Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,107 exploits
Exploit-DB
BIND - 'TSIG' Denial of Service
CVE-2020-8617HIGHdosmultiple20 May 2020
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware19 May 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
Exploit-DBVexDay Proof
Pi-Hole - heisenbergCompensator Blocklist OS Command Execution (Metasploit)
CVE-2020-11108remotephp19 May 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISK
open
GitHub PoC105
Cisco AnyConnect < 4.8.02042 privilege escalation through path traversal
CVE-2020-3153MEDIUMunder attackransomware19 May 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RISK
open
Metasploit300
BIND TSIG Badtime Query Denial of Service
CVE-2020-8617HIGH19 May 2020
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RISK
open
Exploit-DB
Submitty 20.04.01 - Persistent Cross-Site Scripting
CVE-2020-12882webappsphp19 May 2020
Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a
23RISK
open
Exploit-DB
Mikrotik Router Monitoring System 1.2.3 - 'community' SQL Injection
CVE-2020-13118webappshardware18 May 2020
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community
23RISK
open
VulnCheck XDB
initial-access
CVE-2018-13379CRITICALunder attackransomware18 May 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware18 May 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
Exploit-DB
HP LinuxKI 6.01 - Remote Command Injection
CVE-2020-7209remotemultiple18 May 2020
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RISK
open
GitHub PoC30
Tool to try multiple paths for PHPunit RCE CVE-2017-9841
CVE-2017-9841CRITICALunder attack18 May 2020
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
Exploit-DB
Oracle Hospitality RES 3700 5.7 - Remote Code Execution
CVE-2019-3025webappsjava18 May 2020
Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications. The supported versi
28RISK
open
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALunder attack18 May 2020
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC
yukar1z0e/CVE-2018-13379
CVE-2018-13379CRITICALunder attackransomware18 May 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-18935CRITICALunder attackransomware17 May 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
VulnCheck XDB
local
CVE-2018-0802HIGHunder attackransomware17 May 2020
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISK
open
Metasploit600
LinuxKI Toolset 6.01 Remote Command Execution
CVE-2020-720917 May 2020
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RISK
open
GitHub PoC
TelerikUI Vulnerability Scanner (CVE-2019-18935)
CVE-2019-18935CRITICALunder attackransomware17 May 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC89
Weblogic Vuln POC EXP cve-2020-2551 cve-2020-2555 cve-2020-2883 ,。。。
CVE-2020-2551CRITICALunder attack16 May 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-2883CRITICALunder attack16 May 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
GitHub PoC
PoC for CVE-2020-3153 Cisco AnyConnect Secure Mobility Client EoP
CVE-2020-3153MEDIUMunder attackransomware15 May 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2020-1280015 May 2020
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Uploa
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-10199HIGHunder attack15 May 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
VulnCheck XDB
local
CVE-2020-3153MEDIUMunder attackransomware15 May 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RISK
open
GitHub PoC
CVE-2018-10933_Scanner
CVE-2018-10933CRITICAL15 May 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
Metasploit600
Plesk/myLittleAdmin ViewState .NET Deserialization
CVE-2020-1316615 May 2020
The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcod
60RISK
open
GitHub PoC
cdedmondson/Modified-CVE-2015-3306-Exploit
CVE-2015-330615 May 2020
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
GitHub PoC31
CVE-2020-10199 回显版本
CVE-2020-10199HIGHunder attack15 May 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
GitHub PoC
ES File Explorer Open Port Vulnerability - CVE-2019-6447
CVE-2019-644714 May 2020
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open
VulnCheck XDB
initial-access
CVE-2019-0193HIGHunder attack14 May 2020
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISK
open
previouspage 770 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.