Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
13,947 exploits
GitHub PoC9
CutePHP Cute News 2.1.2 RCE PoC
CVE-2019-1144718 Mar 2021
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
GitHub PoC
Exploit Code for CVE-2019-11447 aka CuteNews 2.1.2 Avatar upload RCE (Authenticated)
CVE-2019-1144717 Mar 2021
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
GitHub PoC51
This is a Poc for BIGIP iControl unauth RCE
CVE-2021-22986CRITICALunder attackransomware17 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC124
ProxyLogon(CVE-2021-26855+CVE-2021-27065) Exchange Server RCE(SSRF->GetWebShell)
CVE-2021-26855CRITICALunder attackransomware17 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC4
CVE-2021-26855 proxyLogon metasploit exploit script
CVE-2021-26855CRITICALunder attackransomware17 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC33
ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin. We have also chained this bug with another post-auth arbitrary-file-write vulnerability, CVE-2021-27065, to get code execution.
CVE-2021-26855CRITICALunder attackransomware16 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
Chaining CVE-2021-26855 and CVE-2021-26857 to exploit Microsoft Exchange
CVE-2021-26855CRITICALunder attackransomware16 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
automate me!
CVE-2021-21973MEDIUMunder attack16 Mar 2021
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of UR
100RISK
open
GitHub PoC6
Mr-xn/CVE-2021-26855-d
CVE-2021-26855CRITICALunder attackransomware15 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC803
Sudo Baron Samedit Exploit
CVE-2021-3156HIGHunder attack15 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC28
CVE-2021-26855 & CVE-2021-27065
CVE-2021-26855CRITICALunder attackransomware15 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC4
patched to work
CVE-2021-26855CRITICALunder attackransomware15 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC22
RCE exploit for Microsoft Exchange Server (CVE-2021-26855).
CVE-2021-26855CRITICALunder attackransomware14 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Exploit Samba
CVE-2007-244714 Mar 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC9
RCE exploit for ProxyLogon vulnerability in Microsoft Exchange
CVE-2021-26855CRITICALunder attackransomware14 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC30
CVE-2021-26855: PoC (Not a HoneyPoC for once!)
CVE-2021-26855CRITICALunder attackransomware14 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
vonderchild/CVE-2016-3088
CVE-2016-3088CRITICALunder attack12 Mar 2021
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC
Will write a python script for exploiting this vulnerability
CVE-2020-25213CRITICALunder attack12 Mar 2021
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
GitHub PoC3
Scanner and PoC for CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware12 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC61
PoC of proxylogon chain SSRF(CVE-2021-26855) to write file by testanull, censored by github
CVE-2021-26855CRITICALunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC5
Apache ActiveMQ Remote Code Execution Exploit
CVE-2016-3088CRITICALunder attack11 Mar 2021
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC5
CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065
CVE-2021-26855CRITICALunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC12
CVE-2021-26855, also known as Proxylogon, is a server-side request forgery (SSRF) vulnerability in Exchange that allows an attacker to send arbitrary HTTP requests and authenticate as the Exchange server.
CVE-2021-26855CRITICALunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC111
proxylogon exploit - CVE-2021-26857
CVE-2021-26857HIGHunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
93RISK
open
GitHub PoC1,077
Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-UltraVires/Redis-Unauthorized-RCE/TDOA-V11.7-GetOnlineCookie/VMware-vCenter-GetAnyFile/yongyou-GRP-U8-XXE/Oracle-WebLogic-CVE-2020-14883/Oracle-WebLogic-CVE-2020-14882/Apache-Solr-GetAnyFile/F5-BIG-IP-CVE-2021-22986/Sonicwall-SSL-VPN-RCE/GitLab-Graphql-CNVD-2021-14193/D-Link-DCS-CVE-2020-25078/WLAN-AP-WEA453e-RCE/360TianQing-Unauthorized/360TianQing-SQLinjection/FanWeiOA-V8-SQLinjection/QiZhiBaoLeiJi-AnyUserLogin/QiAnXin-WangKangFirewall-RCE/金山-V8-终端安全系统/NCCloud-SQLinjection/ShowDoc-RCE
CVE-2020-14883HIGHunder attack11 Mar 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC53
alt3kx/CVE-2021-26855_PoC
CVE-2021-26855CRITICALunder attackransomware10 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC17
PoC exploit code for CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware09 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC100
h4x0r-dz/CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware09 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
oneoy/CVE-2021-1732-Exploit
CVE-2021-1732HIGHunder attackransomware09 Mar 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
This script test the CVE-2021-26855 vulnerability on Exchange Server.
CVE-2021-26855CRITICALunder attackransomware09 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
previouspage 376 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.