Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
79,057 exploits
GitHub PoC
ActorExpose/CVE-2017-11882
CVE-2017-11882HIGHunder attackransomware03 Dec 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC1
Scan through given ip list
CVE-2019-0708CRITICALunder attackransomware03 Dec 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DB
WonderCMS 3.1.3 - Authenticated Remote Code Execution
CVE-2020-35314webappsphp02 Dec 2020
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, al
28RISK
open
Exploit-DB
WonderCMS 3.1.3 - Authenticated SSRF to Remote Remote Code Execution
CVE-2020-35313webappsphp02 Dec 2020
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in Wonder
35RISK
open
Exploit-DB
Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile
CVE-2020-28687webappsmultiple02 Dec 2020
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upl
28RISK
open
Exploit-DB
Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality
CVE-2020-27423webappsphp02 Dec 2020
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial o
23RISK
open
Exploit-DB
Anuko Time Tracker 1.19.23.5311 - Password Reset leading to Account Takeover
CVE-2020-27422webappsphp02 Dec 2020
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an a
23RISK
open
Exploit-DB
Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Add Artwork
CVE-2020-28688webappsmultiple02 Dec 2020
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to uplo
28RISK
open
Metasploit300
KOFFEE - Kia OFFensivE Exploit
CVE-2020-853902 Dec 2020
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an atta
18RISK
open
Exploit-DB
WordPress Plugin Wp-FileManager 6.8 - RCE
CVE-2020-25213CRITICALunder attackwebappsphp02 Dec 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
Exploit-DB
PRTG Network Monitor 20.4.63.1412 - 'maps' Stored XSS
CVE-2020-14073webappswindows02 Dec 2020
XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can c
23RISK
open
Exploit-DB
Joomla! Component GMapFP 3.5 - Unauthenticated Arbitrary File Upload
CVE-2020-23972webappsphp01 Dec 2020
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating
50RISK
open
GitHub PoC49
Python / scapy module implementing SRVLOC/SLP protocol and scans for enabled OpenSLP services.
CVE-2019-5544CRITICALunder attackransomware01 Dec 2020
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of
100RISK
open
GitHub PoC49
Python / scapy module implementing SRVLOC/SLP protocol and scans for enabled OpenSLP services.
CVE-2020-3992CRITICALunder attackransomware01 Dec 2020
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-
100RISK
open
Exploit-DB
Wordpress Plugin EventON Calendar 3.0.5 - Reflected Cross-Site Scripting
CVE-2020-29395webappsphp01 Dec 2020
The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.
43RISK
open
VulnCheck XDB
infoleak
CVE-2020-3992CRITICALunder attackransomware01 Dec 2020
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-
100RISK
open
VulnCheck XDB
local
CVE-2020-27950MEDIUMunder attack01 Dec 2020
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RISK
open
GitHub PoC34
CVE-2020-27950 exploit
CVE-2020-27950MEDIUMunder attack01 Dec 2020
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RISK
open
VulnCheck XDB
infoleak
CVE-2019-5544CRITICALunder attackransomware01 Dec 2020
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of
100RISK
open
VulnCheck XDB
local
CVE-2015-363601 Dec 2020
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RISK
open
GitHub PoC
wikiZ/cve-2018-8120
CVE-2018-8120HIGHunder attackransomware30 Nov 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-11652MEDIUMunder attack30 Nov 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
Exploit-DB
Rejetto HttpFileServer 2.3.x - Remote Command Execution (3)
CVE-2014-6287CRITICALunder attackwebappswindows30 Nov 2020
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-13379CRITICALunder attackransomware30 Nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
GitHub PoC9
This module massively scan and exploit a path traversal vulnerability in the FortiOS SSL VPN web portal may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests (CVE-2018-13379).
CVE-2018-13379CRITICALunder attackransomware30 Nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALunder attack30 Nov 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
GitHub PoC1
Scanning tool to test for SaltStack vulnerabilities CVE-2020-11651 & CVE-2020-11652.
CVE-2020-11651CRITICALunder attack30 Nov 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
GitHub PoC1
wikiZ/cve-2014-4113
CVE-2014-4113HIGHunder attack30 Nov 2020
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISK
open
GitHub PoC
Vbulletin RCE Exploits
CVE-2019-16759CRITICALunder attack29 Nov 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
GitHub PoC42
OpenSSH 2.3 < 7.7 - Username Enumeration
CVE-2018-15473MEDIUM29 Nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
previouspage 737 / 2,636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.