Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
78,295 exploits
Exploit-DB
SonicWall NetExtender 10.2.0.300 - Unquoted Service Path
CVE-2020-5147localwindows17 Aug 2021
SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to
23RISK
open
GitHub PoC1
A tool to crash MySQL servers with CVE-2017-3599
CVE-2017-359916 Aug 2021
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions t
45RISK
open
GitHub PoC30
CVE-2021-34473 Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-34473CRITICALunder attackransomware16 Aug 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Multiple Stored XSS Online Doctor Appointment System
CVE-2021-2579116 Aug 2021
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment S
23RISK
open
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMunder attackransomware16 Aug 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALunder attackransomware16 Aug 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALunder attackransomware16 Aug 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack15 Aug 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
The Heartbleed bug `CVE-2014-0160` is a severe implementation flaw in the OpenSSL library, which enables attackers to steal data from the memory of the victim server. The contents of the stolen data depend on what is there in the memory of the server. It could potentially contain private keys, TLS session keys, usernames, passwords, credit cards, etc. The vulnerability is in the implementation of the Heartbeat protocol, which is used by SSL/TLS to keep the connection alive.
CVE-2014-0160HIGHunder attack15 Aug 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC1
tools for automate configure Ubuntu 20.04 enviroment for testing CVE-2021-28476.
CVE-2021-28476CRITICAL15 Aug 2021
Windows Hyper-V Remote Code Execution Vulnerability
60RISK
open
GitHub PoC1
An implementation of CVE-2020-1938
CVE-2020-1938CRITICALunder attack14 Aug 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALunder attack14 Aug 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC3
WordPress File Upload Vulnerability, Modern Events Calendar Lite WordPress plugin before 5.16.5
CVE-2021-2414514 Aug 2021
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISK
open
GitHub PoC1
Sudo Heap Overflow Baron Samedit
CVE-2021-3156HIGHunder attack13 Aug 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
WpDiscuz 7.0.4 Arbitrary File Upload Exploit
CVE-2020-24186CRITICAL13 Aug 2021
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISK
open
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALunder attackransomware13 Aug 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALunder attackransomware13 Aug 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMunder attackransomware13 Aug 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack13 Aug 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALunder attackransomware13 Aug 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMunder attackransomware13 Aug 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALunder attackransomware13 Aug 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack12 Aug 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
Exploit-DB
Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE)
CVE-2021-37425webappsmultiple12 Aug 2021
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workfl
35RISK
open
GitHub PoC3
Exploit for CVE-2021-36934
CVE-2021-36934HIGHunder attack12 Aug 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC
Zeek Package to detect cve-2017-2741
CVE-2017-274111 Aug 2021
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RISK
open
GitHub PoC5
Scanner for CVE-2021-34473, ProxyShell, A Microsoft Exchange On-premise Vulnerability
CVE-2021-34473CRITICALunder attackransomware11 Aug 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Jerry-zhuang/CVE-2017-1000117
CVE-2017-100011711 Aug 2021
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RISK
open
Exploit-DB
Amica Prodigy 1.7 - Privilege Escalation
CVE-2021-35312localwindows10 Aug 2021
A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Serv
23RISK
open
GitHub PoC
ZeroShell命令执行漏洞批量扫描poc+exp
CVE-2019-1272510 Aug 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
previouspage 669 / 2,610next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.