Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
79,039 exploits
GitHub PoC
https://github.com/awakened1712/CVE-2019-11932://github.com/awakened1712/CVE-2019-11932
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open ↗VulnCheck XDB
local
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗Metasploit600
Nagios XI Prior to 5.8.0 - Plugins Filename Authenticated Remote Code Exection
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RISK
open ↗Exploit-DB
FRITZ!Box 7.20 - DNS Rebinding Protection Bypass
FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism.
23RISK
open ↗VulnCheck XDB
client-side
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISK
open ↗GitHub PoC★ 2
edxsh/CVE-2019-0752
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISK
open ↗GitHub PoC
(cve-2020-17530) struts2_s2-061 freemarker_RCE testscript
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open ↗VulnCheck XDB
initial-access
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open ↗GitHub PoC
cve-2019-0708 vulnerablility scanner
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open ↗Exploit-DB
Nxlog Community Edition 2.10.2150 - DoS (Poc)
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of
23RISK
open ↗Exploit-DB
Cisco ASA 9.14.1.10 and FTD 6.6.0.1 - Path Traversal (2)
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open ↗Exploit-DB
Solaris SunSSH 11.0 x86 - libpam Remote Root
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISK
open ↗Metasploit600
HPE Systems Insight Manager AMF Deserialization RCE
A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerabili
40RISK
open ↗GitHub PoC★ 1
GuillaumePetit84/CVE-2020-35488
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of
23RISK
open ↗GitHub PoC
Apache Solr 1.4 Injection to get a shell
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RISK
open ↗Exploit-DB
Jenkins 2.235.3 - 'X-Forwarded-For' Stored XSS
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via '
23RISK
open ↗GitHub PoC★ 7
CVE-2020-17530-strust2-061
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open ↗Exploit-DB
GitLab 11.4.7 - Remote Code Execution (Authenticated) (1)
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection
28RISK
open ↗Exploit-DB
GitLab 11.4.7 - Remote Code Execution (Authenticated) (1)
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RISK
open ↗GitHub PoC★ 9
Fortinet FortiOS路径遍历漏洞 (CVE-2018-13379)批量检测脚本
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open ↗VulnCheck XDB
initial-access
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open ↗VulnCheck XDB
initial-access
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open ↗VulnCheck XDB
initial-access
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open ↗VulnCheck XDB
infoleak
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open ↗GitHub PoC★ 29
S2-061 CVE-2020-17530
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open ↗VulnCheck XDB
infoleak
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open ↗GitHub PoC★ 2
CVE-2014-0160 OpenSSL Heartbleed Proof of Concept
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open ↗GitHub PoC★ 26
cygenta/CVE-2020-3452
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open ↗Metasploit300
WordPress Total Upkeep Unauthenticated Backup Downloader
Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download
36RISK
open ↗Metasploit600
TerraMaster TOS 4.2.06 or lower - Unauthenticated Remote Code Execution
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inje
40RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.