Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
78,258 exploits
VulnCheck XDB
initial-access
CVE-2020-7247CRITICALunder attack26 Nov 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
GitHub PoC2
Proof of concept for CVE-2020-7247 for educational purposes.
CVE-2020-7247CRITICALunder attack26 Nov 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
VulnCheck XDB
client-side
CVE-2018-8174HIGHunder attackransomware25 Nov 2021
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware25 Nov 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
lisinan988/CVE-2019-0708-scan
CVE-2019-0708CRITICALunder attackransomware25 Nov 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
lisinan988/CVE-2017-11882-exp
CVE-2017-11882HIGHunder attackransomware25 Nov 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC3
A CVE-2021-22205 Gitlab RCE POC written in Golang
CVE-2021-22205CRITICALunder attackransomware25 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware25 Nov 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALunder attackransomware25 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALunder attackransomware25 Nov 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
lisinan988/CVE-2020-0796-exp
CVE-2020-0796CRITICALunder attackransomware25 Nov 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
lisinan988/CVE-2018-8174-exp
CVE-2018-8174HIGHunder attackransomware25 Nov 2021
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
GitHub PoC
lisinan988/CVE-2021-40444-exp
CVE-2021-40444HIGHunder attackransomware25 Nov 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Metabase GeoJSON map local file inclusion
CVE-2021-41277CRITICALunder attack24 Nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISK
open
GitHub PoC4
Vulnmachines/Metabase_CVE-2021-41277
CVE-2021-41277CRITICALunder attack23 Nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISK
open
GitHub PoC83
Microsoft Exchange Server Poc
CVE-2021-42321HIGHunder attackransomware23 Nov 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Python 3 script to identify CVE-2021-26084 via network requests.
CVE-2021-26084CRITICALunder attackransomware23 Nov 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
plugin made for LeakiX
CVE-2021-41277CRITICALunder attack23 Nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISK
open
Exploit-DB
Linux Kernel 5.1.x - 'PTRACE_TRACEME' pkexec Local Privilege Escalation (2)
CVE-2019-13272HIGHunder attacklocallinux23 Nov 2021
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42321HIGHunder attackransomware23 Nov 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42321HIGHunder attackransomware23 Nov 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack23 Nov 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
client-side
CVE-2021-33044CRITICALunder attack22 Nov 2021
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALunder attackransomware22 Nov 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41277CRITICALunder attack22 Nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1676322 Nov 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC
A write up on the THM room Vulnerability Capstone & Exploit script for CVE-2018-16763.
CVE-2018-1676322 Nov 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC
MetaBase 任意文件读取漏洞 fofa批量poc
CVE-2021-41277CRITICALunder attack22 Nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISK
open
GitHub PoC
Alexcot25051999/CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware22 Nov 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
hzshang/CVE-2021-31956
CVE-2021-31956HIGHunder attack22 Nov 2021
Windows NTFS Elevation of Privilege Vulnerability
76RISK
open
previouspage 645 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.