Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,294cataloged exploits
36,048CVEs with public exploitation
24,695lab-tested
78,258 exploits
GitHub PoC2
Unrestricted upload of file with dangerous type in Aviatrix allows an authenticated user to execute arbitrary code
CVE-2021-40870CRITICALunder attack08 Oct 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISK
open
Metasploit600
WordPress Plugin Pie Register Auth Bypass to RCE
CVE-2025-34077CRITICAL08 Oct 2021
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
63RISK
open
GitHub PoC3
POC
CVE-2021-41773HIGHunder attackransomware08 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
I have come-up with a POC for Payara Micro Community 5.2021.6 - Directory Traversal, Please refer above reference field.
CVE-2021-4138108 Oct 2021
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
50RISK
open
GitHub PoC16
Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file which allows an unauthenticated user to execute arbitrary code via directory traversal
CVE-2021-40870CRITICALunder attack07 Oct 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISK
open
GitHub PoC
Hattan515/POC-CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware07 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
CVE-2021-41773 exploit PoC with Docker setup.
CVE-2021-41773HIGHunder attackransomware07 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
CVE-2021-41773, poc, exploit
CVE-2021-41773HIGHunder attackransomware07 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC63
A framework for bug hunting or pentesting targeting websites that have CVE-2021-41773 Vulnerability in public
CVE-2021-41773HIGHunder attackransomware07 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
Apache HTTPd (2.4.49) – Local File Disclosure (LFI)
CVE-2021-41773HIGHunder attackransomware07 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC3
Aviatrix allows an authenticated user to execute arbitrary code
CVE-2021-40870CRITICALunder attack07 Oct 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISK
open
GitHub PoC6
CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware07 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC4
CVE-2021-41773: Path Traversal Zero-Day in Apache HTTP Server Exploited
CVE-2021-41773HIGHunder attackransomware07 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
shiomiyan/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware07 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC28
MASS CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware07 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Unrestricted upload of file with dangerous type in Aviatrix allows an authenticated user to execute arbitrary code
CVE-2021-40870CRITICALunder attack07 Oct 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware07 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-40870CRITICALunder attack07 Oct 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware07 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware07 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-40870CRITICALunder attack07 Oct 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-40870CRITICALunder attack07 Oct 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISK
open
GitHub PoC
ES File Explorer v4.1.9.7.4 Open port vulnerability exploit. CVE-2019-6447
CVE-2019-644707 Oct 2021
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open
GitHub PoC9
Exploit with integrated shodan search
CVE-2021-42013CRITICALunder attackransomware07 Oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
Exploit-DBVexDay Proof
Google SLO-Generator 2.0.0 - Code Execution
CVE-2021-22557MEDIUMlocallinux07 Oct 2021
Code execution in SLO Generator via YAML Payload
33RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack06 Oct 2021
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC5
DirtyCow root privilege escalation (CVE-2016-5195)
CVE-2016-5195HIGHunder attack06 Oct 2021
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware06 Oct 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
hh-hunter/cve-2021-24499
CVE-2021-2449906 Oct 2021
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISK
open
Exploit-DB
Atlassian Jira Server Data Center 8.16.0 - Arbitrary File Read
CVE-2021-26086MEDIUMunder attackwebappsmultiple06 Oct 2021
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RISK
open
previouspage 656 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.