Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
78,258 exploits
Exploit-DB
WordPress Plugin Contact Form 1.7.14 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24276webappsphp28 Sep 2021
Contact Form by Supsystic < 1.7.15 - Reflected Cross-Site scripting (XSS)
43RISK
open
GitHub PoC14
CrackerCat/CVE-2021-30632
CVE-2021-30632HIGHunder attack28 Sep 2021
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISK
open
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALunder attackransomware28 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
Exploit-DB
WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-24610webappsphp28 Sep 2021
TranslatePress < 2.0.9 - Authenticated Stored Cross-Site Scripting
23RISK
open
Exploit-DB
WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24275webappsphp28 Sep 2021
Popup by Supsystic < 1.10.5 - Reflected Cross-Site scripting (XSS)
43RISK
open
Exploit-DB
WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24274webappsphp28 Sep 2021
Ultimate Maps by Supsystic < 1.2.5 - Reflected Cross-Site scripting (XSS)
43RISK
open
GitHub PoC
Sudo heap-based buffer overflow privilege escalation commands and mitigations.
CVE-2021-3156HIGHunder attack27 Sep 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC2
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
CVE-2018-1676327 Sep 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware27 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware27 Sep 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1676327 Sep 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware27 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
CVE-2021-22005_PoC
CVE-2021-22005CRITICALunder attackransomware27 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
Exploit-DB
XAMPP 7.4.3 - Local Privilege Escalation
CVE-2020-11107localwindows27 Sep 2021
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged
28RISK
open
GitHub PoC19
Windows HTTP协议栈远程代码执行漏洞 CVE-2021-31166
CVE-2021-31166CRITICALunder attack27 Sep 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
CVE-2019-19781
CVE-2019-19781CRITICALunder attackransomware27 Sep 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC1
Quick and dirty CVE-2021-38647 (Omigod) exploit written in Go.
CVE-2021-38647CRITICALunder attackransomware26 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware26 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-34527HIGHunder attackransomware26 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware26 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware26 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALunder attackransomware26 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
GitHub PoC10
C# PrintNightmare (CVE-2021-1675)
CVE-2021-1675HIGHunder attackransomware26 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC209
Python implementation for PrintNightmare (CVE-2021-1675 / CVE-2021-34527)
CVE-2021-1675HIGHunder attackransomware26 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
AmesianX/CVE-2021-21220
CVE-2021-21220HIGHunder attack26 Sep 2021
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
100RISK
open
GitHub PoC1
Python script to obtain RCE on Mantis Bug Tracker prior to version 1.2.x Check CVE-2008-4687 for additional information
CVE-2008-468725 Sep 2021
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISK
open
GitHub PoC13
CVE-2021-22005批量验证python脚本
CVE-2021-22005CRITICALunder attackransomware25 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
GitHub PoC17
CVE-2021-3156 - sudo exploit for ubuntu 18.04 & 20.04
CVE-2021-3156HIGHunder attack25 Sep 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-22005CRITICALunder attackransomware25 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware24 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
previouspage 660 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.