Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
8,198 exploits
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware24 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-30632HIGHunder attack20 Sep 2021
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware20 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2015-5122HIGHunder attack19 Sep 2021
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware19 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2015-5119HIGHunder attack19 Sep 2021
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware18 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware18 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware17 Sep 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware15 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware15 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-33766HIGHunder attack15 Sep 2021
Microsoft Exchange Server Information Disclosure Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware14 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware13 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
info-leak
CVE-2020-2865313 Sep 2021
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v
60RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware12 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware12 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack12 Sep 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack12 Sep 2021
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-1960911 Sep 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
VulnCheck XDB
infoleak
CVE-2020-25078HIGHunder attack10 Sep 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware10 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-9054CRITICALunder attack09 Sep 2021
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-5410HIGHunder attack08 Sep 2021
Directory Traversal with spring-cloud-config-server
100RISK
open
VulnCheck XDB
client-side
CVE-2019-11708CRITICALunder attack08 Sep 2021
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RISK
open
VulnCheck XDB
client-side
CVE-2021-26084CRITICALunder attackransomware08 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
previouspage 212 / 274next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.