Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
78,295 exploits
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware04 Aug 2021
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
Exploit-DB
ApacheOfBiz 17.12.01 - Remote Command Execution (RCE)
CVE-2020-9496webappsjava04 Aug 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
GitHub PoC4
s4dbrd/CVE-2020-9496
CVE-2020-949604 Aug 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
GitHub PoC1
An implementation of CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware04 Aug 2021
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC1
An implementation of CVE-2016-8740
CVE-2016-874003 Aug 2021
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2
45RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack02 Aug 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC
CVE-2018-20250
CVE-2018-20250HIGHunder attackransomware02 Aug 2021
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
GitHub PoC3
PenTestical/CVE-2021-22204
CVE-2021-22204MEDIUMunder attack02 Aug 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
GitHub PoC27
AssassinUKG/CVE-2021-22204
CVE-2021-22204MEDIUMunder attack02 Aug 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
GitHub PoC20
POC of CVE-2021-2394
CVE-2021-2394CRITICAL02 Aug 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
70RISK
open
GitHub PoC2
POC experiments with Volume Shadow copy Service (VSS)
CVE-2021-36934HIGHunder attack02 Aug 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC40
POC of CVE-2021-2394
CVE-2021-2394CRITICAL02 Aug 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
70RISK
open
GitHub PoC2
SeriousSAM Auto Exploiter
CVE-2021-36934HIGHunder attack01 Aug 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack01 Aug 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC5
My n-day exploit for CVE-2019-18634 (local privilege escalation)
CVE-2019-1863401 Aug 2021
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open
VulnCheck XDB
initial-access
CVE-2020-2865331 Jul 2021
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v
60RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack30 Jul 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC9
Polkit D-Bus Authentication Bypass Exploit
CVE-2021-3560HIGHunder attack30 Jul 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC9
Full unauthenticated RCE proof of concept for Rocket.Chat 3.12.1 CVE-2021-22911
CVE-2021-2291130 Jul 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
VulnCheck XDB
initial-access
CVE-2018-381030 Jul 2021
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISK
open
GitHub PoC10
WordPress Backup Guard Authenticated Remote Code Execution Exploit
CVE-2021-2415530 Jul 2021
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
60RISK
open
GitHub PoC1
Exploit for CVE-2018-3810
CVE-2018-381030 Jul 2021
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISK
open
GitHub PoC
CVE-2018-9276 PRTG < 18.2.39 Reverse Shell (Python3 support)
CVE-2018-9276HIGHunder attack29 Jul 2021
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
Exploit-DB
CloverDX 5.9.0 - Cross-Site Request Forgery (CSRF)
CVE-2021-29995webappsjava29 Jul 2021
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute
23RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack29 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack29 Jul 2021
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-9276HIGHunder attack29 Jul 2021
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
VulnCheck XDB
local
CVE-2019-10149CRITICALunder attack29 Jul 2021
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC15
Shellshock exploit aka CVE-2014-6271
CVE-2014-6271CRITICALunder attack29 Jul 2021
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
Exploit for CVE-2019-10149
CVE-2019-10149CRITICALunder attack29 Jul 2021
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
previouspage 671 / 2,610next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.