Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,230 exploits
Exploit-DBVexDay Proof
DLINK DWL-2600 - Authenticated Remote Command Injection (Metasploit)
CVE-2019-20499remotehardware31 Mar 2020
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Config
60RISK
open
Exploit-DBVexDay Proof
IBM TM1 / Planning Analytics - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-4716CRITICALunder attackremotemultiple31 Mar 2020
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated use
100RISK
open
Exploit-DB
Grandstream UCM6200 Series CTI Interface - 'user_password' SQL Injection
CVE-2020-5726webappshardware31 Mar 2020
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A rem
23RISK
open
VulnCheck XDB
initial-access
CVE-2020-8515CRITICALunder attack31 Mar 2020
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RISK
open
GitHub PoC
codecat007/CVE-2019-2215
CVE-2019-2215HIGHunder attack31 Mar 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
GitHub PoC17
Windows SMBv3 LPE exploit 已编译版
CVE-2020-0796CRITICALunder attackransomware31 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC4
Coronablue exploit
CVE-2020-0796CRITICALunder attackransomware31 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
local
CVE-2020-0041HIGHunder attack31 Mar 2020
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISK
open
GitHub PoC3
nmap script to detect CVE-2020-8515 on Draytek Devices
CVE-2020-8515CRITICALunder attack31 Mar 2020
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack30 Mar 2020
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware30 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
Exploit for the CVE-2019-16278 vulnerability
CVE-2019-16278CRITICALunder attack30 Mar 2020
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC14
CVE-2020-8515-PoC
CVE-2020-8515CRITICALunder attack30 Mar 2020
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RISK
open
GitHub PoC
tripledd/cve-2020-0796-vuln
CVE-2020-0796CRITICALunder attackransomware30 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Metasploit300
Grandstream UCM62xx IP PBX WebSocket Blind SQL Injection Credential Dump
CVE-2020-572430 Mar 2020
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpo
23RISK
open
Metasploit300
Grandstream UCM62xx IP PBX WebSocket Blind SQL Injection Credential Dump
CVE-2020-572330 Mar 2020
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an atta
18RISK
open
Exploit-DB
Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Local Privilege Escalation
CVE-2020-0796CRITICALunder attackransomwarelocalwindows30 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-8515CRITICALunder attack30 Mar 2020
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RISK
open
Exploit-DB
Multiple DrayTek Products - Pre-authentication Remote Root Code Execution
CVE-2020-8515CRITICALunder attackremotelinux30 Mar 2020
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RISK
open
GitHub PoC1,359
CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost
CVE-2020-0796CRITICALunder attackransomware30 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC244
CVE-2020-0796 Local Privilege Escalation POC
CVE-2020-0796CRITICALunder attackransomware30 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALunder attack29 Mar 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2018-8639HIGHunder attackransomware28 Mar 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RISK
open
VulnCheck XDB
client-side
CVE-2019-5786MEDIUMunder attack28 Mar 2020
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISK
open
Metasploit400
Pi-Hole DHCP MAC OS Command Execution
CVE-2020-8816CRITICALunder attack28 Mar 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RISK
open
GitHub PoC1
CVE-2019-17558 Solr模板注入漏洞图形化一键检测工具。CVE-2019-17558 Solr Velocity Template Vul POC Tool.
CVE-2019-17558HIGHunder attack27 Mar 2020
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALunder attack27 Mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC7
Icecast Header Overwrite buffer overflow RCE < 2.0.1 (Win32)
CVE-2004-156127 Mar 2020
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISK
open
GitHub PoC8
CVE-2020-1938 / CNVD-2020-1048 Detection Tools
CVE-2020-1938CRITICALunder attack27 Mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
Metasploit600
GitLab File Read Remote Code Execution
CVE-2020-1097726 Mar 2020
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
30RISK
open
previouspage 781 / 2,641next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.