Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
13,946 exploits
GitHub PoC68
CVE-2021-38647 - POC to exploit unauthenticated RCE #OMIGOD
CVE-2021-38647CRITICALunder attackransomware20 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
GitHub PoC102
Modified code so that we don´t need to rely on CAB archives
CVE-2021-40444HIGHunder attackransomware19 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
OMIGod / CVE-2021-38647 POC and Demo environment
CVE-2021-38647CRITICALunder attackransomware19 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Modifed ver of the original exploit to save some times on password reseting for unprivileged user
CVE-2021-2291119 Sep 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
GitHub PoC1
Converted Metasploit exploits for Adobe Flash vulnerabilities CVE-2015-3090, CVE-2015-3105, CVE-2015-5119, and CVE-2015-5122 to a Python3 script.
CVE-2015-309019 Sep 2021
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
60RISK
open
GitHub PoC1
A Vagrant VM test lab to learn about CVE-2021-38647 in the Open Management Infrastructure agent (aka "omigod").
CVE-2021-38647CRITICALunder attackransomware18 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
GitHub PoC11
Scan for evidence of CVE-2021-30860 (FORCEDENTRY) exploit
CVE-2021-30860HIGHunder attack18 Sep 2021
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catali
93RISK
open
GitHub PoC3
[CVE-2021-26084] Confluence pre-auth RCE test script
CVE-2021-26084CRITICALunder attackransomware18 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC2
CVE-2021-40539 POC
CVE-2021-40539CRITICALunder attackransomware17 Sep 2021
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open
GitHub PoC233
Proof on Concept Exploit for CVE-2021-38647 (OMIGOD)
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
GitHub PoC20
OMIGOD! OM I GOOD? A free scanner to detect VMs vulnerable to one of the "OMIGOD" vulnerabilities discovered by Wiz's threat research team, specifically CVE-2021-38647.
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
A PoC exploit for CVE-2021-38647 RCE in OMI
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
GitHub PoC6
CVE-2021-2456
CVE-2021-2456CRITICAL16 Sep 2021
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana
70RISK
open
GitHub PoC9
quynhle7821/CVE-2021-2302
CVE-2021-2302CRITICAL16 Sep 2021
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported
48RISK
open
GitHub PoC8
CVE-2021-38647 POC for RCE
CVE-2021-38647CRITICALunder attackransomware15 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
jaysharma786/CVE-2021-29003
CVE-2021-2900315 Sep 2021
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacter
35RISK
open
GitHub PoC10
CVE-2021-33766-poc
CVE-2021-33766HIGHunder attack15 Sep 2021
Microsoft Exchange Server Information Disclosure Vulnerability
100RISK
open
GitHub PoC5
CVE-2021-38647 AKA "OMIGOD" vulnerability in Windows OMI
CVE-2021-38647CRITICALunder attackransomware15 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
GitHub PoC824
CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit
CVE-2021-40444HIGHunder attackransomware15 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Malicious document builder for CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware14 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC19
k8gege/CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware14 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
CVE-2018-15473 Exploit
CVE-2018-15473MEDIUM14 Sep 2021
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC1
POC for CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware13 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC8
CVE-2021-40875: Tools to Inspect Gurock Testrail Servers for Vulnerabilities related to CVE-2021-40875.
CVE-2021-4087513 Sep 2021
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat ac
50RISK
open
GitHub PoC1
2021 kernel vulnerability in Ubuntu.
CVE-2021-3493HIGHunder attack12 Sep 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC
CVE-2021-21972 vCenter-6.5-7.0 RCE POC
CVE-2021-21972CRITICALunder attackransomware12 Sep 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC16
Mass exploitation of CVE-2021-24499 unauthenticated upload leading to remote code execution in Workreap theme.
CVE-2021-2449912 Sep 2021
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISK
open
GitHub PoC
W1kyri3/Exploit-PoC-CVE-2021-40444-inject-ma-doc-vao-docx
CVE-2021-40444HIGHunder attackransomware12 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC168
This repo contain builders of cab file, html file, and docx file for CVE-2021-40444 exploit
CVE-2021-40444HIGHunder attackransomware12 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Reverse engineering the "A Letter Before Court 4.docx" malicious files exploting cve-2021-40444
CVE-2021-40444HIGHunder attackransomware12 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
previouspage 359 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.