Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
78,295 exploits
VulnCheck XDB
infoleak
CVE-2021-31207MEDIUMunder attackransomware10 Aug 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open
GitHub PoC46
nuclei scanner for proxyshell ( CVE-2021-34473 )
CVE-2021-34473CRITICALunder attackransomware10 Aug 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
ZeroShell命令执行漏洞批量扫描poc+exp
CVE-2019-1272510 Aug 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack10 Aug 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
initial-access
CVE-2019-1272510 Aug 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
VulnCheck XDB
client-side
CVE-2020-1020HIGHunder attack10 Aug 2021
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RISK
open
Exploit-DB
Cockpit CMS 0.11.1 - 'Username Enumeration & Password Reset' NoSQL Injection
CVE-2020-35848webappsmultiple10 Aug 2021
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
60RISK
open
GitHub PoC2
CVE-2019-11043
CVE-2019-11043HIGHunder attackransomware10 Aug 2021
Underflow in PHP-FPM can lead to RCE
100RISK
open
GitHub PoC1
OlivierLaflamme/CVE-2021-36934-export-shadow-volume-POC
CVE-2021-36934HIGHunder attack10 Aug 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC10
Windows Font Driver Type 1 VToHOrigin stack corruption
CVE-2020-1020HIGHunder attack10 Aug 2021
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RISK
open
Exploit-DB
Amica Prodigy 1.7 - Privilege Escalation
CVE-2021-35312localwindows10 Aug 2021
A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Serv
23RISK
open
VulnCheck XDB
initial-access
CVE-2019-11043HIGHunder attackransomware10 Aug 2021
Underflow in PHP-FPM can lead to RCE
100RISK
open
Exploit-DB
Cockpit CMS 0.11.1 - 'Username Enumeration & Password Reset' NoSQL Injection
CVE-2020-35847webappsmultiple10 Aug 2021
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
60RISK
open
Exploit-DB
Xiaomi browser 10.2.4.g - Browser Search History Disclosure
CVE-2018-20523localandroid10 Aug 2021
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider
28RISK
open
GitHub PoC
CVE-2021-2109 basic scanner
CVE-2021-2109HIGH09 Aug 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RISK
open
GitHub PoC9
BabyTeam1024/CVE-2021-2394
CVE-2021-2394CRITICAL08 Aug 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
70RISK
open
GitHub PoC
Very basic bash script to exploit the CVE-2019-6447.
CVE-2019-644708 Aug 2021
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open
VulnCheck XDB
client-side
CVE-2013-3900MEDIUMunder attack08 Aug 2021
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
GitHub PoC
Modified version of CVE-2019-5736-PoC by Frichetten
CVE-2019-573607 Aug 2021
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
Metasploit300
Canon Driver Privilege Escalation
CVE-2021-3808507 Aug 2021
The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer pro
18RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack07 Aug 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2015-835106 Aug 2021
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RISK
open
GitHub PoC
CVE-2020-35847, CVE-2020-35848 : Account Takeover
CVE-2020-3584706 Aug 2021
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
60RISK
open
GitHub PoC1
this script is exploit for wordpress old plugin gwolle
CVE-2015-835106 Aug 2021
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RISK
open
Exploit-DB
CMSuno 1.7 - 'tgo' Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-36654webappsphp05 Aug 2021
CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while
23RISK
open
VulnCheck XDB
initial-access
CVE-2017-1000486CRITICALunder attack05 Aug 2021
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISK
open
GitHub PoC4
Pastea/CVE-2017-1000486
CVE-2017-1000486CRITICALunder attack05 Aug 2021
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISK
open
GitHub PoC1
An implementation of CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware04 Aug 2021
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware04 Aug 2021
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC4
s4dbrd/CVE-2020-9496
CVE-2020-949604 Aug 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
previouspage 670 / 2,610next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.