Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,295cataloged exploits
36,048CVEs with public exploitation
24,695lab-tested
78,258 exploits
GitHub PoC9
Path traversal in Apache HTTP Server 2.4.49 (CVE-2021-41773)
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
bypass all stages of the password reset flow
CVE-2021-27651CRITICAL05 Oct 2021
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp
75RISK
open
GitHub PoC13
Exploitation of CVE-2021-41773 a Directory Traversal in Apache 2.4.49.
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC6
Poc.py
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
Working PowerShell POC
CVE-2021-1675HIGHunder attackransomware05 Oct 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
masahiro331/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC52
iilegacyyii/PoC-CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC38
CVE-2021-41773 Path Traversal vulnerability in Apache 2.4.49.
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC17
ZephrFish/CVE-2021-41773-PoC
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC8
CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC13
Atlassian Confluence Server 7.5.1 Pre-Authorization Arbitrary File Read vulnerability (CVE-2021-26085)
CVE-2021-26085MEDIUMunder attackransomware05 Oct 2021
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Exploit-DB
Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read
CVE-2021-26085MEDIUMunder attackransomwarewebappsjava05 Oct 2021
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware05 Oct 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-26085MEDIUMunder attackransomware05 Oct 2021
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RISK
open
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware05 Oct 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC39
lorddemon/CVE-2021-41773-PoC
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Metasploit300
WordPress Plugin Perfect Survey 1.5.1 SQLi (Unauthenticated)
CVE-2021-2476205 Oct 2021
Perfect Survey < 1.5.2 - Unauthenticated SQL Injection
60RISK
open
GitHub PoC25
Atlassian Jira Server/Data Center 8.4.0 - Arbitrary File read (CVE-2021-26086)
CVE-2021-26086MEDIUMunder attack05 Oct 2021
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RISK
open
GitHub PoC1
The plugin does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly
CVE-2021-2456305 Oct 2021
Frontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting
28RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware04 Oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Opensitoo/cve-2020-0796
CVE-2020-0796CRITICALunder attackransomware04 Oct 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC2
Exploit code for CVE-2007-2447 written in Python3.
CVE-2007-244703 Oct 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC2
CVE-2018-15961 — ᴀᴅᴏʙᴇ ᴄᴏʟᴅғᴜsɪᴏɴ (ʀᴄᴇ)
CVE-2018-15961CRITICALunder attack03 Oct 2021
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware03 Oct 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC7
Proof On Concept — Pulse Secure CVE-2021-22893
CVE-2021-22893CRITICALunder attackransomware03 Oct 2021
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windo
90RISK
open
previouspage 658 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.