Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
8,198 exploits
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware05 Oct 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-26085MEDIUMunder attackransomware05 Oct 2021
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RISK
open
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware05 Oct 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware04 Oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-15961CRITICALunder attack03 Oct 2021
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware03 Oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware03 Oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware03 Oct 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALunder attackransomware02 Oct 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-34523CRITICALunder attackransomware02 Oct 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-35211CRITICALunder attackransomware30 Sep 2021
Serv-U Remote Memory Escape Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34730CRITICAL30 Sep 2021
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerability
53RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack28 Sep 2021
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALunder attackransomware28 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware27 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware27 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1676327 Sep 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware27 Sep 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware26 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware26 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware26 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALunder attackransomware26 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-34527HIGHunder attackransomware26 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-22005CRITICALunder attackransomware25 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware24 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-33739HIGHunder attack24 Sep 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RISK
open
previouspage 211 / 274next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.