Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
78,958 exploits
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack18 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-133518 Jan 2021
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
VulnCheck XDB
client-side
CVE-2020-0601HIGHunder attack17 Jan 2021
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC
okanulkr/CurveBall-CVE-2020-0601-PoC
CVE-2020-0601HIGHunder attack17 Jan 2021
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC
1nteger-c/CVE-2019-8605
CVE-2019-8605HIGHunder attack15 Jan 2021
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RISK
open
GitHub PoC
Rust implementation of CVE-2018-16763 with some extra features.
CVE-2018-1676315 Jan 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
Metasploit600
Lucee Administrator imgProcess.cfm Arbitrary File Write
CVE-2021-21307HIGH15 Jan 2021
Remote Code Exploit in Lucee Admin
78RISK
open
VulnCheck XDB
local
CVE-2019-8605HIGHunder attack15 Jan 2021
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RISK
open
VulnCheck XDB
initial-access
CVE-2021-21307HIGH15 Jan 2021
Remote Code Exploit in Lucee Admin
78RISK
open
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALunder attack14 Jan 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack14 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
GitHub PoC18
Exploit script for CVE-2020-7961
CVE-2020-7961CRITICALunder attack14 Jan 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-6207CRITICALunder attack14 Jan 2021
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RISK
open
GitHub PoC82
PoC for CVE-2020-6207 (Missing Authentication Check in SAP Solution Manager)
CVE-2020-6207CRITICALunder attack14 Jan 2021
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RISK
open
GitHub PoC
CVE-2020-17519 EXP
CVE-2020-17519CRITICALunder attack14 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
Exploit-DB
Nagios XI 5.7.X - Remote Code Execution RCE (Authenticated)
CVE-2020-35578webappsphp14 Jan 2021
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RISK
open
Exploit-DB
Laravel 8.4.2 debug mode - Remote code execution
CVE-2021-3129CRITICALunder attackransomwarewebappsphp14 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC289
Exploit for CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware13 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
Metasploit600
Unauthenticated remote code execution in Ignition
CVE-2021-3129CRITICALunder attackransomware13 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
Starry-lord/CVE-2018-0114
CVE-2018-011413 Jan 2021
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
GitHub PoC1
CVE-2017-12615 任意文件写入exp,写入webshell
CVE-2017-12615HIGHunder attackransomware12 Jan 2021
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
Metasploit600
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
CVE-2020-16875HIGH12 Jan 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
48RISK
open
Metasploit600
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
CVE-2020-17132CRITICAL12 Jan 2021
Microsoft Exchange Remote Code Execution Vulnerability
65RISK
open
VulnCheck XDB
initial-access
CVE-2017-12615HIGHunder attackransomware12 Jan 2021
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware11 Jan 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
AnasTaoutaou/CVE-2019-5420
CVE-2019-542011 Jan 2021
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
GitHub PoC8
[CVE-2020-17519] Apache Flink RESTful API Arbitrary File Read
CVE-2020-17519CRITICALunder attack10 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1751810 Jan 2021
Apache Flink directory traversal attack: remote file writing through the REST API
50RISK
open
VulnCheck XDB
initial-access
CVE-2020-1751810 Jan 2021
Apache Flink directory traversal attack: remote file writing through the REST API
50RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack10 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
previouspage 730 / 2,632next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.