Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
78,258 exploits
GitHub PoC2
CVE-2018-15961 — ᴀᴅᴏʙᴇ ᴄᴏʟᴅғᴜsɪᴏɴ (ʀᴄᴇ)
CVE-2018-15961CRITICALunder attack03 Oct 2021
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open
GitHub PoC7
Proof On Concept — Pulse Secure CVE-2021-22893
CVE-2021-22893CRITICALunder attackransomware03 Oct 2021
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windo
90RISK
open
VulnCheck XDB
initial-access
CVE-2018-15961CRITICALunder attack03 Oct 2021
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open
GitHub PoC9
H0j3n/CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware03 Oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
Exploit code for CVE-2007-2447 written in Python3.
CVE-2007-244703 Oct 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC22
the metasploit script(POC/EXP) about CVE-2021-22005 VMware vCenter Server contains an arbitrary file upload vulnerability
CVE-2021-22005CRITICALunder attackransomware02 Oct 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
GitHub PoC16
POC for scanning ProxyShell(CVE-2021-34523,CVE-2021-34473,CVE-2021-31207)
CVE-2021-34523CRITICALunder attackransomware02 Oct 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC2
Exploit for CVE-2019-17662 (ThinVNC 1.0b1)
CVE-2019-1766202 Oct 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISK
open
GitHub PoC
wdjcy/CVE-2021-26084
CVE-2021-26084CRITICALunder attackransomware02 Oct 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-34523CRITICALunder attackransomware02 Oct 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
puckiestyle/CVE-2021-3493
CVE-2021-3493HIGHunder attack02 Oct 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALunder attackransomware02 Oct 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
Metasploit600
ManageEngine ADAudit Plus Authenticated File Write RCE
CVE-2021-4284701 Oct 2021
Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.
40RISK
open
Exploit-DB
WhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS)
CVE-2021-41318webappsmultiple01 Oct 2021
In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input.
23RISK
open
GitHub PoC12
PoC for CVE-2021-3129 (Laravel)
CVE-2021-3129CRITICALunder attackransomware01 Oct 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC1
daletoniris/CVE-2021-22555-esc-priv
CVE-2021-22555HIGHunder attack01 Oct 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
GitHub PoC
CloudMe CVE-2018-6892 POC
CVE-2018-689201 Oct 2021
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISK
open
GitHub PoC1
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for authentication is stored in cleartext in a file that can be read via a ../../ThinVnc.ini directory traversal attack vector.
CVE-2019-1766201 Oct 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISK
open
GitHub PoC12
Simple Serv-U CVE-2021-35211 PoC
CVE-2021-35211CRITICALunder attackransomware30 Sep 2021
Serv-U Remote Memory Escape Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34730CRITICAL30 Sep 2021
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerability
53RISK
open
GitHub PoC28
Cisco RV110w UPnP stack overflow
CVE-2021-34730CRITICAL30 Sep 2021
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerability
53RISK
open
VulnCheck XDB
initial-access
CVE-2021-35211CRITICALunder attackransomware30 Sep 2021
Serv-U Remote Memory Escape Vulnerability
100RISK
open
GitHub PoC
CVE-2021-25162
CVE-2021-2516229 Sep 2021
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products
28RISK
open
GitHub PoC
漏洞复现与poc收集,CVE-2021-21975,cve-2021-22005,CVE-2021-26295,VMware vCenter任意文件读取
CVE-2021-21975HIGHunder attackransomware29 Sep 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
Exploit-DB
WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24287webappsphp29 Sep 2021
Select All Categories and Taxonomies < 1.3.2 - Reflected Cross-Site Scripting (XSS)
43RISK
open
Exploit-DB
WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting
CVE-2021-24286webappsphp29 Sep 2021
Redirect 404 to Parent < 1.3.1 - Reflected Cross-Site Scripting (XSS)
43RISK
open
GitHub PoC5
This docx exploit uses res files inside Microsoft .docx file to execute malicious files. This exploit is related to CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware29 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
According to researchers with Rapid7, over 110,000 devices appear on internet, which run stable Samba versions, while 92,500 seem to run unstable Samba versions, for which there is no fix. The newest Samba models, including the models 4.6.x before 4.6.4, 4.5.x before 4.5.10 and 3.5.0 before 4.4.13, was impacted by this error. May 24, 2017, Samba released version 4.6.4, which fixes a serious remote code execution vulnerability, vulnerability number CVE-2017-7494, which affected Samba 3.5.0 onwards. Vulnerability number: CVE-2017-7494 Severity Rating: High Affected software: • Samba Version < 4.6.4 • Samba Version < 4.5.10 • Samba Version < 4.4.14 Unaffected software: • Samba Version = 4.6.4 • Samba Version = 4.5.10 • Samba Version = 4.4.14
CVE-2017-7494CRITICALunder attackransomware29 Sep 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
GitHub PoC37
rwincey/CVE-2021-22005
CVE-2021-22005CRITICALunder attackransomware28 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
Exploit-DB
WordPress Plugin Contact Form 1.7.14 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24276webappsphp28 Sep 2021
Contact Form by Supsystic < 1.7.15 - Reflected Cross-Site scripting (XSS)
43RISK
open
previouspage 659 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.