Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,329cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
78,324 exploits
Metasploit500
Netfilter x_tables Heap OOB Write Privilege Escalation
CVE-2021-22555HIGHunder attack07 Jul 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
Metasploit400
Sage X3 Administration Service Authentication Bypass Command Execution
CVE-2020-7387MEDIUM07 Jul 2021
Sage X3 AdxAdmin Exposure of Sensitive Information to an Unauthorized Actor
40RISK
open
Metasploit400
Sage X3 Administration Service Authentication Bypass Command Execution
CVE-2020-7388CRITICAL07 Jul 2021
Sage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofing
75RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware07 Jul 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
Exploit-DBVexDay Proof
Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated) (2)
CVE-2021-22911webappslinux07 Jul 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
GitHub PoC42
CVE-2021-3493 Ubuntu OverlayFS Local Privesc (Interactive Bash Shell & Execute Command Entered)
CVE-2021-3493HIGHunder attack07 Jul 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC
Simple batch script to disable the Microsoft Print Spooler service from system
CVE-2021-34527HIGHunder attackransomware07 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC19
Information on the Windows Spooler vulnerability - CVE-2021-1675; CVE 2021 34527
CVE-2021-1675HIGHunder attackransomware07 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
How to fix the PrintNightmare vulnerability
CVE-2021-34527HIGHunder attackransomware07 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack07 Jul 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
Exploit-DB
Pallets Werkzeug 0.15.4 - Path Traversal
CVE-2019-14322webappspython06 Jul 2021
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
50RISK
open
GitHub PoC5
Exploits Password Reset Vulnerability in OpenCRX, CVE-2020-7378. Also maintains Stealth by deleting all the password reset mails created by the script
CVE-2020-7378CRITICAL06 Jul 2021
CRIXP OpenCRX Unverified Password Change
48RISK
open
GitHub PoC2
Workaround for Windows Print Spooler Remote Code Execution Vulnerability(CVE-2021-34527). See: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
CVE-2021-34527HIGHunder attackransomware05 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-1675HIGHunder attackransomware05 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware05 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
Wordpress Plugin Backup Guard 1.5.8 - Remote Code Execution (Authenticated)
CVE-2021-24155webappsphp05 Jul 2021
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
60RISK
open
GitHub PoC801
A PrintNightmare (CVE-2021-34527) Python Scanner. Scan entire subnets for hosts vulnerable to the PrintNightmare RCE
CVE-2021-34527HIGHunder attackransomware05 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
This simple PowerShell script is in response to the "PrintNightmare" vulnerability. This was designed to give a end user the ability to stop and disable the "Print Spooler" service on their computer while awaiting a fix from Microsoft.
CVE-2021-34527HIGHunder attackransomware05 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
edsonjt81/CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware05 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC77
CVE-2021-1675 (PrintNightmare)
CVE-2021-1675HIGHunder attackransomware05 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
OpenEMR < 5.0.1.4 - (Authenticated) File upload - Remote command execution
CVE-2018-1513905 Jul 2021
Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote
28RISK
open
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALunder attack04 Jul 2021
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC23
Masscanner for Laravel phpunit RCE CVE-2017-9841
CVE-2017-9841CRITICALunder attack04 Jul 2021
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC5
Youtube : https://youtu.be/Zr0KjYDSFKQ
CVE-2021-1675HIGHunder attackransomware04 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
to catch cve-2021-1675-printnightmare
CVE-2021-1675HIGHunder attackransomware03 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
Windows Print Spooler Service RCE CVE-2021-1675 (PrintNightmare)
CVE-2021-1675HIGHunder attackransomware03 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
随便放点自己弄的小东西
CVE-2020-0674HIGHunder attack03 Jul 2021
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack03 Jul 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
GitHub PoC7
Exploit for MS Http Protocol Stack RCE vulnerability (CVE-2021-31166)
CVE-2021-31166CRITICALunder attack03 Jul 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack03 Jul 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
previouspage 678 / 2,611next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.