Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,210cataloged exploits
36,420CVEs with public exploitation
24,695lab-tested
79,107 exploits
Metasploit400
WordPress Simple File List Unauthenticated Remote Code Execution
CVE-2020-36847CRITICAL27 Apr 2020
Simple File List < 4.2.3 - Remote Code Execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2017-7921CRITICALunder attack27 Apr 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC
CVE-2018-15133 (Webased)
CVE-2018-15133HIGHunder attack27 Apr 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC102
Hikvision camera CVE-2017-7921-EXP
CVE-2017-7921CRITICALunder attack27 Apr 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC1
wcxxxxx/CVE-2020-7961
CVE-2020-7961CRITICALunder attack27 Apr 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
Exploit-DB
Source Engine CS:GO BuildID: 4937372 - Arbitrary Code Execution
CVE-2020-12242localmacos27 Apr 2020
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in
23RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware26 Apr 2020
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC
Sudo Vulnerability CVE-2019-14287
CVE-2019-1428726 Apr 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC2
WordPress CVE-2017-5487 Exploit in Python
CVE-2017-548726 Apr 2020
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISK
open
GitHub PoC7
android-kernel-exploitation-ashfaq-CVE-2019-2215 docker setup for mac users
CVE-2019-2215HIGHunder attack25 Apr 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
GitHub PoC
JJSO12/Apache-Pluto-3.0.0--CVE-2018-1306
CVE-2018-130624 Apr 2020
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote a
35RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware23 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALunder attackransomware22 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC3
PoC RCE Reverse Shell for CVE-2020-0688
CVE-2020-0688HIGHunder attackransomware22 Apr 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC
section-c/CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware22 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC11
PoC RCE Reverse Shell for CVE-2020-0796 (SMBGhost)
CVE-2020-0796CRITICALunder attackransomware22 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC35
Whatsapp Automatic Payload Generator [CVE-2019-11932]
CVE-2019-1193222 Apr 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
GitHub PoC2
snappyJack/pdfresurrect_CVE-2019-14267
CVE-2019-1426722 Apr 2020
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is misha
23RISK
open
GitHub PoC1
3x1t1um/CVE-2007-2447
CVE-2007-244722 Apr 2020
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC2
CVE-2004-1769 cPanel Resetpass Remote Command Execution
CVE-2004-176921 Apr 2020
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x,
35RISK
open
Metasploit300
IBM Data Risk Manager Arbitrary File Download
CVE-2020-4427CRITICALunder attack21 Apr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security rest
95RISK
open
Metasploit300
IBM Data Risk Manager Arbitrary File Download
CVE-2020-4429CRITICAL21 Apr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ
65RISK
open
Metasploit600
IBM Data Risk Manager a3user Default Password
CVE-2020-4429CRITICAL21 Apr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ
65RISK
open
Exploit-DB
Neowise CarbonFTP 1.4 - Insecure Proprietary Password Encryption
CVE-2020-6857remotewindows21 Apr 2020
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FT
23RISK
open
Metasploit600
IBM Data Risk Manager Unauthenticated Remote Code Execution
CVE-2020-4428CRITICALunder attack21 Apr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary co
85RISK
open
Exploit-DB
Oracle Solaris Common Desktop Environment 1.6 - Local Privilege Escalation
CVE-2020-2944HIGHlocalsolaris21 Apr 2020
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported version
41RISK
open
Metasploit600
IBM Data Risk Manager Unauthenticated Remote Code Execution
CVE-2020-4429CRITICAL21 Apr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ
65RISK
open
Metasploit600
IBM Data Risk Manager Unauthenticated Remote Code Execution
CVE-2020-4427CRITICALunder attack21 Apr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security rest
95RISK
open
Exploit-DBVexDay Proof
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
CVE-2020-5849HIGHunder attackremotelinux20 Apr 2020
Unraid 6.8.0 allows authentication bypass.
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALunder attackransomware20 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
previouspage 775 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.