Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
78,258 exploits
Exploit-DB
WordPress Plugin WPSchoolPress 2.1.16 - 'Multiple' Cross Site Scripting (XSS)
CVE-2021-24664webappsphp15 Nov 2021
WPSchoolPress < 2.1.17 - Multiple Admin+ Stored Cross-Site Scripting
23RISK
open
GitHub PoC1
poc for CVE-2020-2555
CVE-2020-2555CRITICALunder attack15 Nov 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-4045CRITICAL15 Nov 2021
TP-LINK Tapo C200 remote code execution vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2020-2555CRITICALunder attack15 Nov 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
GitHub PoC3
Repo demonstrating CVE-2021-43616 / https://github.com/npm/cli/issues/2701
CVE-2021-43616CRITICAL15 Nov 2021
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in pack
48RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware15 Nov 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Exploit-DB
PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF)
CVE-2021-43617webappsphp15 Nov 2021
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val
28RISK
open
VulnCheck XDB
initial-access
CVE-2017-17562HIGHunder attack14 Nov 2021
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open
GitHub PoC
xMohamed0/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware14 Nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
xMohamed0/CVE-2021-21315-POC
CVE-2021-21315HIGHunder attack14 Nov 2021
Command Injection Vulnerability
100RISK
open
GitHub PoC1
kubota/POC-CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware14 Nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
xMohamed0/CVE-2021-42013-ApacheRCE
CVE-2021-42013CRITICALunder attackransomware14 Nov 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC1
xMohamed0/CVE-2020-5504-phpMyAdmin
CVE-2020-550414 Nov 2021
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could
35RISK
open
GitHub PoC8
Exploit for CVE-2017-17562 vulnerability, that allows RCE on GoAhead (< v3.6.5) if the CGI is enabled and a CGI program is dynamically linked.
CVE-2017-17562HIGHunder attack14 Nov 2021
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALunder attack13 Nov 2021
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
VulnCheck XDB
client-side
CVE-2021-22205CRITICALunder attackransomware13 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC
Python script to exploit webmin vulnerability cve-2006-3392
CVE-2006-339213 Nov 2021
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISK
open
GitHub PoC1
Реализация использования уязвимости Moodle CVE-2014-3544.
CVE-2014-354412 Nov 2021
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before
23RISK
open
GitHub PoC1
CppXL/cve-2021-40449-poc
CVE-2021-40449HIGHunder attackransomware12 Nov 2021
Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
CVE-2021-3560 (Polkit - Local Privilege Escalation)
CVE-2021-3560HIGHunder attack12 Nov 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC237
GitLab CE/EE Preauth RCE using ExifTool
CVE-2021-22205CRITICALunder attackransomware11 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
Exploit-DB
FormaLMS 2.4.4 - Authentication Bypass
CVE-2021-43136webappsmultiple11 Nov 2021
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain
28RISK
open
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
CVE-2021-42013CRITICALunder attackransomwarewebappsmultiple11 Nov 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
CVE-2021-41773HIGHunder attackransomwarewebappsmultiple11 Nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
On the 11/11/21 the apache 2.4.49-2.4.50 remote command execution POC has been published online and this is a loader so that you can mass exploit servers using this.
CVE-2021-41773HIGHunder attackransomware11 Nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Ce programme permet de détecter une faille RCE sur les serveurs Apache 2.4.49 et Apache 2.4.50
CVE-2021-41773HIGHunder attackransomware11 Nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALunder attackransomware11 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC
Dockerized Proof-of-Concept of CVE-2021-40438 in Apache 2.4.48.
CVE-2021-40438CRITICALunder attackransomware11 Nov 2021
mod_proxy SSRF
100RISK
open
GitHub PoC
bu1xuan2/CVE-2018-15961
CVE-2018-15961CRITICALunder attack10 Nov 2021
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open
GitHub PoC1
rust noob tried write easy exploit code with rust lang
CVE-2021-21315HIGHunder attack10 Nov 2021
Command Injection Vulnerability
100RISK
open
previouspage 647 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.