Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
78,056 exploits
GitHub PoC
Kayky-cmd/CVE-2019-6447--.
CVE-2019-644703 Feb 2022
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open
GitHub PoC1
Apache HTTP Server 2.4.50 - RCE Lab
CVE-2021-42013CRITICALunder attackransomware03 Feb 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC196
L4ys/CVE-2022-21882
CVE-2022-21882HIGHunder attackransomware03 Feb 2022
Win32k Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware03 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
Exploit-DB
WordPress Plugin Domain Check 1.0.16 - Reflected Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-24926webappsphp02 Feb 2022
Domain Check < 1.0.17 - Reflected Cross-Site Scripting
43RISK
open
Exploit-DB
WordPress Plugin Product Slider for WooCommerce 1.13.21 - Cross Site Scripting (XSS)
CVE-2021-24300webappsphp02 Feb 2022
PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)
43RISK
open
Exploit-DB
WordPress Plugin Contact Form Check Tester 1.0.2 - Broken Access Control
CVE-2021-24247webappsphp02 Feb 2022
Contact Form Check Tester <= 1.0.2 - Broken Access Control to Cross-Site Scripting (XSS)
23RISK
open
Exploit-DB
Wordpress Plugin 404 to 301 2.0.2 - SQL-Injection (Authenticated)
CVE-2015-9323webappsphp02 Feb 2022
The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
50RISK
open
Exploit-DB
WordPress Plugin Post Grid 2.1.1 - Cross Site Scripting (XSS)
CVE-2021-24488webappsphp02 Feb 2022
Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)
43RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware02 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
Exploit-DB
Wordpress Plugin Download Monitor WordPress V 4.4.4 - SQL Injection (Authenticated)
CVE-2021-24786HIGHwebappsphp02 Feb 2022
Download Monitor < 4.4.5 - Admin+ SQL Injection
61RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware02 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
Exploit-DB
WordPress Plugin Learnpress 4.1.4.1 - Arbitrary Image Renaming
CVE-2022-0377webappsphp02 Feb 2022
LearnPress < 4.1.5 - Arbitrary Image Renaming
23RISK
open
Metasploit400
Cisco RV340 SSL VPN Unauthenticated Remote Code Execution
CVE-2022-20699CRITICALunder attack02 Feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RISK
open
Exploit-DB
Chamilo LMS 1.11.14 - Account Takeover
CVE-2021-37391webappsphp02 Feb 2022
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator
23RISK
open
Exploit-DB
Moodle 3.11.4 - SQL Injection
CVE-2022-0332webappsphp02 Feb 2022
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web serv
35RISK
open
Exploit-DB
Mozilla Firefox 67 - Array.pop JIT Type Confusion
CVE-2019-11707HIGHunder attacklocalwindows02 Feb 2022
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RISK
open
Exploit-DB
PHP Unit 4.8.28 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2017-9841CRITICALunder attackwebappsphp02 Feb 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
Metasploit400
Zyxel Unauthenticated LAN Remote Code Execution
CVE-2023-28769CRITICAL01 Feb 2022
The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware v
43RISK
open
GitHub PoC8
CVE-2022-21882
CVE-2022-21882HIGHunder attackransomware01 Feb 2022
Win32k Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC
Study on Linux kernel code injection via CVE-2014-3153 (Towelroot)
CVE-2014-3153HIGHunder attack01 Feb 2022
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
Metasploit600
Zyxel chained RCE using LFI and weak password derivation algorithm
CVE-2023-28770HIGH01 Feb 2022
The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmwa
48RISK
open
GitHub PoC
qkrtjsrbs315/CVE-2013-1763
CVE-2013-176301 Feb 2022
Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows l
23RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware01 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2022-21882HIGHunder attackransomware01 Feb 2022
Win32k Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware31 Jan 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC9
CVE-2021-3560 analysis
CVE-2021-3560HIGHunder attack31 Jan 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware31 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware31 Jan 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Metasploit300
Microweber CMS v1.2.10 Local File Inclusion (Authenticated)
CVE-2025-34076MEDIUM30 Jan 2022
Microweber CMS Authenticated Local File Inclusion via Backup API
28RISK
open
previouspage 614 / 2,602next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.