Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
78,137 exploits
VulnCheck XDB
client-side
CVE-2021-21972CRITICALunder attackransomware09 Dec 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
Metasploit600
Microsoft Exchange Server ChainedSerializationBinder RCE
CVE-2022-23277HIGH09 Dec 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
48RISK
open
VulnCheck XDB
initial-access
CVE-2018-120709 Dec 2021
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RISK
open
Metasploit600
Microsoft Exchange Server ChainedSerializationBinder RCE
CVE-2021-42321HIGHunder attackransomware09 Dec 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Metasploit300
Log4Shell HTTP Scanner
CVE-2021-44228CRITICALunder attackransomware09 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
update to Daniele Scanu's SQL Injection Exploit - CVE-2019-9053
CVE-2019-905309 Dec 2021
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC2
CVE-2021-43798Exp多线程批量验证脚本
CVE-2021-43798HIGHunder attack09 Dec 2021
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware09 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
CVE-2021-27928-POC
CVE-2021-2792809 Dec 2021
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RISK
open
Exploit-DB
Student Management System 1.0 - SQLi Authentication Bypass
CVE-2020-23935webappsphp09 Dec 2021
Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (
28RISK
open
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALunder attackransomware08 Dec 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44077CRITICALunder attack08 Dec 2021
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack08 Dec 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC
RamPanic/CVE-2019-19609-EXPLOIT
CVE-2019-1960908 Dec 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
VulnCheck XDB
initial-access
CVE-2019-1960908 Dec 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
GitHub PoC4
s1gh/CVE-2021-43798
CVE-2021-43798HIGHunder attack08 Dec 2021
Grafana path traversal
100RISK
open
GitHub PoC1
CVE-2021-43798-Grafana任意文件读取漏洞
CVE-2021-43798HIGHunder attack08 Dec 2021
Grafana path traversal
100RISK
open
GitHub PoC17
grafana CVE-2021-43798任意文件读取漏洞POC,采用多插件轮训检测的方法,允许指定单URL和从文件中读取URL
CVE-2021-43798HIGHunder attack08 Dec 2021
Grafana path traversal
100RISK
open
GitHub PoC36
Proof of Concept Exploit for ManageEngine ServiceDesk Plus CVE-2021-44077
CVE-2021-44077CRITICALunder attack08 Dec 2021
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RISK
open
GitHub PoC
Grafana File-Read Vuln
CVE-2021-43798HIGHunder attack08 Dec 2021
Grafana path traversal
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack08 Dec 2021
Grafana path traversal
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack08 Dec 2021
Grafana path traversal
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack07 Dec 2021
Grafana path traversal
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack07 Dec 2021
Grafana path traversal
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack07 Dec 2021
Grafana path traversal
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack07 Dec 2021
Grafana path traversal
100RISK
open
GitHub PoC6
利用grafan CVE-2021-43798任意文件读漏洞,自动探测是否有漏洞、存在的plugin、提取密钥、解密server端db文件,并输出data_sourrce信息。
CVE-2021-43798HIGHunder attack07 Dec 2021
Grafana path traversal
100RISK
open
GitHub PoC270
A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key / decrypt data_source info automatic.
CVE-2021-43798HIGHunder attack07 Dec 2021
Grafana path traversal
100RISK
open
GitHub PoC27
Grafana Arbitrary File Reading Vulnerability
CVE-2021-43798HIGHunder attack07 Dec 2021
Grafana path traversal
100RISK
open
GitHub PoC24
CVE-2021-43798:Grafana 任意文件读取漏洞
CVE-2021-43798HIGHunder attack07 Dec 2021
Grafana path traversal
100RISK
open
previouspage 640 / 2,605next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.