Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,230 exploits
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALunder attack17 Mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
Exploit-DBVexDay Proof
Rconfig 3.x - Chained Remote Code Execution (Metasploit)
CVE-2019-19509remotelinux17 Mar 2020
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a
60RISK
open
Metasploit600
Vesta Control Panel Authenticated Remote Code Execution
CVE-2020-1080817 Mar 2020
Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint.
40RISK
open
Exploit-DBVexDay Proof
ManageEngine Desktop Central - Java Deserialization (Metasploit)
CVE-2020-10189CRITICALunder attackremotemultiple17 Mar 2020
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RISK
open
Metasploit600
VMware Fusion USB Arbitrator Setuid Privilege Escalation
CVE-2020-3950HIGHunder attack17 Mar 2020
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for
86RISK
open
GitHub PoC1
Scanner CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware17 Mar 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware17 Mar 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DBVexDay Proof
Rconfig 3.x - Chained Remote Code Execution (Metasploit)
CVE-2020-10220remotelinux17 Mar 2020
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware17 Mar 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-0708CRITICALunder attackransomware17 Mar 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware16 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-0796CRITICALunder attackransomware16 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC1
Lightweight PoC and Scanner for CVE-2020-0796 without authentication.
CVE-2020-0796CRITICALunder attackransomware16 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC3
CVE-2020-0796_CoronaBlue_SMBGhost
CVE-2020-0796CRITICALunder attackransomware16 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC1
Scanner for CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware16 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC9
CVE-2020-0796-Scanner
CVE-2020-0796CRITICALunder attackransomware15 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC22
An unauthenticated PoC for CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware15 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware15 Mar 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC148
CVE-2019-0708 (BlueKeep) proof of concept allowing pre-auth RCE on Windows7
CVE-2019-0708CRITICALunder attackransomware15 Mar 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DB
Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC)
CVE-2020-0796CRITICALunder attackransomwaredoswindows14 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC14
Advanced scanner for CVE-2020-0796 - SMBv3 RCE
CVE-2020-0796CRITICALunder attackransomware14 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
CVE-2020-0796 Python POC buffer overflow
CVE-2020-0796CRITICALunder attackransomware14 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC15
基于asyncio(协程)的CVE-2020-0796 速度还是十分可观的,方便运维师傅们对内网做下快速检测。
CVE-2020-0796CRITICALunder attackransomware14 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack14 Mar 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
Metasploit400
SMBv3 Compression Buffer Overflow
CVE-2020-0796CRITICALunder attackransomware13 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC1
Little scanner to know if a machine is runnig SMBv3 (possible vulnerability CVE-2020-0796)
CVE-2020-0796CRITICALunder attackransomware13 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Metasploit200
SMBv3 Compression Buffer Overflow
CVE-2020-0796CRITICALunder attackransomware13 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC5
CVE-2020-0796 - Working PoC - 20200313
CVE-2020-0796CRITICALunder attackransomware13 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
qq1515406085/CVE-2019-19356
CVE-2019-19356HIGHunder attack13 Mar 2020
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page.
76RISK
open
GitHub PoC
A POC remote buffer overflow for CVE-2003-0264 - SLMail 5.5
CVE-2003-026413 Mar 2020
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISK
open
previouspage 783 / 2,641next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.