Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,057 exploits
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack27 Oct 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
GitHub PoC14
PoC for old Binder vulnerability (based on P0 exploit)
CVE-2019-2215HIGHunder attack27 Oct 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
Exploit-DB
Sentrifugo 3.2 - File Upload Restriction Bypass (Authenticated)
CVE-2019-15813webappsphp27 Oct 2020
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arb
35RISK
open
GitHub PoC
datntsec/CVE-2019-12735
CVE-2019-1273526 Oct 2020
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RISK
open
Exploit-DB
CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Injection
CVE-2017-16783webappsphp26 Oct 2020
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
23RISK
open
Metasploit600
Pulse Secure VPN gzip RCE
CVE-2020-8260HIGHunder attack26 Oct 2020
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform
100RISK
open
GitHub PoC8
POC For CVE-2020-1481 - Jira Username Enumerator/Validator
CVE-2020-1418126 Oct 2020
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
60RISK
open
GitHub PoC2
Python exploit for CVE-2012-2982
CVE-2012-298225 Oct 2020
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHunder attackransomware23 Oct 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
Exploit-DBVexDay Proof
Bludit 3.9.2 - Auth Bruteforce Bypass
CVE-2019-17240LOWwebappsphp23 Oct 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
GitHub PoC11
CVE-2020-0688 PoC
CVE-2020-0688HIGHunder attackransomware23 Oct 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC1
PoC for apache struts 2 vuln cve-2019-0230
CVE-2019-023022 Oct 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISK
open
GitHub PoC2
Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass Exploit/PoC
CVE-2019-17240LOW21 Oct 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
GitHub PoC
HYWZ36/CVE-2020-14645-code
CVE-2020-14645CRITICAL21 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISK
open
GitHub PoC
Elsfa7-110/CVE-2019-1579
CVE-2019-1579HIGHunder attackransomware21 Oct 2020
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RISK
open
GitHub PoC
puckiestyle/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware21 Oct 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
Metasploit300
WordPress Loginizer log SQLi Scanner
CVE-2020-2761521 Oct 2020
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_fa
30RISK
open
VulnCheck XDB
infoleak
CVE-2019-1579HIGHunder attackransomware21 Oct 2020
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware21 Oct 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC2
cve-2020-14644 漏洞环境
CVE-2020-14644CRITICALunder attack20 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
Metasploit600
Nagios XI 5.6.0-5.7.3 - Mibs.php Authenticated Remote Code Exection
CVE-2020-579120 Oct 2020
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RISK
open
Metasploit600
NSClient++ 0.5.2.35 - Privilege escalation
CVE-2025-34078HIGH20 Oct 2020
NSClient++ 0.5.2.35 Local Privilege Escalation via ExternalScripts and Web Interface
36RISK
open
Metasploit600
Oracle WebLogic Server Administration Console Handle RCE
CVE-2020-14882CRITICALunder attack20 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Metasploit600
NSClient++ 0.5.2.35 - ExternalScripts Authenticated Remote Code Execution
CVE-2025-34079HIGH20 Oct 2020
NSClient++ Authenticated Remote Code Execution via ExternalScripts API
36RISK
open
Metasploit600
Oracle WebLogic Server Administration Console Handle RCE
CVE-2020-14883HIGHunder attack20 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Metasploit600
Oracle WebLogic Server Administration Console Handle RCE
CVE-2020-14750CRITICALunder attack20 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Metasploit300
Oracle Solaris SunSSH PAM parse_user_name() Buffer Overflow
CVE-2020-14871CRITICALunder attack20 Oct 2020
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISK
open
Metasploit600
Nagios XI 5.5.0-5.7.3 - Snmptrap Authenticated Remote Code Exection
CVE-2020-579220 Oct 2020
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user
30RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware19 Oct 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
Exploit-DB
HiSilicon Video Encoders - RCE via unauthenticated command injection
CVE-2020-24217webappshardware19 Oct 2020
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpo
35RISK
open
previouspage 744 / 2,636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.