Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,230 exploits
VulnCheck XDB
client-side
CVE-2019-11707HIGHunder attack13 Apr 2020
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RISK
open
VulnCheck XDB
local
CVE-2018-19320HIGHunder attackransomware13 Apr 2020
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISK
open
GitHub PoC19
Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)
CVE-2018-19320HIGHunder attackransomware13 Apr 2020
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware12 Apr 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC8
CVE-2018-7600【Drupal7】批量扫描工具。
CVE-2018-7600CRITICALunder attackransomware12 Apr 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC1
Code execution for CVE-2017-11176
CVE-2017-1117610 Apr 2020
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISK
open
Metasploit300
Zen Load Balancer Directory Traversal
CVE-2020-1149110 Apr 2020
Monitoring::Logs in Zen Load Balancer 3.10.1 allows remote authenticated admins to conduct absolute path traversal attac
18RISK
open
Metasploit300
VMware vCenter Server vmdir Information Disclosure
CVE-2020-3952CRITICALunder attack09 Apr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
Metasploit300
VMware vCenter Server vmdir Authentication Bypass
CVE-2020-3952CRITICALunder attack09 Apr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
GitHub PoC
This Repository use to test Apache Killer (cve-2011-3192).
CVE-2011-319209 Apr 2020
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-10199HIGHunder attack08 Apr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
GitHub PoC35
CVE-2020-10199、CVE-2020-10204、CVE-2020-11444
CVE-2020-10199HIGHunder attack08 Apr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-20699CRITICALunder attack08 Apr 2020
Cisco Small Business RV Series Routers Vulnerabilities
100RISK
open
VulnCheck XDB
client-side
CVE-2017-12149CRITICALunder attackransomware08 Apr 2020
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
GitHub PoC25
CVE-2020-10199、CVE-2020-10204漏洞一键检测工具,图形化界面。CVE-2020-10199 and CVE-2020-10204 Vul Tool with GUI.
CVE-2020-10199HIGHunder attack08 Apr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
Exploit-DB
Amcrest Dahua NVR Camera IP2M-841 - Denial of Service (PoC)
CVE-2020-5735HIGHunder attackdoshardware08 Apr 2020
Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacke
83RISK
open
GitHub PoC7
CVE-2020-0796 (SMBGhost) LPE
CVE-2020-0796CRITICALunder attackransomware07 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
local
CVE-2019-1609807 Apr 2020
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user t
28RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware07 Apr 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack07 Apr 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
infoleak
CVE-2020-10199HIGHunder attack07 Apr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
GitHub PoC19
CVE-2020-10199 CVE-2020-10204 Python POC
CVE-2020-10199HIGHunder attack07 Apr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALunder attackransomware07 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware07 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC8
CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本
CVE-2018-7600CRITICALunder attackransomware07 Apr 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
CVE-2017-10271
CVE-2017-10271HIGHunder attackransomware06 Apr 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC75
Cobalt Strike AggressorScripts CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware06 Apr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Exploit-DB
WhatsApp Desktop 0.3.9308 - Persistent Cross-Site Scripting
CVE-2019-18426HIGHunder attackwebappsmultiple06 Apr 2020
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.
83RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware06 Apr 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
local
CVE-2019-1215HIGHunder attackransomware06 Apr 2020
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Win
76RISK
open
previouspage 779 / 2,641next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.