Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
13,947 exploits
GitHub PoC2
MasterSploit/LPE---CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware20 Nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC6
FortiVuln
CVE-2018-13379CRITICALunder attackransomware19 Nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
GitHub PoC4
PHP-FPM Remote Command Execution Exploit
CVE-2019-11043HIGHunder attackransomware18 Nov 2020
Underflow in PHP-FPM can lead to RCE
100RISK
open
GitHub PoC4
CVE-2020-3452
CVE-2020-3452HIGHunder attack18 Nov 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC2
CVE-2017-10271
CVE-2017-10271HIGHunder attackransomware18 Nov 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC10
CVE-2017-3506
CVE-2017-3506HIGHunder attack18 Nov 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC
DHCP exploitation with DynoRoot (CVE-2018-1111)
CVE-2018-1111HIGH17 Nov 2020
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISK
open
GitHub PoC9
A Remote Code Execution (RCE) exploit for Huawei HG532d based on CVE-2017-17215 vulnerability. Modded from original PoC code from exploit-db.com
CVE-2017-1721517 Nov 2020
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
45RISK
open
GitHub PoC
windows.vm
CVE-2019-3396CRITICALunder attackransomware17 Nov 2020
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC
BabyTeam1024/CVE-2020-14882
CVE-2020-14882CRITICALunder attack17 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC1
b1ack0wl/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware16 Nov 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
nex1less/CVE-2015-4852
CVE-2015-4852CRITICALunder attack16 Nov 2020
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISK
open
GitHub PoC57
Exploit for Laravel Remote Code Execution with API_KEY (CVE-2018-15133)
CVE-2018-15133HIGHunder attack13 Nov 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC12
Hikvision IP camera access bypass exploit, developed by golang.
CVE-2017-7921CRITICALunder attack13 Nov 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC
rvermeulen/apache-struts-cve-2017-9805
CVE-2017-9805HIGHunder attack13 Nov 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
GitHub PoC1
CVE-2020-25213 Wordpress File Manager 6.7 Plugin 0day exploit
CVE-2020-25213CRITICALunder attack13 Nov 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
GitHub PoC
MuirlandOracle/CVE-2014-6271-IPFire
CVE-2014-6271CRITICALunder attack12 Nov 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC36
海康威视未授权访问检测poc及口令爆破
CVE-2017-7921CRITICALunder attack12 Nov 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC3
zavke/CVE-2020-10189-ManageEngine
CVE-2020-10189CRITICALunder attack12 Nov 2020
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RISK
open
GitHub PoC5
xfiftyone/CVE-2020-14882
CVE-2020-14882CRITICALunder attack12 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC2
A very simple buffer overflow using CVE-2013-4730 against PCman's FTP server
CVE-2013-473012 Nov 2020
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open
GitHub PoC7
Detection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750
CVE-2020-14882CRITICALunder attack12 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC2
基于qt的图形化CVE-2020-14882漏洞回显测试工具.
CVE-2020-14882CRITICALunder attack11 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC7
Weblogic 身份认证绕过漏洞批量检测脚本
CVE-2020-14883HIGHunder attack11 Nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
Frivolous-scholar/CVE-2017-5941-NodeJS-RCE
CVE-2017-594110 Nov 2020
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISK
open
GitHub PoC
HaoJame/CVE-2017-11882
CVE-2017-11882HIGHunder attackransomware10 Nov 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC
Dicha vulnerabilidad se presentaba en la funcionalidad mc_project_get_users, y su detección es tan solo modificando y enviando el parámetro “access” sin ningún valor y cambiando el tipo de valor a String.
CVE-2020-28413MEDIUM10 Nov 2020
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the A
33RISK
open
GitHub PoC1
datntsec/CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware10 Nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
The following is the outcome of playing with CVE-2020-1472 and attempting to automate the process of gaining a shell on the DC
CVE-2020-1472MEDIUMunder attackransomware10 Nov 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
An automated PoC for CVE 2018-15133
CVE-2018-15133HIGHunder attack09 Nov 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
previouspage 385 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.