Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
78,291 exploits
GitHub PoC3
guglia001/CVE-2019-18818
CVE-2019-1881829 Aug 2021
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-25223CRITICALunder attack29 Aug 2021
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISK
open
GitHub PoC9
Exploit for CVE-2019-19609 in Strapi (Remote Code Execution)
CVE-2019-1960929 Aug 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
GitHub PoC1
Citrix ADC RCE cve-2019-19781
CVE-2019-19781CRITICALunder attackransomware29 Aug 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC11
CVE-2020-25223
CVE-2020-25223CRITICALunder attack29 Aug 2021
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISK
open
GitHub PoC1
CVE-2004-2687 DistCC Daemon Command Execution
CVE-2004-268728 Aug 2021
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISK
open
GitHub PoC
AssassinUKG/CVE-2021-29447
CVE-2021-29447HIGH27 Aug 2021
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC1
A proof of concept for CVE-2016-6515
CVE-2016-651526 Aug 2021
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RISK
open
Exploit-DB
HP OfficeJet 4630/7110 MYM1FN2025AR/2117A - Stored Cross-Site Scripting (XSS)
CVE-2021-3441webappshardware25 Aug 2021
A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross
23RISK
open
Metasploit600
Atlassian Confluence WebWork OGNL Injection
CVE-2021-26084CRITICALunder attackransomware25 Aug 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC1
Kibana Prototype Pollution
CVE-2019-7609CRITICALunder attack24 Aug 2021
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-6308MEDIUM24 Aug 2021
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated at
60RISK
open
GitHub PoC24
my exp for chrome V8 CVE-2021-30551
CVE-2021-30551HIGHunder attack22 Aug 2021
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corru
83RISK
open
VulnCheck XDB
client-side
CVE-2021-30551HIGHunder attack22 Aug 2021
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corru
83RISK
open
GitHub PoC
rood8008/CVE-2021-35464
CVE-2021-35464CRITICALunder attackransomware21 Aug 2021
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-35464CRITICALunder attackransomware21 Aug 2021
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RISK
open
GitHub PoC1
An implementation of CVE-2015-3306
CVE-2015-330621 Aug 2021
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
VulnCheck XDB
client-side
CVE-2018-999520 Aug 2021
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC11
CVE-2018-19320 LPE Exploit
CVE-2018-19320HIGHunder attackransomware19 Aug 2021
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISK
open
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALunder attack19 Aug 2021
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
VulnCheck XDB
local
CVE-2018-19320HIGHunder attackransomware19 Aug 2021
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISK
open
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMunder attackransomware18 Aug 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open
Exploit-DB
crossfire-server 1.9.0 - 'SetUp()' Remote Buffer Overflow
CVE-2006-1236remotelinux18 Aug 2021
Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrar
28RISK
open
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALunder attackransomware18 Aug 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALunder attackransomware18 Aug 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
SonicWall NetExtender 10.2.0.300 - Unquoted Service Path
CVE-2020-5147localwindows17 Aug 2021
SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to
23RISK
open
GitHub PoC1
CVE-2019-11932
CVE-2019-1193217 Aug 2021
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
GitHub PoC30
CVE-2021-34473 Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-34473CRITICALunder attackransomware16 Aug 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMunder attackransomware16 Aug 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open
GitHub PoC1
Multiple Stored XSS Online Doctor Appointment System
CVE-2021-2579116 Aug 2021
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment S
23RISK
open
previouspage 668 / 2,610next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.