Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
13,947 exploits
GitHub PoC
Wh1t3Fox/cve-2018-15473
CVE-2018-15473MEDIUM02 Sep 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC2
(CVE-2019-2725) Oracle WLS(Weblogic) RCE test sciript
CVE-2019-2725HIGHunder attackransomware31 Aug 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC1
(CVE-2019-16759) vBulletin_Routestring-RCE
CVE-2019-16759CRITICALunder attack31 Aug 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
GitHub PoC1
(CVE-2017-5638) XworkStruts RCE Vuln test script
CVE-2017-5638CRITICALunder attackransomware31 Aug 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC1
(CVE-2020-3452) Cisco Adaptive Security Appliance Software - Local File Inclusion Vuln Test sciript
CVE-2020-3452HIGHunder attack31 Aug 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC4
(CVE-2019-6340, CVE-2018-7600) drupal8-REST-RCE
CVE-2019-6340HIGHunder attack31 Aug 2020
Drupal core - Highly critical - Remote Code Execution
100RISK
open
GitHub PoC3
PoC of Full Account Takeover on RAD SecFlow-1v
CVE-2020-1325931 Aug 2020
A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauth
23RISK
open
GitHub PoC4
(CVE-2019-6340, CVE-2018-7600) drupal8-REST-RCE
CVE-2018-7600CRITICALunder attackransomware31 Aug 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC22
Tool to test for existence of CVE-2020-8218
CVE-2020-8218HIGHunder attack29 Aug 2020
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform
83RISK
open
GitHub PoC22
[CVE-2017-9822] DotNetNuke Cookie Deserialization Remote Code Execution (RCE)
CVE-2017-9822HIGHunder attackransomware28 Aug 2020
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RISK
open
GitHub PoC
This CVE-2018-8120 File
CVE-2018-8120HIGHunder attackransomware27 Aug 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
GitHub PoC47
An exploit for CVE-2019-17026. It pops xcalc and was tested on Ubuntu (x64).
CVE-2019-17026HIGHunder attack27 Aug 2020
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are
83RISK
open
GitHub PoC
TelerikUI Vulnerability Scanner (CVE-2019-18935)
CVE-2019-18935CRITICALunder attackransomware26 Aug 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC2
Exploit for CVE-2019-16724
CVE-2019-1672425 Aug 2020
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Excepti
60RISK
open
GitHub PoC1
sunian19/CVE-2019-16759
CVE-2019-16759CRITICALunder attack24 Aug 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
GitHub PoC
CVE-2017-8570 Exp及利用样本分析
CVE-2017-0261HIGHunder attack22 Aug 2020
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the softwar
93RISK
open
GitHub PoC35
CVE-2019-0230 & s2-059 poc.
CVE-2019-023020 Aug 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISK
open
GitHub PoC
starling021/CVE-2019-11932-SupportApp
CVE-2019-1193220 Aug 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
GitHub PoC1
ctlyz123/CVE-2020-17496
CVE-2020-17496CRITICALunder attack20 Aug 2020
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe
100RISK
open
GitHub PoC532
WebLogic利用CVE-2020-2883打Shiro rememberMe反序列化漏洞,一键注册蚁剑filter内存shell
CVE-2020-2883CRITICALunder attack19 Aug 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
GitHub PoC16
[CVE-2019-18935] Telerik UI for ASP.NET AJAX (RadAsyncUpload Handler) .NET JSON Deserialization
CVE-2019-18935CRITICALunder attackransomware19 Aug 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC
superzerosec/cve-2020-5902
CVE-2020-5902CRITICALunder attackransomware18 Aug 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
GitHub PoC
Logeirs/CVE-2018-0114
CVE-2018-011418 Aug 2020
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
GitHub PoC4
[CVE-2020-0688] Microsoft Exchange Server Fixed Cryptographic Key Remote Code Execution (RCE)
CVE-2020-0688HIGHunder attackransomware17 Aug 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC1
cyberharsh/PHP_CVE-2012-1823
CVE-2012-1823CRITICALunder attack17 Aug 2020
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISK
open
GitHub PoC6
This tools will extracts and dumps Email + SMTP from vBulletin database server
CVE-2019-16759CRITICALunder attack16 Aug 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
GitHub PoC3
dwisiswant0/CVE-2020-9496
CVE-2020-949615 Aug 2020
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
GitHub PoC7
[CVE-2020-3452] Cisco Adaptive Security Appliance (ASA) & Cisco Firepower Threat Defense (FTD) Web Service Read-Only Directory Traversal
CVE-2020-3452HIGHunder attack13 Aug 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC1
Vbulletin RCE Exploit
CVE-2019-16759CRITICALunder attack13 Aug 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
GitHub PoC15
CVE-2019-0230 Exploit POC
CVE-2019-023013 Aug 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISK
open
previouspage 390 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.