Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,108cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
79,107 exploits
GitHub PoC
CVE-2020-1938 exploit
CVE-2020-1938CRITICALunder attack12 May 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC
dinidhu96/IT19013756_-CVE-2016-4971-
CVE-2016-497112 May 2020
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RISK
open
GitHub PoC
SachinThanushka/CVE-2018-1160
CVE-2018-1160CRITICAL12 May 2020
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RISK
open
GitHub PoC3
Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287/Google Android - 'Stagefright' Remote Code Execution - CVE-2015-1538
CVE-2015-153812 May 2020
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISK
open
GitHub PoC
This is a Dirty Cow (CVE-2016-5195) privilege escalation vulnerability exploit
CVE-2016-5195HIGHunder attack12 May 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
Lumindu/CVE-2017-16995-Linux-Kernel---BPF-Sign-Extension-Local-Privilege-Escalation-
CVE-2017-1699512 May 2020
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
GitHub PoC
Dirtycow also is known as CVE-2016-5195
CVE-2016-5195HIGHunder attack12 May 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
CVE-2019-5736
CVE-2019-573612 May 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC
SNP Assignment on a Linux vulnerability
CVE-2019-10149CRITICALunder attack12 May 2020
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC
AvishkaSenadheera/CVE-2017-9805---Documentation---IT19143378
CVE-2017-9805HIGHunder attack12 May 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
GitHub PoC
lalishasanduwara/CVE-2018-10933
CVE-2018-10933CRITICAL12 May 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC1
Exploit work Privilege Escalation CVE-2017-1000112
CVE-2017-100011212 May 2020
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISK
open
GitHub PoC
This is my SNP project where my ID is IT19366128
CVE-2015-132812 May 2020
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
GitHub PoC4
CVE-2019-6111 vulnerability exploitation
CVE-2019-6111MEDIUM12 May 2020
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh
45RISK
open
Exploit-DB
WordPress Plugin ChopSlider 3.4 - 'id' SQL Injection
CVE-2020-11530webappsphp12 May 2020
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RISK
open
Metasploit600
Wordpress Drag and Drop Multi File Uploader RCE
CVE-2020-1280011 May 2020
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Uploa
60RISK
open
GitHub PoC
shanuka-ashen/Dirty-Cow-Explanation-CVE-2016-5195-
CVE-2016-5195HIGHunder attack11 May 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
Sudo Security Policy bypass Vulnerability
CVE-2019-1428711 May 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC1
Google Android - 'Stagefright' Remote Code Execution - CVE-2015-1538
CVE-2015-153811 May 2020
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISK
open
GitHub PoC
Documentation for Sudo Security Bypass - CVE 2019-14287
CVE-2019-1428711 May 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC1
Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287
CVE-2019-13272HIGHunder attack11 May 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC
Exploit code for CVE-2015-5477 POC
CVE-2015-547711 May 2020
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-1040MEDIUM11 May 2020
Windows NTLM Tampering Vulnerability
45RISK
open
Exploit-DB
SolarWinds MSP PME Cache Service 1.1.14 - Insecure File Permissions
CVE-2020-12608localwindows11 May 2020
An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Moni
28RISK
open
VulnCheck XDB
initial-access
CVE-2015-547711 May 2020
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISK
open
Exploit-DB
Pi-hole < 4.4 - Authenticated Remote Code Execution / Privileges Escalation
CVE-2020-11108webappslinux10 May 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-8816CRITICALunder attack10 May 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RISK
open
GitHub PoC10
A Python script to exploit CVE-2020-8816, a remote code execution vulnerability on the Pi-hole
CVE-2020-8816CRITICALunder attack10 May 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-2883CRITICALunder attack10 May 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
Exploit-DB
Pi-hole < 4.4 - Authenticated Remote Code Execution
CVE-2020-11108webappslinux10 May 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISK
open
previouspage 772 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.