Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
78,056 exploits
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware26 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware26 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware26 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware26 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware26 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware26 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware26 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC5
discordianfish/cve-2022-0185-crash-poc
CVE-2022-0185HIGHunder attack26 Jan 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISK
open
GitHub PoC1,158
PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)
CVE-2021-4034HIGHunder attackransomware26 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC1
统信UOS 桌面操作系统,存在CVE-2021-4034漏洞(Linux Polkit本地权限提升漏洞)。
CVE-2021-4034HIGHunder attackransomware26 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC20
dadvlingd/CVE-2021-4034
CVE-2021-4034HIGHunder attackransomware26 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC12
CVE-2021-4034 POC and Docker and Analysis write up
CVE-2021-4034HIGHunder attackransomware26 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC1,327
Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
CVE-2021-4034HIGHunder attackransomware26 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC3
PoC for cve-2021-4034
CVE-2021-4034HIGHunder attackransomware26 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
Metasploit600
Spring Cloud Gateway Remote Code Execution
CVE-2022-22947CRITICALunder attack26 Jan 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
Metasploit600
GLPI htmLawed php command injection
CVE-2022-35914CRITICALunder attack26 Jan 2022
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
GitHub PoC8
This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists of embedded payload. The exploit was made public as CVE-2010-1240.
CVE-2010-124026 Jan 2022
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISK
open
GitHub PoC46
numanturle/CVE-2022-0332
CVE-2022-033225 Jan 2022
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web serv
35RISK
open
VulnCheck XDB
infoleak
CVE-2022-21371HIGH25 Jan 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISK
open
GitHub PoC2,043
CVE-2021-4034 1day
CVE-2021-4034HIGHunder attackransomware25 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
client-side
CVE-2019-573625 Jan 2022
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware25 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware25 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC27
Oracle WebLogic Server 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 Local File Inclusion
CVE-2022-21371HIGH25 Jan 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISK
open
Metasploit600
Local Privilege Escalation in polkits pkexec
CVE-2021-4034HIGHunder attackransomware25 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
Exploit-DB
PHPIPAM 1.4.4 - SQLi (Authenticated)
CVE-2022-23046webappsphp25 Jan 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISK
open
VulnCheck XDB
info-leak
CVE-2021-39312HIGH24 Jan 2022
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISK
open
GitHub PoC
Exploit-WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read
CVE-2021-39312HIGH24 Jan 2022
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISK
open
GitHub PoC2
Strapi CMS 3.0.0-beta.17.4 - Unauthenticated Remote Code Execution (CVE-2019-18818, CVE-2019-19609)
CVE-2019-1960923 Jan 2022
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
GitHub PoC28
CVE-2022-21907 Vulnerability PoC
CVE-2022-21907CRITICAL23 Jan 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
previouspage 618 / 2,602next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.