Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,329cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,721GitHub PoC 14,482VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
78,324 exploits
Metasploit500
Netfilter x_tables Heap OOB Write Privilege Escalation
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open ↗Metasploit400
Sage X3 Administration Service Authentication Bypass Command Execution
Sage X3 AdxAdmin Exposure of Sensitive Information to an Unauthorized Actor
40RISK
open ↗Metasploit400
Sage X3 Administration Service Authentication Bypass Command Execution
Sage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofing
75RISK
open ↗Exploit-DB✓ VexDay Proof
Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated) (2)
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open ↗GitHub PoC★ 42
CVE-2021-3493 Ubuntu OverlayFS Local Privesc (Interactive Bash Shell & Execute Command Entered)
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗GitHub PoC
Simple batch script to disable the Microsoft Print Spooler service from system
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 19
Information on the Windows Spooler vulnerability - CVE-2021-1675; CVE 2021 34527
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 2
How to fix the PrintNightmare vulnerability
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
local
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗Exploit-DB
Pallets Werkzeug 0.15.4 - Path Traversal
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
50RISK
open ↗GitHub PoC★ 5
Exploits Password Reset Vulnerability in OpenCRX, CVE-2020-7378. Also maintains Stealth by deleting all the password reset mails created by the script
CRIXP OpenCRX Unverified Password Change
48RISK
open ↗GitHub PoC★ 2
Workaround for Windows Print Spooler Remote Code Execution Vulnerability(CVE-2021-34527). See: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
remote-with-credentials
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗Exploit-DB
Wordpress Plugin Backup Guard 1.5.8 - Remote Code Execution (Authenticated)
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
60RISK
open ↗GitHub PoC★ 801
A PrintNightmare (CVE-2021-34527) Python Scanner. Scan entire subnets for hosts vulnerable to the PrintNightmare RCE
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
This simple PowerShell script is in response to the "PrintNightmare" vulnerability. This was designed to give a end user the ability to stop and disable the "Print Spooler" service on their computer while awaiting a fix from Microsoft.
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
edsonjt81/CVE-2021-1675
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 77
CVE-2021-1675 (PrintNightmare)
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 2
OpenEMR < 5.0.1.4 - (Authenticated) File upload - Remote command execution
Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote
28RISK
open ↗VulnCheck XDB
initial-access
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open ↗GitHub PoC★ 23
Masscanner for Laravel phpunit RCE CVE-2017-9841
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open ↗GitHub PoC★ 5
Youtube : https://youtu.be/Zr0KjYDSFKQ
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
to catch cve-2021-1675-printnightmare
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 2
Windows Print Spooler Service RCE CVE-2021-1675 (PrintNightmare)
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
随便放点自己弄的小东西
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISK
open ↗GitHub PoC★ 7
Exploit for MS Http Protocol Stack RCE vulnerability (CVE-2021-31166)
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.