Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,230 exploits
Metasploit200
SMBv3 Compression Buffer Overflow
CVE-2020-0796CRITICALunder attackransomware13 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
kn6869610/CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Metasploit0
vBulletin /ajax/api/content_infraction/getIndexableContent nodeid Parameter SQL Injection
CVE-2020-1272012 Mar 2020
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
40RISK
open
GitHub PoC57
Scanner for CVE-2020-0796 - A SMBv3.1.1 + SMB compression RCE
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Exploit-DB
WordPress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
CVE-2020-9371webappsphp12 Mar 2020
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php
23RISK
open
Metasploit300
vBulletin /ajax/api/content_infraction/getIndexableContent nodeid Parameter SQL Injection
CVE-2020-1272012 Mar 2020
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
40RISK
open
GitHub PoC2
SMBv3 RCE vulnerability in SMBv3
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC14
This project is used for scanning cve-2020-0796 SMB vulnerability
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC1
This repository contains a test case for CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
CVE-2020-0796 SMBv3.1.1 Compression Capability Vulnerability Scanner
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC1
Scanners List - Microsoft Windows SMBv3 Remote Code Execution Vulnerability (CVE-2020-0796)
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC4
Scanner script to identify hosts vulnerable to CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
This script will apply the workaround for the vulnerability CVE-2020-0796 for the SMBv3 unauthenticated RCE
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC332
PoC for triggering buffer overflow via CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC19
Multithread SMB scanner to check CVE-2020-0796 for SMB v3.11
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Exploit-DB
rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution
CVE-2020-10221HIGHunder attackwebappsphp12 Mar 2020
lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands vi
100RISK
open
Exploit-DB
WordPress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
CVE-2020-9372webappsphp12 Mar 2020
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or
23RISK
open
Exploit-DB
rConfig 3.9 - 'searchColumn' SQL Injection
CVE-2020-10220webappsphp12 Mar 2020
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open
GitHub PoC
Check system is vulnerable CVE-2020-0796 (SMB v3)
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC1
SMBGhost (CVE-2020-0796) threaded scanner
CVE-2020-0796CRITICALunder attackransomware12 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
Implementing CVE-2020-0601
CVE-2020-0601HIGHunder attack12 Mar 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
Metasploit400
Rconfig 3.x Chained Remote Code Execution
CVE-2019-1950911 Mar 2020
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a
60RISK
open
Metasploit400
Rconfig 3.x Chained Remote Code Execution
CVE-2020-1022011 Mar 2020
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open
Exploit-DB
Horde Groupware Webmail Edition 5.2.22 - PHAR Loading
CVE-2020-8866MEDIUMwebappsphp11 Mar 2020
This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmai
33RISK
open
Exploit-DB
Horde Groupware Webmail Edition 5.2.22 - PHP File Inclusion
CVE-2020-8866MEDIUMwebappsphp11 Mar 2020
This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmai
33RISK
open
GitHub PoC
Authentication Bypass in Server Code for LibSSH
CVE-2018-10933CRITICAL11 Mar 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC721
Scanner for CVE-2020-0796 - SMBv3 RCE
CVE-2020-0796CRITICALunder attackransomware11 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC9
CVE-2020-0796 Flaw Mitigation - Active Directory Administrative Templates
CVE-2020-0796CRITICALunder attackransomware11 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC17
Identifying and Mitigating the CVE-2020–0796 flaw in the fly
CVE-2020-0796CRITICALunder attackransomware11 Mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
previouspage 784 / 2,641next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.