Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
8,213 exploits
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack25 May 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9248CRITICALunder attack24 May 2021
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-11978HIGHunder attack22 May 2021
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was disco
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALunder attackransomware22 May 2021
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-3674922 May 2021
Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware22 May 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-1272522 May 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack21 May 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMunder attack21 May 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
VulnCheck XDB
local
CVE-2021-21551HIGHunder attack21 May 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack20 May 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-7238CRITICALunder attack20 May 2021
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack19 May 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack19 May 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2021-300718 May 2021
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead
60RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack18 May 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-908117 May 2021
20RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack17 May 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack16 May 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-949613 May 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
VulnCheck XDB
local
CVE-2021-21551HIGHunder attack13 May 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISK
open
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMunder attack12 May 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMunder attack11 May 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3046111 May 2021
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISK
open
VulnCheck XDB
initial-access
CVE-2020-881311 May 2021
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack10 May 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack09 May 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALunder attackransomware09 May 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-949607 May 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-3046107 May 2021
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISK
open
previouspage 220 / 274next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.