Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,107 exploits
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALunder attackransomware02 Jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Exploit-DB
vCloud Director 9.7.0.15498291 - Remote Code Execution
CVE-2020-3956remotelinux02 Jun 2020
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4
28RISK
open
Exploit-DB
Microsoft Windows - 'SMBGhost' Remote Code Execution
CVE-2020-0796CRITICALunder attackransomwareremotewindows02 Jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC5
Exploit for CVE-2020-9283 based on Go
CVE-2020-928302 Jun 2020
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the
28RISK
open
Metasploit300
Cisco 7937G Denial-of-Service Attack
CVE-2020-1613802 Jun 2020
A denial-of-service issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to remot
23RISK
open
Exploit-DB
OpenCart 3.0.3.2 - Stored Cross Site Scripting (Authenticated)
CVE-2020-10596webappsphp02 Jun 2020
OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upl
23RISK
open
GitHub PoC
CVE-2020-0796-exp
CVE-2020-0796CRITICALunder attackransomware02 Jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Metasploit300
Cisco 7937G Denial-of-Service Reboot Attack
CVE-2020-1613902 Jun 2020
A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the de
40RISK
open
Metasploit300
Cisco 7937G SSH Privilege Escalation
CVE-2020-1613702 Jun 2020
A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to re
23RISK
open
Metasploit300
Cisco DCNM auth bypass
CVE-2019-15975CRITICAL01 Jun 2020
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
85RISK
open
Metasploit300
Directory Traversal in Spring Cloud Config Server
CVE-2020-5410HIGHunder attack01 Jun 2020
Directory Traversal with spring-cloud-config-server
100RISK
open
Exploit-DB
WordPress Plugin BBPress 2.5 - Unauthenticated Privilege Escalation
CVE-2020-13693webappsphp01 Jun 2020
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Regi
35RISK
open
GitHub PoC89
PoC exploit for VMware Cloud Director RCE (CVE-2020-3956)
CVE-2020-395601 Jun 2020
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4
28RISK
open
Exploit-DB
QuickBox Pro 2.1.8 - Authenticated Remote Code Execution
CVE-2020-13448webappsphp01 Jun 2020
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execut
28RISK
open
Exploit-DB
VMware vCenter Server 6.7 - Authentication Bypass
CVE-2020-3952CRITICALunder attackwebappsmultiple01 Jun 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
VulnCheck XDB
local
CVE-2020-106601 Jun 2020
.NET Framework Elevation of Privilege Vulnerability
23RISK
open
VulnCheck XDB
local
CVE-2020-106601 Jun 2020
.NET Framework Elevation of Privilege Vulnerability
23RISK
open
GitHub PoC3
nmurilo/CVE-2008-4687-exploit
CVE-2008-468730 May 2020
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISK
open
GitHub PoC5
The reproduction code for CVE-2019-8641.
CVE-2019-864129 May 2020
An out-of-bounds read was addressed with improved input validation.
28RISK
open
VulnCheck XDB
initial-access
CVE-2017-15944CRITICALunder attack29 May 2020
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALunder attackransomware29 May 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC2
This project for CVE-2019-18935
CVE-2019-18935CRITICALunder attackransomware29 May 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC
yukar1z0e/CVE-2017-15944
CVE-2017-15944CRITICALunder attack29 May 2020
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISK
open
GitHub PoC
halsten/CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware28 May 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALunder attackransomware28 May 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
local
CVE-2016-072827 May 2020
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISK
open
GitHub PoC55
CVE-2016-4437-Shiro反序列化爆破模块和key,命令执行,反弹shell的脚本
CVE-2016-4437CRITICALunder attack27 May 2020
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware27 May 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware27 May 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2016-4437CRITICALunder attack27 May 2020
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISK
open
previouspage 768 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.