Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,107 exploits
GitHub PoC
修改IP地址即可实现命令执行
CVE-2017-804601 Aug 2020
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISK
open
GitHub PoC42
POC for CVE-2020-13151
CVE-2020-1315101 Aug 2020
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RISK
open
GitHub PoC24
CVE-2020-3452 exploit
CVE-2020-3452HIGHunder attack01 Aug 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-8174HIGHunder attackransomware31 Jul 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
Metasploit500
Aerospike Database UDF Lua Code Execution
CVE-2020-1315131 Jul 2020
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RISK
open
VulnCheck XDB
initial-access
CVE-2016-3088CRITICALunder attack31 Jul 2020
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC
ericisnotrealname/CVE-2018-8174_EXP
CVE-2018-8174HIGHunder attackransomware31 Jul 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
GitHub PoC15
ActiveMQ_putshell直接获取webshell
CVE-2016-3088CRITICALunder attack31 Jul 2020
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC1
Simple detection tool for Blueborne vulnerability found on Android devices --- CVE-2017-0781.
CVE-2017-078130 Jul 2020
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISK
open
GitHub PoC7
Shitrix : CVE-2019-19781 - Remote Code Execution on Citrix ADC Netscaler exploit
CVE-2019-19781CRITICALunder attackransomware30 Jul 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-19781CRITICALunder attackransomware30 Jul 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
Exploit-DB
Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site Scripting
CVE-2020-15038webappsphp29 Jul 2020
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
23RISK
open
VulnCheck XDB
local
CVE-2020-1071329 Jul 2020
A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB veri
23RISK
open
GitHub PoC
CVE-2020-3452 : Cisco ASA and FTD Unauthorized Remote File Reading Nmap NSE Script
CVE-2020-3452HIGHunder attack29 Jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
Exploit-DB
Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
CVE-2020-3187CRITICALwebappshardware29 Jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISK
open
GitHub PoC4
A network detection package for CVE-2020-5902, a CVE10.0 vulnerability affecting F5 Networks, Inc BIG-IP devices.
CVE-2020-5902CRITICALunder attackransomware28 Jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-289328 Jul 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
60RISK
open
Exploit-DB
Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion
CVE-2020-3452HIGHunder attackwebappshardware28 Jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-3452HIGHunder attack28 Jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC1
环境下载
CVE-2020-14645CRITICAL28 Jul 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISK
open
GitHub PoC
Better version of rastating.github.io/bludit-brute-force-mitigation-bypass/
CVE-2019-17240LOW28 Jul 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
GitHub PoC1
CrackerCat/CVE-2020-3187
CVE-2020-3187CRITICAL28 Jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISK
open
GitHub PoC2
This exploit is remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data
CVE-2016-209827 Jul 2020
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISK
open
GitHub PoC2
Citrix ADC scanner (CVE-2019-19781) using hosts retrieved from Shodan API.
CVE-2019-19781CRITICALunder attackransomware27 Jul 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-061027 Jul 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
35RISK
open
GitHub PoC3
Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API.
CVE-2019-11510CRITICALunder attackransomware27 Jul 2020
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALunder attackransomware27 Jul 2020
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
VulnCheck XDB
local
CVE-2020-9934MEDIUMunder attack27 Jul 2020
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue
78RISK
open
VulnCheck XDB
initial-access
CVE-2019-11510CRITICALunder attackransomware27 Jul 2020
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open
GitHub PoC24
CVE-2020–9934 POC
CVE-2020-9934MEDIUMunder attack27 Jul 2020
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue
78RISK
open
previouspage 758 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.