Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,107 exploits
Metasploit600
Inductive Automation Ignition Remote Code Execution
CVE-2020-1200411 Jun 2020
The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior
23RISK
open
Metasploit600
Inductive Automation Ignition Remote Code Execution
CVE-2020-1064411 Jun 2020
The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted dat
23RISK
open
Exploit-DB
WinGate 9.4.1.5998 - Insecure Folder Permissions
CVE-2020-13866localwindows10 Jun 2020
WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges
23RISK
open
GitHub PoC
Norton Core Secure WiFi PoC (CVE-2018-5234) on Rust.
CVE-2018-523410 Jun 2020
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RISK
open
Metasploit600
Trend Micro Web Security (Virtual Appliance) Remote Code Execution
CVE-2020-860610 Jun 2020
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authent
40RISK
open
Metasploit600
Trend Micro Web Security (Virtual Appliance) Remote Code Execution
CVE-2020-860410 Jun 2020
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensi
40RISK
open
Metasploit600
Trend Micro Web Security (Virtual Appliance) Remote Code Execution
CVE-2020-860510 Jun 2020
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitr
60RISK
open
GitHub PoC355
SMBGhost (CVE-2020-0796) Automate Exploitation and Detection
CVE-2020-0796CRITICALunder attackransomware10 Jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALunder attackransomware10 Jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Exploit-DB
Bludit 3.9.12 - Directory Traversal
CVE-2019-16113webappsphp09 Jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISK
open
GitHub PoC5
Bludit >= 3.9.2 - Authenticated RCE (CVE-2019-16113)
CVE-2019-1611309 Jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISK
open
GitHub PoC
适配12.2.1.3和12.2.1.4版本
CVE-2020-2883CRITICALunder attack09 Jun 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
GitHub PoC3
SMBv3 Ghost (CVE-2020-0796) Vulnerability
CVE-2020-0796CRITICALunder attackransomware09 Jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
ratiros01/CVE-2004-1561
CVE-2004-156109 Jun 2020
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISK
open
GitHub PoC3
This is the exploit of CVE-2019-17240.
CVE-2019-17240LOW08 Jun 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
GitHub PoC72
Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215
CVE-2019-2215HIGHunder attack07 Jun 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack07 Jun 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware06 Jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Exploit-DB
D-Link DIR-615 T1 20.10 - CAPTCHA Bypass
CVE-2019-17525webappshardware04 Jun 2020
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and
23RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware04 Jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
client-side
CVE-2020-0796CRITICALunder attackransomware04 Jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware04 Jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC13
CVE-2019-16113 - bludit >= 3.9.2 RCE authenticate
CVE-2019-1611304 Jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISK
open
Metasploit600
Pandora FMS Events Remote Command Execution
CVE-2020-1385104 Jun 2020
Artica Pandora FMS 7.44 allows remote command execution via the events feature.
40RISK
open
Metasploit600
Cayin xPost wayfinder_seqid SQLi to RCE
CVE-2020-7356CRITICAL04 Jun 2020
Cayin xPost SQL Injection
48RISK
open
Metasploit600
Cayin CMS NTP Server RCE
CVE-2020-7357CRITICAL04 Jun 2020
Cayin CMS Command Injection
55RISK
open
GitHub PoC5
ynots0ups/CVE-2019-16113
CVE-2019-1611303 Jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISK
open
GitHub PoC
CVE-2020-5410
CVE-2020-5410HIGHunder attack03 Jun 2020
Directory Traversal with spring-cloud-config-server
100RISK
open
GitHub PoC3
Data Collection Related to Exim CVE-2019-10149
CVE-2019-10149CRITICALunder attack03 Jun 2020
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
Metasploit300
Cisco 7937G SSH Privilege Escalation
CVE-2020-1613702 Jun 2020
A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to re
23RISK
open
previouspage 767 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.