Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
78,056 exploits
Exploit-DB
ConnectWise Control 19.2.24707 - Username Enumeration
CVE-2019-16516remotemultiple05 Jan 2022
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumer
28RISK
open
Exploit-DB
SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS)
CVE-2021-45425webappsphp05 Jan 2022
Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScrip
23RISK
open
GitHub PoC
alexpena5635/CVE-2021-44228_scanner-main-Modified-
CVE-2021-44228CRITICALunder attackransomware05 Jan 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Exploit-DB
WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection
CVE-2021-24750webappsphp05 Jan 2022
WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection
50RISK
open
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALunder attackransomware05 Jan 2022
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
Exploit-DB
Nettmp NNT 5.1 - SQLi Authentication Bypass
CVE-2021-45814webappsphp05 Jan 2022
Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel
23RISK
open
Exploit-DB
WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read (Unauthenticated)
CVE-2021-39312HIGHwebappsphp05 Jan 2022
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISK
open
GitHub PoC
Bassmaster Plugin NodeJS RCE
CVE-2014-720504 Jan 2022
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RISK
open
GitHub PoC
the name of virus is the detection of microsoft defender, is the tipic antivirus
CVE-2017-0147HIGHunder attackransomware04 Jan 2022
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
Atmail XSS-CSRF-RCE Exploit Chain
CVE-2012-259304 Jan 2022
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote atta
23RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-2509403 Jan 2022
Tatsu < 3.3.12 - Unauthenticated RCE
60RISK
open
GitHub PoC
Log4j2 LDAP 취약점 테스트 (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware03 Jan 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC9
darkpills/CVE-2021-25094-tatsu-preauth-rce
CVE-2021-2509403 Jan 2022
Tatsu < 3.3.12 - Unauthenticated RCE
60RISK
open
GitHub PoC
the name of virus is the detection of microsoft defender, is the tipic antivirus
CVE-2012-0158HIGHunder attackransomware03 Jan 2022
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls
100RISK
open
GitHub PoC
This repository contains a Spring Boot web application vulnerable to CVE-2021-44228, known as log4shell.
CVE-2021-44228CRITICALunder attackransomware31 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware30 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Presents how to exploit CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALunder attackransomware30 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
Auerswald VoIP System Secret Backdoors -PoC
CVE-2021-4085929 Dec 2021
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web
60RISK
open
GitHub PoC
d4rk30/CVE-2017-12943
CVE-2017-1294329 Dec 2021
D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?RE
35RISK
open
VulnCheck XDB
initial-access
CVE-2020-1154629 Dec 2021
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailing
50RISK
open
GitHub PoC3
trganda/CVE-2021-22204
CVE-2021-22204MEDIUMunder attack29 Dec 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware28 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
"Lavel Exploit CVE-2018-15133 is a powerful exploit that allows attackers to gain unauthorized access to vulnerable systems. This exploit was originally developed as part of a Capture The Flag (CTF) challenge and has since been used by security researchers and ethical hackers to identify and address vulnerabilities in web applications.
CVE-2018-15133HIGHunder attack28 Dec 2021
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware28 Dec 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-15133HIGHunder attack28 Dec 2021
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC11
CVE-2019-9053 Exploit for Python 3
CVE-2019-905328 Dec 2021
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC2
Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit
CVE-2021-40444HIGHunder attackransomware28 Dec 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
A spigot plugin to fix CVE-2021-44228 Log4j remote code execution vulnerability, to protect Minecraft clients.
CVE-2021-44228CRITICALunder attackransomware28 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC209
A tool for detect&exploit vmware product log4j(cve-2021-44228) vulnerability.Support VMware HCX/vCenter/NSX/Horizon/vRealize Operations Manager
CVE-2021-44228CRITICALunder attackransomware28 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC5
Auerswald COMpact 8.0B Backdoors exploit
CVE-2021-4085928 Dec 2021
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web
60RISK
open
previouspage 622 / 2,602next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.