Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,324 exploits
Exploit-DB
CHIYU IoT Devices - Denial of Service (DoS)
CVE-2021-31642webappshardware03 Jun 2021
A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including B
35RISK
open
Exploit-DB
CHIYU IoT Devices - 'Telnet' Authentication Bypass
CVE-2021-31251remotehardware03 Jun 2021
An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Tec
35RISK
open
Exploit-DB
FUDForum 3.1.0 - 'author' Reflected XSS
CVE-2021-27520webappsphp03 Jun 2021
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "
38RISK
open
GitHub PoC
LogonTracer v1.2.0 RCE
CVE-2018-1616702 Jun 2021
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
50RISK
open
GitHub PoC23
An extended proof-of-concept for the CVE-2021-21551 Dell ‘dbutil_2_3.sys’ Kernel Exploit
CVE-2021-21551HIGHunder attack02 Jun 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISK
open
Exploit-DB
Apache Airflow 1.10.10 - 'Example Dag' Remote Code Execution
CVE-2020-13927CRITICALunder attackwebappsmultiple02 Jun 2021
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th
100RISK
open
Exploit-DB
Products.PluggableAuthService 2.6.0 - Open Redirect
CVE-2021-21337MEDIUMwebappspython02 Jun 2021
URL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService
33RISK
open
GitHub PoC
This vulnerability exists in OpenBSD’s mail server OpenSMTPD’s “smtp_mailaddr()” function, and affects OpenBSD version 6.6. This allows an attacker to execute arbitrary shell commands like “sleep 66” as root user
CVE-2020-7247CRITICALunder attack02 Jun 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
Exploit-DB
Seo Panel 4.8.0 - 'category' Reflected XSS
CVE-2021-28418webappsphp02 Jun 2021
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and
23RISK
open
GitHub PoC9
bluefrostsecurity/CVE-2021-28476
CVE-2021-28476CRITICAL02 Jun 2021
Windows Hyper-V Remote Code Execution Vulnerability
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-7247CRITICALunder attack02 Jun 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
Exploit-DB
GetSimple CMS 3.3.4 - Information Disclosure
CVE-2014-8722webappsphp02 Jun 2021
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<user
28RISK
open
Exploit-DB
Seo Panel 4.8.0 - 'search_name' Reflected XSS
CVE-2021-28417webappsphp02 Jun 2021
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and t
23RISK
open
Exploit-DB
Apache Airflow 1.10.10 - 'Example Dag' Remote Code Execution
CVE-2020-11978HIGHunder attackwebappsmultiple02 Jun 2021
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was disco
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1616702 Jun 2021
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
50RISK
open
VulnCheck XDB
local
CVE-2021-21551HIGHunder attack02 Jun 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-21985CRITICALunder attackransomware01 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-21985CRITICALunder attackransomware01 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
Exploit-DB
LogonTracer 1.2.0 - Remote Code Execution (Unauthenticated)
CVE-2018-16167webappsmultiple01 Jun 2021
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
50RISK
open
GitHub PoC
This script check the CVE-2021-21985 vulnerability and patch on vCenter Server.
CVE-2021-21985CRITICALunder attackransomware01 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC2
CVE-2021-21985 Checker.
CVE-2021-21985CRITICALunder attackransomware01 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC3
Wordpress XXE injection 구축 자동화 및 PoC
CVE-2021-29447HIGH01 Jun 2021
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC
rnnsz/CVE-2008-4654
CVE-2008-465431 May 2021
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RISK
open
GitHub PoC
rnnsz/CVE-2017-15950
CVE-2017-1595031 May 2021
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary co
23RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware31 May 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC3
python3 POC for CVE-2019-2729 WebLogic Deserialization Vulnerability and CVE-2017-10271 amongst others
CVE-2017-10271HIGHunder attackransomware31 May 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21389HIGH31 May 2021
BuddyPress privilege escalation via REST API
61RISK
open
GitHub PoC226
PoC for CVE-2021-28476 a guest-to-host "Hyper-V Remote Code Execution Vulnerability" in vmswitch.sys.
CVE-2021-28476CRITICAL31 May 2021
Windows Hyper-V Remote Code Execution Vulnerability
60RISK
open
GitHub PoC3
python3 POC for CVE-2019-2729 WebLogic Deserialization Vulnerability and CVE-2017-10271 amongst others
CVE-2019-2729CRITICAL31 May 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISK
open
GitHub PoC59
arbitrary kernel read/write in dbutil_2_3.sys, Proof of Concept Local Privilege Escalation to nt authority/system
CVE-2021-21551HIGHunder attack30 May 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISK
open
previouspage 685 / 2,611next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.