Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,107 exploits
VulnCheck XDB
initial-access
CVE-2020-6287CRITICALunder attack15 Jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open
GitHub PoC225
PoC for CVE-2020-6287, CVE-2020-6286 (SAP RECON vulnerability)
CVE-2020-6287CRITICALunder attack15 Jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open
GitHub PoC2
ctlyz123/CVE-2020-8193
CVE-2020-8193MEDIUMunder attack15 Jul 2020
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISK
open
GitHub PoC237
A denial-of-service proof-of-concept for CVE-2020-1350
CVE-2020-1350CRITICALunder attack15 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
GitHub PoC
Windows registry mitigation response to CVE-2020-1350
CVE-2020-1350CRITICALunder attack15 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
GitHub PoC9
Detection of attempts to exploit Microsoft Windows DNS server via CVE-2020-1350 (AKA SIGRed)
CVE-2020-1350CRITICALunder attack15 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
GitHub PoC15
This Powershell Script is checking if your server is vulnerable for the CVE-2020-1350 Remote Code Execution flaw in the Windows DNS Service
CVE-2020-1350CRITICALunder attack15 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
Exploit-DB
Zyxel Armor X1 WAP6806 - Directory Traversal
CVE-2020-14461webappshardware15 Jul 2020
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
23RISK
open
Exploit-DB
BSA Radar 1.6.7234.24750 - Local File Inclusion
CVE-2020-14946webappsmultiple14 Jul 2020
downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and e
23RISK
open
GitHub PoC4
mr-r3b00t/CVE-2020-1350
CVE-2020-1350CRITICALunder attack14 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
GitHub PoC7
Fake exploit tool, designed to rickroll users attempting to actually exploit.
CVE-2020-1350CRITICALunder attack14 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
Exploit-DB
Trend Micro Web Security Virtual Appliance 6.5 SP2 Patch 4 Build 1901 - Remote Code Execution (Metasploit)
CVE-2020-8605webappsmultiple14 Jul 2020
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitr
60RISK
open
GitHub PoC279
HoneyPoC: Proof-of-Concept (PoC) script to exploit SIGRed (CVE-2020-1350). Achieves Domain Admin on Domain Controllers running Windows Server 2000 up to Windows Server 2019.
CVE-2020-1350CRITICALunder attack14 Jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
Metasploit600
SharePoint DataSet / DataTable Deserialization
CVE-2020-1147HIGHunder attack14 Jul 2020
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
100RISK
open
Metasploit600
Apache Airflow 1.10.10 - Example DAG Remote Code Execution
CVE-2020-13927CRITICALunder attack14 Jul 2020
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th
100RISK
open
Metasploit300
SAP Unauthenticated WebService User Creation
CVE-2020-6287CRITICALunder attack14 Jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open
Metasploit600
Apache Airflow 1.10.10 - Example DAG Remote Code Execution
CVE-2020-11978HIGHunder attack14 Jul 2020
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was disco
100RISK
open
Metasploit600
Apache OFBiz XML-RPC Java Deserialization
CVE-2023-5146713 Jul 2020
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RISK
open
Metasploit600
Apache OFBiz XML-RPC Java Deserialization
CVE-2020-949613 Jul 2020
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
GitHub PoC3
TeamViewer Store Credentials Decryption
CVE-2019-18988HIGHunder attack13 Jul 2020
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for dif
86RISK
open
Metasploit600
Apache OFBiz XML-RPC Java Deserialization
CVE-2023-4907013 Jul 2020
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RISK
open
GitHub PoC8
Scanning for CVE-2020-8193 - Auth Bypass check
CVE-2020-8193MEDIUMunder attack13 Jul 2020
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-8193MEDIUMunder attack13 Jul 2020
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-11043HIGHunder attackransomware13 Jul 2020
Underflow in PHP-FPM can lead to RCE
100RISK
open
VulnCheck XDB
local
CVE-2019-18988HIGHunder attack13 Jul 2020
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for dif
86RISK
open
GitHub PoC
quick and dirty PHP RCE proof of concept
CVE-2019-11043HIGHunder attackransomware13 Jul 2020
Underflow in PHP-FPM can lead to RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-8193MEDIUMunder attack12 Jul 2020
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-8193MEDIUMunder attack12 Jul 2020
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISK
open
GitHub PoC
momika233/cve-2020-5902
CVE-2020-5902CRITICALunder attackransomware12 Jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
GitHub PoC
freeFV/CVE-2020-5902-fofa-scan
CVE-2020-5902CRITICALunder attackransomware12 Jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
previouspage 761 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.