Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,057 exploits
Exploit-DB
HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow (DoS)
CVE-2020-24214webappshardware19 Oct 2020
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a
35RISK
open
Exploit-DB
HiSilicon Video Encoders - Full admin access via backdoor password
CVE-2020-24215webappshardware19 Oct 2020
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use har
28RISK
open
Exploit-DB
Hostel Management System 2.1 - Cross Site Scripting (Multiple Fields)
CVE-2020-25270webappsphp19 Oct 2020
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, o
23RISK
open
Exploit-DB
Typesetter CMS 5.1 - Arbitrary Code Execution (Authenticated)
CVE-2020-25790webappsphp19 Oct 2020
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archi
28RISK
open
GitHub PoC7
ThinkAdmin CVE-2020-25540 poc
CVE-2020-2554019 Oct 2020
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISK
open
Exploit-DB
HiSilicon Video Encoders - Unauthenticated file disclosure via path traversal
CVE-2020-24219webappshardware19 Oct 2020
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthentic
28RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware19 Oct 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
Exploit-DB
HiSilicon video encoders - RCE via unauthenticated upload of malicious firmware
CVE-2020-24217webappshardware19 Oct 2020
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpo
35RISK
open
Exploit-DB
Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in
CVE-2019-1003030CRITICALunder attackwebappsjava19 Oct 2020
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISK
open
GitHub PoC
Exploitable target to CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware19 Oct 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
datntsec/CVE-2019-13272
CVE-2019-13272HIGHunder attack19 Oct 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC
Exploits CuteNews 2.1.2 via poor file upload checks used when uploading an avatar image leading to RCE.
CVE-2019-1144718 Oct 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-1144718 Oct 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
GitHub PoC
stealth-ronin/CVE-2017-0199-PY-KIT
CVE-2017-0199HIGHunder attackransomware18 Oct 2020
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-1472MEDIUMunder attackransomware17 Oct 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALunder attack17 Oct 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
GitHub PoC5
C# Vulnerability Checker for CVE-2020-1472 Aka Zerologon
CVE-2020-1472MEDIUMunder attackransomware17 Oct 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
Converted with tweaks from a metasploit module as an exercise for OSCP studying and exploit development
CVE-2015-330616 Oct 2020
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALunder attack16 Oct 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
Exploit-DB
Seat Reservation System 1.0 - Unauthenticated SQL Injection
CVE-2020-25762webappsphp16 Oct 2020
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v
28RISK
open
VulnCheck XDB
infoleak
CVE-2015-1635CRITICALunder attack16 Oct 2020
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
GitHub PoC
Check for events that indicate non compatible devices -> CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware15 Oct 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC3
CVE-2019–15107 - Unauthenticated RCE Webmin <=1.920
CVE-2019-15107CRITICALunder attackransomware15 Oct 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware15 Oct 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-3452HIGHunder attack14 Oct 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC2
FancyDoesSecurity/CVE-2020-2883
CVE-2020-2883CRITICALunder attack14 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-5902CRITICALunder attackransomware14 Oct 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-2883CRITICALunder attack14 Oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
Metasploit600
Microsoft SharePoint Server-Side Include and ViewState RCE
CVE-2020-16952HIGH13 Oct 2020
Microsoft SharePoint Remote Code Execution Vulnerability
58RISK
open
Exploit-DB
Cisco ASA and FTD 9.6.4.42 - Path Traversal
CVE-2020-3452HIGHunder attackwebappshardware12 Oct 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
previouspage 745 / 2,636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.