Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
24,460 exploits
Exploit-DB
Microsoft Exchange 2019 - Unauthenticated Email Download
CVE-2021-26855CRITICALunder attackransomwarewebappswindows18 May 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
Microsoft Internet Explorer 8 - 'SetMouseCapture ' Use After Free
CVE-2013-3893HIGHunder attacklocalwindows17 May 2021
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 throug
100RISK
open
Exploit-DB
IPFire 2.25 - Remote Code Execution (Authenticated)
CVE-2021-33393webappscgi17 May 2021
lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It
50RISK
open
Exploit-DB
Subrion CMS 4.2.1 - Arbitrary File Upload
CVE-2018-19422webappsphp17 May 2021
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RISK
open
Exploit-DBVexDay Proof
Chamilo LMS 1.11.14 - Remote Code Execution (Authenticated)
CVE-2021-31933HIGHwebappsphp14 May 2021
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a paramete
46RISK
open
Exploit-DB
Firefox 72 IonMonkey - JIT Type Confusion
CVE-2019-17026HIGHunder attacklocalwindows_x86-6413 May 2021
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are
83RISK
open
Exploit-DB
ZeroShell 3.9.0 - Remote Command Execution
CVE-2019-12725webappslinux13 May 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
Exploit-DB
Microsoft Internet Explorer 11 and WPAD service 'Jscript.dll' - Use-After-Free
CVE-2020-0674HIGHunder attacklocalwindows_x86-6413 May 2021
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISK
open
Exploit-DB
Microweber CMS 1.1.20 - Remote Code Execution (Authenticated)
CVE-2020-28337webappsphp10 May 2021
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to g
28RISK
open
Exploit-DB
b2evolution 7-2-2 - 'cf_name' SQL Injection
CVE-2021-28242webappsphp06 May 2021
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive dat
23RISK
open
Exploit-DB
Piwigo 11.3.0 - 'language' SQL
CVE-2021-27973webappsphp03 May 2021
SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
28RISK
open
Exploit-DB
GNU Wget < 1.18 - Arbitrary File Upload (2)
CVE-2016-4971remotelinux30 Apr 2021
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RISK
open
Exploit-DB
Moodle 3.6.1 - Persistent Cross-Site Scripting (XSS)
CVE-2019-3810MEDIUMwebappsphp30 Apr 2021
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported vers
38RISK
open
Exploit-DB
Cacti 1.2.12 - 'filter' SQL Injection
CVE-2020-14295webappsphp29 Apr 2021
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RISK
open
Exploit-DB
Kirby CMS 3.5.3.1 - 'file' Cross-Site Scripting (XSS)
CVE-2021-29460HIGHwebappsphp28 Apr 2021
Cross-site scripting (XSS) from unsanitized uploaded SVG files
41RISK
open
Exploit-DB
SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (2)
CVE-2021-28419webappsphp26 Apr 2021
The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads
28RISK
open
Exploit-DB
DzzOffice 2.02.1 - 'Multiple' Cross-Site Scripting (XSS)
CVE-2021-3318webappsmultiple23 Apr 2021
attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.
23RISK
open
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-30030webappsphp22 Apr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php.
23RISK
open
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-31329webappsphp22 Apr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php
23RISK
open
Exploit-DB
CMS Made Simple 2.2.15 - 'title' Cross-Site Scripting (XSS)
CVE-2021-28935webappsphp22 Apr 2021
CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > M
23RISK
open
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-30042webappsphp22 Apr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Cont
23RISK
open
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-31327webappsphp22 Apr 2021
Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field.
23RISK
open
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-30039webappsphp22 Apr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-repo
23RISK
open
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-30034webappsphp22 Apr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php.
23RISK
open
Exploit-DB
RemoteClinic 2 - 'Multiple' Cross-Site Scripting (XSS)
CVE-2021-30044webappsphp21 Apr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php.
23RISK
open
Exploit-DB
Multilaser Router RE018 AC1200 - Cross-Site Request Forgery (Enable Remote Access)
CVE-2021-31152webappshardware21 Apr 2021
Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can ena
23RISK
open
Exploit-DB
Adtran Personal Phone Manager 10.8.1 - DNS Exfiltration
CVE-2021-25681webappshardware21 Apr 2021
AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. T
28RISK
open
Exploit-DB
Adtran Personal Phone Manager 10.8.1 - 'Multiple' Reflected Cross-Site Scripting (XSS)
CVE-2021-25680webappshardware21 Apr 2021
The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These
23RISK
open
Exploit-DB
Adtran Personal Phone Manager 10.8.1 - 'emailAddress' Stored Cross-Site Scripting (XSS)
CVE-2021-25679webappshardware21 Apr 2021
The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. T
23RISK
open
Exploit-DBVexDay Proof
GravCMS 1.10.7 - Unauthenticated Arbitrary File Write (Metasploit)
CVE-2021-21425CRITICALwebappsphp21 Apr 2021
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.