Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,107 exploits
VulnCheck XDB
initial-access
CVE-2012-268806 Mar 2020
Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.
28RISK
open
GitHub PoC
CVE-2020-8597
CVE-2020-8597CRITICAL06 Mar 2020
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RISK
open
VulnCheck XDB
initial-access
CVE-2019-11580CRITICALunder attackransomware06 Mar 2020
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RISK
open
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8654remotemultiple05 Mar 2020
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD
60RISK
open
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8655HIGHunder attackremotemultiple05 Mar 2020
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RISK
open
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8656remotemultiple05 Mar 2020
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe
60RISK
open
Exploit-DBVexDay Proof
Exchange Control Panel - Viewstate Deserialization (Metasploit)
CVE-2020-0688HIGHunder attackransomwareremotewindows05 Mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC
CVE-2019-13272
CVE-2019-13272HIGHunder attack05 Mar 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8657CRITICALunder attackremotemultiple05 Mar 2020
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include
100RISK
open
VulnCheck XDB
local
CVE-2019-13272HIGHunder attack05 Mar 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
Metasploit500
ManageEngine Desktop Central Java Deserialization
CVE-2020-10189CRITICALunder attack05 Mar 2020
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-8655HIGHunder attack05 Mar 2020
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RISK
open
VulnCheck XDB
initial-access
CVE-2020-865605 Mar 2020
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe
60RISK
open
Metasploit600
Metasploit Libnotify Plugin Arbitrary Command Execution
CVE-2020-7350MEDIUM04 Mar 2020
Metasploit Framework Plugin Libnotify Command Injection
28RISK
open
GitHub PoC5
PoC for Forgot2kEyXCHANGE (CVE-2020-0688) written in PowerShell
CVE-2020-0688HIGHunder attackransomware04 Mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
VulnCheck XDB
local
CVE-2019-1458HIGHunder attackransomware03 Mar 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
GitHub PoC
exploitblizzard/CVE-2020-0601-spoofkey
CVE-2020-0601HIGHunder attack03 Mar 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC181
POC for cve-2019-1458
CVE-2019-1458HIGHunder attackransomware03 Mar 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
GitHub PoC
PoC of CVE
CVE-2020-6418HIGHunder attack03 Mar 2020
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISK
open
Exploit-DB
Microsoft Windows - 'WizardOpium' Local Privilege Escalation
CVE-2019-1458HIGHunder attackransomwarelocalwindows03 Mar 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
GitHub PoC17
reversing mtk-su
CVE-2020-0069HIGHunder attack03 Mar 2020
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RISK
open
Exploit-DB
Alfresco 5.2.4 - Persistent Cross-Site Scripting
CVE-2020-8777webappsphp03 Mar 2020
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo,
23RISK
open
Exploit-DB
Alfresco 5.2.4 - Persistent Cross-Site Scripting
CVE-2020-8776webappsphp03 Mar 2020
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a
23RISK
open
GitHub PoC
CVE-2020-1938
CVE-2020-1938CRITICALunder attack03 Mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
Exploit-DB
Alfresco 5.2.4 - Persistent Cross-Site Scripting
CVE-2020-8778webappsphp03 Mar 2020
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document,
23RISK
open
VulnCheck XDB
denial-of-service
CVE-2018-6789CRITICALunder attackransomware02 Mar 2020
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALunder attack02 Mar 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
Metasploit600
SharePoint Workflows XOML Injection
CVE-2020-0646CRITICALunder attack02 Mar 2020
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N
100RISK
open
Exploit-DB
TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)
CVE-2019-19143webappshardware02 Mar 2020
TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi
23RISK
open
Exploit-DB
Joplin Desktop 1.0.184 - Cross-Site Scripting
CVE-2020-9038webappsmultiple02 Mar 2020
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
23RISK
open
previouspage 785 / 2,637next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.