Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
78,958 exploits
VulnCheck XDB
initial-access
CVE-2020-11652MEDIUMunder attack25 Dec 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
GitHub PoC
wood03mm/CVE-2016-3088
CVE-2016-3088CRITICALunder attack24 Dec 2020
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2016-3088CRITICALunder attack24 Dec 2020
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC
Insecure Folder permission that lead to privilege escalation
CVE-2020-2816924 Dec 2020
The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory
23RISK
open
Exploit-DB
GitLab 11.4.7 - RCE (Authenticated) (2)
CVE-2018-19585webappsruby24 Dec 2020
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection
28RISK
open
GitHub PoC7
Weblogic Server CVE-2020-14645 EXP for Python (complete in one step)
CVE-2020-14645CRITICAL24 Dec 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISK
open
Exploit-DB
GitLab 11.4.7 - RCE (Authenticated) (2)
CVE-2018-19571webappsruby24 Dec 2020
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RISK
open
GitHub PoC
Webmin Exploit Scanner CVE-2020-35606 CVE-2019-12840
CVE-2020-3560623 Dec 2020
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can ex
28RISK
open
GitHub PoC
SaharAttackit/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware23 Dec 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware23 Dec 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
Webmin Exploit Scanner CVE-2020-35606 CVE-2019-12840
CVE-2019-1284023 Dec 2020
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISK
open
GitHub PoC4
Supervisord远程命令执行漏洞脚本
CVE-2017-1161022 Dec 2020
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2017-1161022 Dec 2020
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-1394222 Dec 2020
Remote Code Execution in Apache Unomi
50RISK
open
Exploit-DB
Spiceworks 7.5 - HTTP Header Injection
CVE-2020-25901webappswindows21 Dec 2020
Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious we
23RISK
open
Exploit-DB
SCO Openserver 5.0.7 - 'section' Reflected XSS
CVE-2020-25495webappssco21 Dec 2020
A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote at
38RISK
open
VulnCheck XDB
initial-access
CVE-2018-15133HIGHunder attack21 Dec 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'To OLAP' Reflected XSS
CVE-2020-20141webappsmultiple21 Dec 2020
Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Tab
23RISK
open
Exploit-DB
SCO Openserver 5.0.7 - 'outputform' Command Injection
CVE-2020-25494webappssco21 Dec 2020
Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in ou
35RISK
open
GitHub PoC35
Laravel RCE exploit. CVE-2018-15133
CVE-2018-15133HIGHunder attack21 Dec 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'Remote Report' Reflected XSS
CVE-2020-20140webappsmultiple21 Dec 2020
Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Cha
23RISK
open
Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'Remote JSON' Reflected XSS
CVE-2020-20139webappsmultiple21 Dec 2020
Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table
23RISK
open
Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'To remote CSV' Reflected XSS
CVE-2020-20142webappsmultiple21 Dec 2020
Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table &
23RISK
open
GitHub PoC1
POC for CVE-2018-0114 written in Go
CVE-2018-011420 Dec 2020
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
GitHub PoC2
DirtyCOW Exploit for Android
CVE-2016-5195HIGHunder attack20 Dec 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
local
CVE-2020-0787HIGHunder attackransomware20 Dec 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISK
open
GitHub PoC
https://github.com/awakened1712/CVE-2019-11932://github.com/awakened1712/CVE-2019-11932
CVE-2019-1193220 Dec 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack20 Dec 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC2
Collection of PoCs created for SmarterMail < Build 6985 RCE
CVE-2019-721420 Dec 2020
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RISK
open
Metasploit600
Nagios XI Prior to 5.8.0 - Plugins Filename Authenticated Remote Code Exection
CVE-2020-3557819 Dec 2020
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RISK
open
previouspage 733 / 2,632next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.