Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
13,947 exploits
GitHub PoC9
HiveNightmare a.k.a. SeriousSam Local Privilege Escalation in Windows – CVE-2021-36934
CVE-2021-36934HIGHunder attack22 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC1
A capability to identify and remediate CVE-2021-36934 (HiveNightmare)
CVE-2021-36934HIGHunder attack22 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC1
CVE-2021-36934 PowerShell Fix
CVE-2021-36934HIGHunder attack22 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC9
Fix for the CVE-2021-36934
CVE-2021-36934HIGHunder attack21 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC5
Detection and Mitigation script for CVE-2021-36934 (HiveNightmare aka. SeriousSam)
CVE-2021-36934HIGHunder attack21 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC210
Pure Nim implementation for exploiting CVE-2021-36934, the SeriousSAM local privilege escalation
CVE-2021-36934HIGHunder attack20 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC1
Winter3un/CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware20 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
h3x0v3rl0rd/CVE-2019-16278
CVE-2019-16278CRITICALunder attack19 Jul 2021
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC3
h3x0v3rl0rd/CVE-2019-9053
CVE-2019-905318 Jul 2021
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC
systeminformation
CVE-2021-21315HIGHunder attack18 Jul 2021
Command Injection Vulnerability
100RISK
open
GitHub PoC
zha0/Microsoft-CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware18 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
CVE-2021-3493 Ubuntu漏洞
CVE-2021-3493HIGHunder attack16 Jul 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC
thalpius/microsoft-cve-2021-1675
CVE-2021-1675HIGHunder attackransomware16 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
1stPeak/CVE-2019-2725-environment
CVE-2019-2725HIGHunder attackransomware16 Jul 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC14
CVE-2021-22555 Exploit
CVE-2021-22555HIGHunder attack16 Jul 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
GitHub PoC4
cgwalters/container-cve-2021-22555
CVE-2021-22555HIGHunder attack16 Jul 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
GitHub PoC5
h3x0v3rl0rd/CVE-2017-7269
CVE-2017-7269CRITICALunder attack16 Jul 2021
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC1
h3x0v3rl0rd/CVE-2009-2265
CVE-2009-226515 Jul 2021
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISK
open
GitHub PoC1
JoneyJunior/cve-2021-22555
CVE-2021-22555HIGHunder attack15 Jul 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
GitHub PoC1
1stPeak/CVE-2020-0796-Scanner
CVE-2020-0796CRITICALunder attackransomware14 Jul 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
Wordpress Most Popular Post plugin vuln
CVE-2021-42362HIGH14 Jul 2021
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RISK
open
GitHub PoC
TheWay-hue/CVE-2017-5689-Checker
CVE-2017-5689CRITICALunder attack14 Jul 2021
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RISK
open
GitHub PoC
Cve-2021-1675 or cve-2021-34527? Detailed analysis and exploitation of windows print spooler 0day vulnerability!!!
CVE-2021-34527HIGHunder attackransomware13 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
A patch for PrintNightmare vulnerability that occurs to print spooler service for Windows machines [CVE-2021-34527]
CVE-2021-34527HIGHunder attackransomware12 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
h3x0v3rl0rd/CVE-2015-1635
CVE-2015-1635CRITICALunder attack12 Jul 2021
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
GitHub PoC
CVE-2021-1675 / CVE-2021-34527 - PrintNightmare Python, C# and PowerShell Exploits Implementations (LPE & RCE)
CVE-2021-1675HIGHunder attackransomware12 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
h3x0v3rl0rd/CVE-2015-1635-POC
CVE-2015-1635CRITICALunder attack12 Jul 2021
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
GitHub PoC15
k8gege/cve-2021-1675
CVE-2021-1675HIGHunder attackransomware11 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
cve-2021-21985 powershell poc
CVE-2021-21985CRITICALunder attackransomware11 Jul 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC1
Scanner for CVE-2020-1938
CVE-2020-1938CRITICALunder attack11 Jul 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
previouspage 365 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.