Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
78,137 exploits
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack10 Dec 2021
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-12617HIGHunder attack10 Dec 2021
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack10 Dec 2021
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC195
Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
racoon-rac/CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
wheezysec/CVE-2021-44228-kusto
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC7
CVE-2021-44228 DFIR Notes
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
CVE-2017-12617 is a critical vulnerability leading to Remote Code Execution (RCE) in Apache Tomcat.
CVE-2017-12617HIGHunder attack10 Dec 2021
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
GitHub PoC
varppi/CVE-2012-2982
CVE-2012-298210 Dec 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
GitHub PoC
log4shell sample application (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Mitigation for Log4Shell Security Vulnerability CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC5
A Java Agent that disables Apache Log4J's JNDI Lookup to mitigate CVE-2021-44228 ("Log4Shell").
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
CVE-2021-43798Exp多线程批量验证脚本
CVE-2021-43798HIGHunder attack09 Dec 2021
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware09 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-120709 Dec 2021
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RISK
open
VulnCheck XDB
client-side
CVE-2021-21972CRITICALunder attackransomware09 Dec 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC
update to Daniele Scanu's SQL Injection Exploit - CVE-2019-9053
CVE-2019-905309 Dec 2021
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC89
Apache Log4j 远程代码执行
CVE-2021-44228CRITICALunder attackransomware09 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC17
Exploit iDRAC 7 & 8 firmware < 2.52.52.52
CVE-2018-120709 Dec 2021
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RISK
open
GitHub PoC1
CVE-2021-27928-POC
CVE-2021-2792809 Dec 2021
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RISK
open
GitHub PoC5
Simple program for exploit grafana
CVE-2021-43798HIGHunder attack09 Dec 2021
Grafana path traversal
100RISK
open
GitHub PoC19
Patch up CVE-2021-44228 for minecraft forge 1.7.10 - 1.12.2
CVE-2021-44228CRITICALunder attackransomware09 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC9
Grafana-POC任意文件读取漏洞(CVE-2021-43798)
CVE-2021-43798HIGHunder attack09 Dec 2021
Grafana path traversal
100RISK
open
Exploit-DB
Grafana 8.3.0 - Directory Traversal and Arbitrary File Read
CVE-2021-43798HIGHunder attackwebappsmultiple09 Dec 2021
Grafana path traversal
100RISK
open
previouspage 639 / 2,605next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.