Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,057 exploits
GitHub PoC13
Exploiting CVE-2014-3153, AKA Towelroot.
CVE-2014-3153HIGHunder attack31 Oct 2020
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
Exploit-DB
DedeCMS v.5.8 - _keyword_ Cross-Site Scripting
CVE-2020-27533webappsphp30 Oct 2020
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to
23RISK
open
GitHub PoC
alexfrancow/CVE-2020-14882
CVE-2020-14882CRITICALunder attack30 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack30 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC1
CuteNews Avatar 2.1.2 Remote Code Execution Vulnerability
CVE-2019-1144730 Oct 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-1144730 Oct 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack29 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack29 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack29 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Metasploit600
Rapid7 Metasploit Framework msfvenom APK Template Command Injection
CVE-2020-7384HIGH29 Oct 2020
Client-Side Command Injection in Rapid7 Metasploit
68RISK
open
GitHub PoC
Un semplice exploit che sfrutta CVE-2015-7297, CVE-2015-7857 and CVE-2015-7858 per elencare gli utenti con la psw del db
CVE-2015-729729 Oct 2020
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISK
open
GitHub PoC2
Scans for Microsoft Exchange Versions with masscan
CVE-2020-0688HIGHunder attackransomware29 Oct 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC17
CVE-2020-14882 Weblogic-Exp
CVE-2020-14882CRITICALunder attack29 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2015-785829 Oct 2020
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISK
open
GitHub PoC7
CVE-2020-14882 EXP 回显
CVE-2020-14882CRITICALunder attack29 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC2
Bash script to exploit the Oracle's Weblogic Unauthenticated Remote Command Execution - CVE-2020-14882
CVE-2020-14882CRITICALunder attack29 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Exploit-DB
Nagios XI 5.7.3 - 'mibs.php' Remote Command Injection (Authenticated)
CVE-2020-5791webappsphp28 Oct 2020
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RISK
open
Metasploit600
Micro Focus Operations Bridge Manager / Reporter Local Privilege Escalation
CVE-2020-1185528 Oct 2020
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The
18RISK
open
Metasploit600
Micro Focus Operations Bridge Manager / Reporter Local Privilege Escalation
CVE-2020-11858HIGH28 Oct 2020
Code execution with escalated privilegesn vlnerability in Operation bridge Manager and Operations Bridge (containerized) products.
36RISK
open
Metasploit600
Micro Focus UCMDB Java Deserialization Unauthenticated Remote Code Execution
CVE-2020-11854CRITICAL28 Oct 2020
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products.
85RISK
open
Metasploit600
Micro Focus UCMDB Java Deserialization Unauthenticated Remote Code Execution
CVE-2020-11853HIGH28 Oct 2020
Arbitrary code execution vulnerability on multiple Micro Focus products
58RISK
open
Exploit-DB
Blueman < 2.1.4 - Local Privilege Escalation
CVE-2020-15238HIGHlocallinux28 Oct 2020
Local privilege escalation Blueman
41RISK
open
Metasploit600
Micro Focus Operations Bridge Manager Authenticated Remote Code Execution
CVE-2020-11853HIGH28 Oct 2020
Arbitrary code execution vulnerability on multiple Micro Focus products
58RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack28 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack28 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Exploit-DB
Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewImage' Directory Traversal/Local File Inclusion
CVE-2020-14864HIGHunder attackwebappslinux28 Oct 2020
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ins
100RISK
open
VulnCheck XDB
local
CVE-2020-1054HIGHunder attack28 Oct 2020
Win32k Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC287
CVE-2020–14882、CVE-2020–14883
CVE-2020-14882CRITICALunder attack28 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC29
CVE-2020–14882 by Jang
CVE-2020-14882CRITICALunder attack28 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
Windows 7 LPE
CVE-2020-1054HIGHunder attack28 Oct 2020
Win32k Elevation of Privilege Vulnerability
98RISK
open
previouspage 743 / 2,636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.