Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,107 exploits
GitHub PoC3
Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API.
CVE-2019-11510CRITICALunder attackransomware27 Jul 2020
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open
Exploit-DB
ManageEngine Applications Manager 13 - 'MenuHandlerServlet' SQL Injection
CVE-2016-9488webappsjava26 Jul 2020
ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities
23RISK
open
GitHub PoC2
A registry-based workaround can be used to help protect an affected Windows server, and it can be implemented without requiring an administrator to restart the server. Because of the volatility of this vulnerability, administrators may have to implement the workaround before they apply the security update in order to enable them to update their systems by using a standard deployment cadence.
CVE-2020-1350CRITICALunder attack26 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
Exploit-DB
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - 'hash' SQL Injection (Unauthenticated)
CVE-2019-20361HIGHwebappsphp26 Jul 2020
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b
78RISK
open
Exploit-DB
Bio Star 2.8.2 - Local File Inclusion
CVE-2020-15050webappsmultiple26 Jul 2020
An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary fi
50RISK
open
Exploit-DB
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - Unauthenticated File Download
CVE-2019-19985MEDIUMwebappsphp26 Jul 2020
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file downloa
70RISK
open
Exploit-DB
F5 Big-IP 13.1.3 Build 0.0.6 - Local File Inclusion
CVE-2020-5902CRITICALunder attackransomwarewebappshardware26 Jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
Exploit-DB
Bludit 3.9.2 - Directory Traversal
CVE-2019-16113webappsmultiple26 Jul 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISK
open
Exploit-DB
pfSense 2.4.4-p3 - Cross-Site Request Forgery
CVE-2019-16667webappsphp26 Jul 2020
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executi
35RISK
open
Exploit-DB
Rails 5.0.1 - Remote Code Execution
CVE-2020-8163webappsruby26 Jul 2020
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RISK
open
Exploit-DB
INNEO Startup TOOLS 2018 M040 13.0.70.3804 - Remote Code Execution
CVE-2020-15492webappsmultiple26 Jul 2020
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe we
28RISK
open
VulnCheck XDB
initial-access
CVE-2020-3452HIGHunder attack25 Jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC20
KaLendsi/CVE-2020-1054
CVE-2020-1054HIGHunder attack25 Jul 2020
Win32k Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC
没有编写完成,以后学习更多知识在回来完善
CVE-2015-856225 Jul 2020
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISK
open
VulnCheck XDB
local
CVE-2020-1054HIGHunder attack25 Jul 2020
Win32k Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2015-856225 Jul 2020
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISK
open
GitHub PoC3
Little, stupid python validator(?) for CVE-2020-3452 on CISCO devices.
CVE-2020-3452HIGHunder attack25 Jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC2
XDev05/CVE-2020-3452-PoC
CVE-2020-3452HIGHunder attack24 Jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
Metasploit600
Mida Solutions eFramework ajaxreq.php Command Injection
CVE-2020-1592024 Jul 2020
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Executi
60RISK
open
GitHub PoC2
unauth file read in cisco asa & firepower.
CVE-2020-3452HIGHunder attack24 Jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC25
CVE-2020-3452 Cisco ASA Scanner -unauth Path Traversal Check
CVE-2020-3452HIGHunder attack24 Jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC
mr-r3b00t/CVE-2020-3452
CVE-2020-3452HIGHunder attack24 Jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-3452HIGHunder attack24 Jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-3452HIGHunder attack24 Jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2017-11826HIGHunder attack23 Jul 2020
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Serv
93RISK
open
VulnCheck XDB
client-side
CVE-2017-8759HIGHunder attack23 Jul 2020
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
VulnCheck XDB
initial-access
CVE-2020-2555CRITICALunder attack22 Jul 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
Exploit-DB
Docsify.js 4.11.4 - Reflective Cross-Site Scripting
CVE-2020-7680webappsmultiple22 Jul 2020
docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters a
23RISK
open
GitHub PoC
A powershell script to deploy the registry mitigation key for CVE-2020-1350
CVE-2020-1350CRITICALunder attack22 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
Exploit-DB
WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection
CVE-2020-15363webappsphp22 Jul 2020
The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.
23RISK
open
previouspage 759 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.