Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
8,198 exploits
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware19 Dec 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware19 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-5902CRITICALunder attackransomware19 Dec 2021
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-45046CRITICALunder attackransomware18 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALunder attackransomware18 Dec 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack17 Dec 2021
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack16 Dec 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
initial-access
CVE-2021-45046CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack13 Dec 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
local
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42287HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42287HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42287HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
previouspage 204 / 274next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.