Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
78,258 exploits
GitHub PoC2
Poc CVE-2021-42013 - Apache 2.4.50 without CGI
CVE-2021-42013CRITICALunder attackransomware23 Oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
Poc CVE-2021-41773 - Apache 2.4.49 with CGI enabled
CVE-2021-41773HIGHunder attackransomware23 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
cve-2021-41773.py is a python script that will help in finding Path Traversal or Remote Code Execution vulnerability in Apache 2.4.49
CVE-2021-41773HIGHunder attackransomware23 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
BabyTeam1024/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware22 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
scopion/CVE-2017-3241
CVE-2017-324122 Oct 2021
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RISK
open
Metasploit300
BillQuick Web Suite txtID SQLi
CVE-2021-42258CRITICALunder attackransomware22 Oct 2021
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution
95RISK
open
Exploit-DB
Jetty 9.4.37.v20210219 - Information Disclosure
CVE-2021-28164MEDIUMwebappsjava22 Oct 2021
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
70RISK
open
Metasploit300
Wordpress Plugin Catch Themes Demo Import RCE
CVE-2021-39352HIGH21 Oct 2021
Catch Themes Demo Import <= 1.7 Admin+ Arbitrary File Upload
48RISK
open
GitHub PoC
CVE-2021-3156 exploit
CVE-2021-3156HIGHunder attack20 Oct 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware20 Oct 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
local
CVE-2021-40449HIGHunder attackransomware20 Oct 2021
Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
LayarKacaSiber/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware20 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC98
windows 10 14393 LPE
CVE-2021-40449HIGHunder attackransomware20 Oct 2021
Win32k Elevation of Privilege Vulnerability
100RISK
open
Exploit-DB
SonicWall SMA 10.2.1.0-17sv - Password Reset
CVE-2021-20034webappshardware20 Oct 2021
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal
45RISK
open
GitHub PoC
THIS IS NOT AN ORIGINAL EXPLOIT. THIS IS AN AUDITED VERSION FOR A THM BOX
CVE-2020-10915CRITICAL20 Oct 2021
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.
85RISK
open
GitHub PoC
LayarKacaSiber/CVE-2021-42013
CVE-2021-42013CRITICALunder attackransomware20 Oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC2
Just a simple CVE-2021-31166 exploit tool
CVE-2021-31166CRITICALunder attack20 Oct 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware20 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
Exploit CVE 2021 26084 Confluence
CVE-2021-26084CRITICALunder attackransomware20 Oct 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
Exploit-DB
WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24719webappsphp19 Oct 2021
Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)
23RISK
open
VulnCheck XDB
initial-access
CVE-2019-398019 Oct 2021
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to
23RISK
open
GitHub PoC
bibo318/kali-CVE-2019-0708-lab
CVE-2019-0708CRITICALunder attackransomware19 Oct 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-21234HIGH19 Oct 2021
Directory Traversal
61RISK
open
Exploit-DB
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
CVE-2021-42565webappsmultiple19 Oct 2021
myfactory.FMS before 7.1-912 allows XSS via the UID parameter.
38RISK
open
Exploit-DB
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
CVE-2021-42566webappsmultiple19 Oct 2021
myfactory.FMS before 7.1-912 allows XSS via the Error parameter.
38RISK
open
GitHub PoC1
Exploit For CVE-2019-17662
CVE-2019-1766218 Oct 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISK
open
Exploit-DB
Plastic SCM 10.0.16.5622 - WebAdmin Server Access
CVE-2021-41382webappsmultiple18 Oct 2021
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
23RISK
open
GitHub PoC1
Lab setup for CVE-2021-41773 (Apache httpd 2.4.49) and CVE-2021-42013 (Apache httpd 2.4.50).
CVE-2021-41773HIGHunder attackransomware18 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack18 Oct 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC17
CVE-2021-36260
CVE-2021-36260CRITICALunder attack18 Oct 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
previouspage 652 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.