Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,230 exploits
Exploit-DB
TP-Link Archer C50 3 - Denial of Service (PoC)
CVE-2020-9375doshardware26 Mar 2020
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a
28RISK
open
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALunder attack26 Mar 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1676326 Mar 2020
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
Metasploit600
GitLab File Read Remote Code Execution
CVE-2020-1097726 Mar 2020
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
30RISK
open
GitHub PoC1
CVE 2018-16763
CVE-2018-1676326 Mar 2020
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC20
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.
CVE-2020-937525 Mar 2020
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a
28RISK
open
Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
CVE-2020-10882HIGH25 Mar 2020
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Arch
68RISK
open
Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
CVE-2020-10883MEDIUM25 Mar 2020
This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware
48RISK
open
Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
CVE-2020-10884HIGH25 Mar 2020
This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer
61RISK
open
Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
CVE-2020-2834725 Mar 2020
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the sl
40RISK
open
Exploit-DB
LeptonCMS 4.5.0 - Persistent Cross-Site Scripting
CVE-2020-12707webappsphp25 Mar 2020
An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only secur
23RISK
open
Exploit-DB
WordPress Plugin WPForms 1.5.8.2 - Persistent Cross-Site Scripting
CVE-2020-10385webappsphp24 Mar 2020
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.
23RISK
open
Exploit-DB
UCM6202 1.0.18.13 - Remote Command Injection
CVE-2020-5722CRITICALunder attackwebappshardware24 Mar 2020
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafte
100RISK
open
GitHub PoC109
quarkslab/CVE-2020-0069_poc
CVE-2020-0069HIGHunder attack24 Mar 2020
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RISK
open
VulnCheck XDB
local
CVE-2020-0069HIGHunder attack24 Mar 2020
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RISK
open
GitHub PoC
A check for GHOST; cve-2015-0235
CVE-2015-023524 Mar 2020
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RISK
open
Exploit-DB
UliCMS 2020.1 - Persistent Cross-Site Scripting
CVE-2020-12704webappsphp24 Mar 2020
UliCMS before 2020.2 has PageController stored XSS.
23RISK
open
GitHub PoC6
CVE-2017-12636|exploit Couchdb
CVE-2017-1263623 Mar 2020
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISK
open
Metasploit600
Grandstream UCM62xx IP PBX sendPasswordEmail RCE
CVE-2020-5722CRITICALunder attack23 Mar 2020
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafte
100RISK
open
GitHub PoC1
DoS PoC for CVE-2020-0796 (SMBGhost)
CVE-2020-0796CRITICALunder attackransomware21 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
client-side
CVE-2019-13720HIGHunder attack21 Mar 2020
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap
93RISK
open
GitHub PoC3
批量检测幽灵猫漏洞
CVE-2020-1938CRITICALunder attack20 Mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
Exploit-DBVexDay Proof
VMware Fusion 11.5.2 - Privilege Escalation
CVE-2020-3950HIGHunder attacklocalmacos20 Mar 2020
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for
86RISK
open
GitHub PoC8
Vulnerability scanner for CVE-2020-0688
CVE-2020-0688HIGHunder attackransomware19 Mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC66
An experimental script PoC for Kr00k vulnerability (CVE-2019-15126)
CVE-2019-1512618 Mar 2020
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal
23RISK
open
Metasploit0
Safari in Operator Side Effect Exploit
CVE-2020-985618 Mar 2020
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An application may be able
18RISK
open
Metasploit0
Safari in Operator Side Effect Exploit
CVE-2020-980118 Mar 2020
A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1.1. A malicious process may ca
18RISK
open
Metasploit600
macOS cfprefsd Arbitrary File Write Local Privilege Escalation
CVE-2020-983918 Mar 2020
A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Cata
18RISK
open
Metasploit0
Safari in Operator Side Effect Exploit
CVE-2020-985018 Mar 2020
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, wa
40RISK
open
Exploit-DB
Broadcom Wi-Fi Devices - 'KR00K Information Disclosure
CVE-2019-15126remotemultiple18 Mar 2020
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal
23RISK
open
previouspage 782 / 2,641next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.