Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,057 exploits
VulnCheck XDB
local
CVE-2015-2546HIGHunder attackransomware09 Aug 2020
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
76RISK
open
VulnCheck XDB
local
CVE-2016-0099HIGHunder attackransomware09 Aug 2020
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open
GitHub PoC12
Automated F5 Big IP Remote Code Execution (CVE-2020-5902) Scanner Written In Python 3
CVE-2020-5902CRITICALunder attackransomware09 Aug 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-0143HIGHunder attackransomware09 Aug 2020
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
VulnCheck XDB
local
CVE-2020-0683HIGHunder attack09 Aug 2020
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RISK
open
VulnCheck XDB
local
CVE-2019-0808HIGHunder attack09 Aug 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack09 Aug 2020
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2015-237009 Aug 2020
The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP
23RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware09 Aug 2020
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2020-1054HIGHunder attack09 Aug 2020
Win32k Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2017-0213HIGHunder attackransomware09 Aug 2020
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISK
open
VulnCheck XDB
local
CVE-2015-000309 Aug 2020
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
23RISK
open
VulnCheck XDB
local
CVE-2021-33739HIGHunder attack09 Aug 2020
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
local
CVE-2016-7255HIGHunder attack09 Aug 2020
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISK
open
VulnCheck XDB
local
CVE-2016-322509 Aug 2020
The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
50RISK
open
VulnCheck XDB
local
CVE-2019-062309 Aug 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
23RISK
open
VulnCheck XDB
local
CVE-2014-4113HIGHunder attack09 Aug 2020
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISK
open
VulnCheck XDB
local
CVE-2018-8639HIGHunder attackransomware09 Aug 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RISK
open
VulnCheck XDB
local
CVE-2020-0787HIGHunder attackransomware09 Aug 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISK
open
VulnCheck XDB
local
CVE-2015-1701HIGHunder attackransomware09 Aug 2020
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RISK
open
VulnCheck XDB
infoleak
CVE-2020-5902CRITICALunder attackransomware09 Aug 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
VulnCheck XDB
local
CVE-2011-2005HIGHunder attack09 Aug 2020
afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly valid
98RISK
open
Metasploit600
vBulletin 5.x /ajax/render/widget_tabbedcontainer_tab_panel PHP remote code execution.
CVE-2020-17496CRITICALunder attack09 Aug 2020
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe
100RISK
open
GitHub PoC3
CVE-2016-2555
CVE-2016-255509 Aug 2020
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISK
open
VulnCheck XDB
local
CVE-2018-8453HIGHunder attackransomware09 Aug 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
VulnCheck XDB
local
CVE-2015-2387HIGHunder attack09 Aug 2020
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server
83RISK
open
Metasploit600
Artica proxy 4.30.000000 Auth Bypass service-cmds-peform Command Injection
CVE-2020-1750509 Aug 2020
Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter i
40RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware09 Aug 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
local
CVE-2010-333809 Aug 2020
The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7
43RISK
open
VulnCheck XDB
local
CVE-2019-0803HIGHunder attackransomware09 Aug 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
83RISK
open
previouspage 755 / 2,636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.