnerability CVE-2007-2447
CVE-2007-244706 Dec 2020
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC1
PoC for CVE: 2017-5638 - Apache Struts2 S2-045
CVE-2017-5638CRITICALunder attackransomware06 Dec 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
[qdPM < 9.1 - Remote Code Execution](https://www.exploit-db.com/exploits/48146)
CVE-2020-724605 Dec 2020
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISK
open
GitHub PoC14
This small script helps to avoid using MetaSploit (msfconsole) during the Enterprise pentests and OSCP-like exams. Grep included function will help you to get only the important information.
CVE-2006-339204 Dec 2020
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISK
open
GitHub PoC
diegojuan/CVE-2019-15107
CVE-2019-15107CRITICALunder attackransomware03 Dec 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC
ActorExpose/CVE-2017-11882
CVE-2017-11882HIGHunder attackransomware03 Dec 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC1
Scan through given ip list
CVE-2019-0708CRITICALunder attackransomware03 Dec 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC34
CVE-2020-27950 exploit
CVE-2020-27950MEDIUMunder attack01 Dec 2020
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RISK
open
GitHub PoC49
Python / scapy module implementing SRVLOC/SLP protocol and scans for enabled OpenSLP services.
CVE-2020-3992CRITICALunder attackransomware01 Dec 2020
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-
100RISK
open
GitHub PoC49
Python / scapy module implementing SRVLOC/SLP protocol and scans for enabled OpenSLP services.
CVE-2019-5544CRITICALunder attackransomware01 Dec 2020
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of
100RISK
open
GitHub PoC1
Scanning tool to test for SaltStack vulnerabilities CVE-2020-11651 & CVE-2020-11652.
CVE-2020-11651CRITICALunder attack30 Nov 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
GitHub PoC
wikiZ/cve-2018-8120
CVE-2018-8120HIGHunder attackransomware30 Nov 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
GitHub PoC9
This module massively scan and exploit a path traversal vulnerability in the FortiOS SSL VPN web portal may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests (CVE-2018-13379).
CVE-2018-13379CRITICALunder attackransomware30 Nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
GitHub PoC1
wikiZ/cve-2014-4113
CVE-2014-4113HIGHunder attack30 Nov 2020
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISK
open
GitHub PoC42
OpenSSH 2.3 < 7.7 - Username Enumeration
CVE-2018-15473MEDIUM29 Nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC
Vbulletin RCE Exploits
CVE-2019-16759CRITICALunder attack29 Nov 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
GitHub PoC1
Exploit script for Apache Struts2 REST Plugin XStream RCE (‎CVE-2017-9805)
CVE-2017-9805HIGHunder attack28 Nov 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
GitHub PoC
Dirty-Racoon/CVE-2018-15473-py3
CVE-2018-15473MEDIUM27 Nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC5
CVE-2020-2883
CVE-2020-2883CRITICALunder attack26 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
GitHub PoC
openssh<7.7 用户名枚举
CVE-2018-15473MEDIUM26 Nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC4
A CVE-2020-17087 PoC.
CVE-2020-17087HIGHunder attack26 Nov 2020
Windows Kernel Local Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC1
www201001/https-github.com-iBearcat-CVE-2018-8174_EXP
CVE-2018-8174HIGHunder attackransomware24 Nov 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
GitHub PoC1
www201001/https-github.com-iBearcat-CVE-2018-8174_EXP.git-
CVE-2018-8174HIGHunder attackransomware24 Nov 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
GitHub PoC
1stPeak/CVE-2018-15473
CVE-2018-15473MEDIUM23 Nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC1
This container was made to explain and demonstrate how CVE-2019-15813 (Sentrifugo works)
CVE-2019-1581322 Nov 2020
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arb
35RISK
open
previouspage 384 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.