Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,558cataloged exploits
34,977CVEs with public exploitation
24,695lab-tested
13,947 exploits
GitHub PoC
Abdennour-py/CVE-2021-3493
CVE-2021-3493HIGHunder attack02 May 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC
DXY0411/CVE-2020-23342
CVE-2020-2334202 May 2021
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
28RISK
open
GitHub PoC1
Completed a working exploit for CVE-2018-17463 for fun.
CVE-2018-17463HIGHunder attack02 May 2021
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RISK
open
GitHub PoC
CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow
CVE-2009-018201 May 2021
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RISK
open
GitHub PoC2
Confluence unauthorize template injection
CVE-2019-3396CRITICALunder attackransomware01 May 2021
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC
CVE-2003-0264 SLMail5.5_RemoteBufferOverflow
CVE-2003-026401 May 2021
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISK
open
GitHub PoC3
vsftpd 2.3.4 Backdoor Exploit
CVE-2011-252301 May 2021
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC
Drupal Drupal 8.6.x RCE Exploit
CVE-2019-6340HIGHunder attack01 May 2021
Drupal core - Highly critical - Remote Code Execution
100RISK
open
GitHub PoC7
Apache OFBiz unsafe deserialization of XMLRPC arguments
CVE-2020-949630 Apr 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
GitHub PoC
lvyoshino/CVE-2018-4878
CVE-2018-4878HIGHunder attackransomware30 Apr 2021
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open
GitHub PoC17
Moodle (< 3.6.2, < 3.5.4, < 3.4.7, < 3.1.16) XSS PoC for Privilege Escalation (Student to Admin)
CVE-2019-3810MEDIUM29 Apr 2021
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported vers
38RISK
open
GitHub PoC225
CVE-2021-3156 - Sudo Baron Samedit
CVE-2021-3156HIGHunder attack29 Apr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC2
Authenticated SQL injection to command execution on Cacti 1.2.12
CVE-2020-1429528 Apr 2021
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RISK
open
GitHub PoC1
PoC for CVE-2018-13382, never successfully tested so swim at your own risk
CVE-2018-13382CRITICALunder attackransomware28 Apr 2021
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISK
open
GitHub PoC1
streghstreek/CVE-2020-1938
CVE-2020-1938CRITICALunder attack27 Apr 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC10
lsw29475/CVE-2018-8611
CVE-2018-8611HIGHunder attack27 Apr 2021
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RISK
open
GitHub PoC1
CVE-2019-12725 ZeroShell 远程命令执行漏洞
CVE-2019-1272527 Apr 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
GitHub PoC31
Read my blog for more info -
CVE-2021-1732HIGHunder attackransomware25 Apr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
edsonjt81/sudo-cve-2019-18634
CVE-2019-1863425 Apr 2021
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open
GitHub PoC
edsonjt81/CVE-2019-14287-
CVE-2019-1428725 Apr 2021
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC1
rebuild cve
CVE-2021-329125 Apr 2021
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
28RISK
open
GitHub PoC2
b1tg/CVE-2018-6065-exploit
CVE-2018-6065HIGHunder attack24 Apr 2021
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISK
open
GitHub PoC66
CVE-2021-1732 poc & exp; tested on 20H2
CVE-2021-1732HIGHunder attackransomware23 Apr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC8
Automated tool to exploit sharepoint CVE-2019-0604
CVE-2019-0604CRITICALunder attackransomware22 Apr 2021
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISK
open
GitHub PoC
itssmikefm/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware22 Apr 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC13
CVE-2021-22192
CVE-2021-22192CRITICAL22 Apr 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticat
53RISK
open
GitHub PoC3
POC exploit for CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware22 Apr 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC3
oneoy/CVE-2021-3493
CVE-2021-3493HIGHunder attack22 Apr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC8
Exploiting a Cross-site request forgery (CSRF) attack to creat a new privileged user through the Webmin's add users feature
CVE-2021-3176221 Apr 2021
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users fea
23RISK
open
GitHub PoC1
Exploiting a Cross-site request forgery (CSRF) attack to creat a new privileged user through the Webmin's add users feature
CVE-2021-3176221 Apr 2021
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users fea
23RISK
open
previouspage 372 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.