Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
78,258 exploits
VulnCheck XDB
infoleak
CVE-2021-3674914 Oct 2021
Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)
60RISK
open
VulnCheck XDB
infoleak
CVE-2021-30858HIGHunder attack14 Oct 2021
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, m
76RISK
open
GitHub PoC2
musergi/CVE-2021-3156
CVE-2021-3156HIGHunder attack13 Oct 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
Hasintha-98/Sudo-Vulnerability-Exploit-CVE-2019-14287
CVE-2019-1428713 Oct 2021
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
VulnCheck XDB
infoleak
CVE-2020-1077013 Oct 2021
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack13 Oct 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware13 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack13 Oct 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE)
CVE-2021-42013CRITICALunder attackransomwarewebappsmultiple13 Oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-42013CRITICALunder attackransomware13 Oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC61
Tool check: CVE-2021-41773, CVE-2021-42013, CVE-2020-17519
CVE-2021-41773HIGHunder attackransomware13 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Exploit-DB
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
CVE-2020-10770webappsjava13 Oct 2021
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RISK
open
Exploit-DB
Sonicwall SonicOS 7.0 - Host Header Injection
CVE-2021-20031webappshardware13 Oct 2021
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management
43RISK
open
GitHub PoC61
Tool check: CVE-2021-41773, CVE-2021-42013, CVE-2020-17519
CVE-2020-17519CRITICALunder attack13 Oct 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
GitHub PoC8
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
CVE-2020-1077013 Oct 2021
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RISK
open
GitHub PoC51
Windows Etw LPE
CVE-2021-34486HIGHunder attack12 Oct 2021
Windows Event Tracing Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC13
hoav18/CVE-2021-22941
CVE-2021-22941CRITICALunder attackransomware12 Oct 2021
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacke
90RISK
open
GitHub PoC
nxlog ubuntu CVE-2020-35488
CVE-2020-3548812 Oct 2021
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of
23RISK
open
VulnCheck XDB
initial-access
CVE-2019-1881812 Oct 2021
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
VulnCheck XDB
local
CVE-2021-34486HIGHunder attack12 Oct 2021
Windows Event Tracing Elevation of Privilege Vulnerability
71RISK
open
Metasploit400
Win32k NtGdiResetDC Use After Free Local Privilege Elevation
CVE-2021-40449HIGHunder attackransomware12 Oct 2021
Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
critical: Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) (CVE-2021-42013)
CVE-2021-41773HIGHunder attackransomware12 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE
CVE-2021-41773HIGHunder attackransomware11 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC188
Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.
CVE-2021-33044CRITICALunder attack11 Oct 2021
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
GitHub PoC8
dongpohezui/cve-2021-33045
CVE-2021-33045CRITICALunder attack11 Oct 2021
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
GitHub PoC4
CVE-2021-41773 Grabber
CVE-2021-41773HIGHunder attackransomware11 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
rasyidfox/CVE-2019-18818
CVE-2019-1881811 Oct 2021
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
VulnCheck XDB
client-side
CVE-2021-33044CRITICALunder attack11 Oct 2021
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware11 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-1881811 Oct 2021
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
previouspage 654 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.