Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
78,295 exploits
GitHub PoC1
Exploit for CVE-2019-10149
CVE-2019-10149CRITICALunder attack29 Jul 2021
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC1
CVE-2021-36934 HiveNightmare vulnerability checker and workaround
CVE-2021-36934HIGHunder attack29 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC1
Exploit for CVE-2018-12636
CVE-2018-1263628 Jul 2021
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admi
28RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack28 Jul 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC1
Local Privilege Escalation via snapd (CVE-2019-7304) Remastered PoC exploit
CVE-2019-7304HIGH28 Jul 2021
Local privilege escalation via snapd socket
53RISK
open
GitHub PoC2
NYCY_homework_&_meeting
CVE-2021-3560HIGHunder attack28 Jul 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC3
To fight against Windows security breach PrintNightmare! (CVE-2021-34527, CVE-2021-1675)
CVE-2021-34527HIGHunder attackransomware28 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-12617HIGHunder attack27 Jul 2021
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack27 Jul 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC1
An implementation of CVE-2017-12617
CVE-2017-12617HIGHunder attack27 Jul 2021
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
GitHub PoC7
HiveNightmare aka SeriousSAM
CVE-2021-36934HIGHunder attack27 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC1
0x0D1n/CVE-2021-36934
CVE-2021-36934HIGHunder attack26 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC3
haidv35/CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware26 Jul 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
local
CVE-2021-30807HIGHunder attack26 Jul 2021
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS
76RISK
open
GitHub PoC
Exodusro/CVE-2021-3156
CVE-2021-3156HIGHunder attack26 Jul 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack26 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack26 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
Exploit-DB
Elasticsearch ECE 7.13.3 - Anonymous Database Dump
CVE-2021-22146webappsmultiple26 Jul 2021
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.
28RISK
open
Metasploit600
ManageEngine OpManager SumPDU Java Deserialization
CVE-2021-328726 Jul 2021
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the
30RISK
open
Metasploit600
ManageEngine OpManager SumPDU Java Deserialization
CVE-2020-2865326 Jul 2021
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware25 Jul 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware25 Jul 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack25 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack25 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC5
PoC for CVE-2021-36934 Aka HiveNightmare/SeriousSAM written in python3
CVE-2021-36934HIGHunder attack25 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC
This PowerShell script will take the mitigation measures for CVE-2021-36934 described by Microsoft and the US CERT team. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36934 https://kb.cert.org/vuls/id/506989 USE AT YOUR OWN RISK -- BACKUPS MAY BREAK.
CVE-2021-36934HIGHunder attack25 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC3
C# PoC for CVE-2021-36934/HiveNightmare/SeriousSAM
CVE-2021-36934HIGHunder attack24 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack24 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack24 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-2093324 Jul 2021
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.
50RISK
open
previouspage 672 / 2,610next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.