Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,697GitHub PoC 14,455VulnCheck XDB 8,811Nuclei 4,349Metasploit 3,488✓ verified onlyrecentpopularrisk
78,258 exploits
GitHub PoC
bu1xuan2/CVE-2018-15961
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open ↗GitHub PoC★ 18
A Zeek package to detect CVE-2021-42292, a Microsoft Excel local privilege escalation exploit.
Microsoft Excel Security Feature Bypass Vulnerability
83RISK
open ↗GitHub PoC★ 1
This Metasploit module exploits an unauthenticated remote code execution vulnerability which exists in Apache version 2.4.49 (CVE-2021-41773). If files outside of the document root are not protected by ‘require all denied’ and CGI has been explicitly enabled, it can be used to execute arbitrary commands. This vulnerability has been reintroduced in the Apache 2.4.50 fix (CVE-2021-42013).
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 3
VMWARE VCENTER SERVER VIRTUAL SAN HEALTH CHECK PLUG-IN RCE (CVE-2021-21985)
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open ↗GitHub PoC★ 6
faisalfs10x/GitLab-CVE-2021-22205-scanner
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗Exploit-DB
FusionPBX 4.5.29 - Remote Code Execution (RCE) (Authenticated)
An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained t
35RISK
open ↗Metasploit300
Wordpress Secure Copy Content Protection and Content Locking sccp_id Unauthenticated SQLi
Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection
60RISK
open ↗GitHub PoC★ 1
Contains the offensive (exploit and auxiliary) modules for the CVE-2021-40444.
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 15
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open ↗VulnCheck XDB
local
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2
90RISK
open ↗GitHub PoC★ 29
A sample POC for CVE-2021-30657 affecting MacOS
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2
90RISK
open ↗GitHub PoC
mmeza-developer/CVE-2019-5420-RCE
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open ↗GitHub PoC
JWT Exploit
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open ↗VulnCheck XDB
initial-access
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗GitHub PoC★ 3
Exploit for GitLab CVE-2021-22205 Unauthenticated Remote Code Execution
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗GitHub PoC
hh-hunter/cve-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗GitHub PoC★ 4
Pickle Serialization Remote Code Execution - Memcached Poisoning
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code e
48RISK
open ↗GitHub PoC★ 2
Modification of gitlab exploit anything under 13.10
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open ↗GitHub PoC★ 6
Some docker images to play with CVE-2021-41773 and CVE-2021-42013
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗VulnCheck XDB
initial-access
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗GitHub PoC
zkhalidul/GrabberWP-CVE-2017-5487
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISK
open ↗GitHub PoC
CVE-2021-22205& GitLab CE/EE RCE
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗VulnCheck XDB
remote-with-credentials
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open ↗VulnCheck XDB
initial-access
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open ↗VulnCheck XDB
infoleak
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.