Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,697GitHub PoC 14,455VulnCheck XDB 8,811Nuclei 4,349Metasploit 3,488✓ verified onlyrecentpopularrisk
78,258 exploits
Exploit-DB
WordPress Plugin WPSchoolPress 2.1.16 - 'Multiple' Cross Site Scripting (XSS)
WPSchoolPress < 2.1.17 - Multiple Admin+ Stored Cross-Site Scripting
23RISK
open ↗GitHub PoC★ 1
poc for CVE-2020-2555
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open ↗GitHub PoC★ 3
Repo demonstrating CVE-2021-43616 / https://github.com/npm/cli/issues/2701
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in pack
48RISK
open ↗VulnCheck XDB
denial-of-service
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open ↗Exploit-DB
PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF)
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val
28RISK
open ↗VulnCheck XDB
initial-access
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open ↗GitHub PoC
xMohamed0/CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 1
kubota/POC-CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC
xMohamed0/CVE-2021-42013-ApacheRCE
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗GitHub PoC★ 1
xMohamed0/CVE-2020-5504-phpMyAdmin
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could
35RISK
open ↗GitHub PoC★ 8
Exploit for CVE-2017-17562 vulnerability, that allows RCE on GoAhead (< v3.6.5) if the CGI is enabled and a CGI program is dynamically linked.
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open ↗VulnCheck XDB
initial-access
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open ↗VulnCheck XDB
client-side
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗GitHub PoC
Python script to exploit webmin vulnerability cve-2006-3392
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISK
open ↗GitHub PoC★ 1
Реализация использования уязвимости Moodle CVE-2014-3544.
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before
23RISK
open ↗GitHub PoC
CVE-2021-3560 (Polkit - Local Privilege Escalation)
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open ↗GitHub PoC★ 237
GitLab CE/EE Preauth RCE using ExifTool
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗Exploit-DB
FormaLMS 2.4.4 - Authentication Bypass
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain
28RISK
open ↗Exploit-DB✓ VexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗Exploit-DB✓ VexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 2
On the 11/11/21 the apache 2.4.49-2.4.50 remote command execution POC has been published online and this is a loader so that you can mass exploit servers using this.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC
Ce programme permet de détecter une faille RCE sur les serveurs Apache 2.4.49 et Apache 2.4.50
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗VulnCheck XDB
initial-access
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗GitHub PoC
Dockerized Proof-of-Concept of CVE-2021-40438 in Apache 2.4.48.
mod_proxy SSRF
100RISK
open ↗GitHub PoC
bu1xuan2/CVE-2018-15961
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open ↗GitHub PoC★ 1
rust noob tried write easy exploit code with rust lang
Command Injection Vulnerability
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.