Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,947VulnCheck XDB 8,542Nuclei 4,243Metasploit 3,468✓ verified onlyrecentpopularrisk
13,947 exploits
GitHub PoC★ 1
2021 kernel vulnerability in Ubuntu.
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗GitHub PoC
Hunting CVE-2018-13379
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open ↗GitHub PoC
Strapi Remote Code Execution
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open ↗GitHub PoC★ 4
fengjixuchui/CVE-2021-40444-docx-Generate
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
sbladiamond/CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open ↗GitHub PoC
KnoooW/CVE-2021-40444-docx-Generate
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 11
A malicious .cab creation tool for CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1,743
CVE-2021-40444 PoC
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
CVE-2021-40444 Sample
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
koharin/CVE-2020-0041
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISK
open ↗GitHub PoC
Confluence OGNL injection
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open ↗GitHub PoC★ 3
CVE-2020-9054 PoC for Zyxel
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
100RISK
open ↗GitHub PoC★ 16
rfcxv/CVE-2021-40444-POC
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 3
maguireja/CVE-2020-25223
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISK
open ↗GitHub PoC
Immersive-Labs-Sec/cve-2021-40444-analysis
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 3
vysecurity/CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
Something I wrote for CVE-2019-15107, a Webmin backdoor
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open ↗GitHub PoC★ 1
CVE-2021-26084 patch as provided in "Confluence Security Advisory - 2021-08-25"
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open ↗GitHub PoC★ 2
Exploit chain for CVE-2019-9791 & CVE-2019-11708 against firefox 65.0 on windows 64bit
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects w
28RISK
open ↗GitHub PoC★ 16
Microsoft MSHTML Remote Code Execution Vulnerability CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 2
Patched Confluence 7.12.2 (CVE-2021-26084)
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open ↗GitHub PoC★ 1
Modified Verion of CVE-2016-0792
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RISK
open ↗GitHub PoC★ 1
A quick and dirty PoC of cve-2021-26084 as none of the existing ones worked for me.
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open ↗GitHub PoC★ 30
Atlassian Confluence CVE-2021-26084 one-liner mass checker
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open ↗GitHub PoC★ 5
A vulnerability can allow an attacker to guess the automatically generated development mode secret token.
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open ↗GitHub PoC
Confluence OGNL Injection [CVE-2021-26084].
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RISK
open ↗GitHub PoC
BabyTeam1024/cve-2018-2628
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.