Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,229 exploits
GitHub PoC1
CVE-2017-12615 批量脚本
CVE-2017-12615HIGHunder attackransomware20 Jan 2020
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
VulnCheck XDB
local
CVE-2019-8605HIGHunder attack20 Jan 2020
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RISK
open
GitHub PoC1
Remote Command Injection Vulnerability (CVE-2007-2447), allows remote attackers to execute arbitrary commands by specifying a Samba username containing shell meta characters.
CVE-2007-244720 Jan 2020
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC
Ash112121/CVE-2020-0601
CVE-2020-0601HIGHunder attack20 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
Exploit-DB
Easy XML Editor 1.7.8 - XML External Entity Injection
CVE-2019-19031localxml20 Jan 2020
Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS
23RISK
open
GitHub PoC5
tfp0 based on CVE-2019-8591/CVE-2019-8605
CVE-2019-859120 Jan 2020
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.
23RISK
open
VulnCheck XDB
initial-access
CVE-2020-2551CRITICALunder attack19 Jan 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISK
open
GitHub PoC211
how detect CVE-2020-2551 poc exploit python Weblogic RCE with IIOP
CVE-2020-2551CRITICALunder attack19 Jan 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISK
open
GitHub PoC
Repo containing lua scripts and PCAP to find CVE-2020-0601 exploit attempts via network traffic
CVE-2020-0601HIGHunder attack19 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC3
CurveBall (CVE-2020-0601) - PoC CVE-2020-0601, or commonly referred to as CurveBall, is a vulnerability in which the signature of certificates using elliptic curve cryptography (ECC) is not correctly verified. Attackers can supply hand-rolled generators, bypassing validation, antivirus & all non-protections.
CVE-2020-0601HIGHunder attack19 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
VulnCheck XDB
client-side
CVE-2020-0601HIGHunder attack19 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC
Perl version of recently published scripts to build ECC certificates with specific parameters re CVE-2020-0601
CVE-2020-0601HIGHunder attack18 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC4
CVE-2019-19844 Docker Edition
CVE-2019-1984418 Jan 2020
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RISK
open
GitHub PoC80
Weblogic RCE with IIOP
CVE-2020-2551CRITICALunder attack18 Jan 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISK
open
GitHub PoC1
Powershell to patch CVE-2020-0601 . Complete security rollup for Windows 10 1507-1909
CVE-2020-0601HIGHunder attack17 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC1
CVE-2019-19781 Attack Triage Script
CVE-2019-19781CRITICALunder attackransomware17 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC
C++ based utility to check if certificates are trying to exploit CVE-2020-0601
CVE-2020-0601HIGHunder attack17 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC
批量概念驗證用
CVE-2019-19781CRITICALunder attackransomware17 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC
A fast multi threaded scanner for Citrix ADC (NetScaler) CVE-2019-19781 - Citrixmash
CVE-2019-19781CRITICALunder attackransomware17 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
Exploit-DBVexDay Proof
Plantronics Hub 3.13.2 - SpokesUpdateService Privilege Escalation (Metasploit)
CVE-2019-15742localwindows17 Jan 2020
A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application
38RISK
open
GitHub PoC2
CurveBall CVE exploitation
CVE-2020-0601HIGHunder attack17 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC
MarkusZehnle/CVE-2020-0601
CVE-2020-0601HIGHunder attack17 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-19781CRITICALunder attackransomware17 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
client-side
CVE-2020-0601HIGHunder attack16 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
Exploit-DB
WordPress Plugin Postie 1.9.40 - Persistent Cross-Site Scripting
CVE-2019-20204webappsphp16 Jan 2020
The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginn
23RISK
open
GitHub PoC3
Check ADC for CVE-2019-19781
CVE-2019-19781CRITICALunder attackransomware16 Jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
Exploit-DB
Jenkins Gitlab Hook Plugin 1.4.2 - Reflected Cross-Site Scripting
CVE-2020-2096webappsjava16 Jan 2020
Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a ref
60RISK
open
GitHub PoC5
😂An awesome curated list of repos for CVE-2020-0601.
CVE-2020-0601HIGHunder attack16 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC1
Curated list of CVE-2020-0601 resources
CVE-2020-0601HIGHunder attack16 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC66
Proof of Concept for CVE-2020-0601
CVE-2020-0601HIGHunder attack16 Jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
previouspage 795 / 2,641next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.