Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,324 exploits
Exploit-DB
WordPress Plugin ReDi Restaurant Reservation 21.0307 - 'Comment' Stored Cross-Site Scripting (XSS)
CVE-2021-24299webappsphp24 May 2021
ReDi Restaurant Reservations < 21.0426 - Unauthenticated Stored Cross-Site Scripting (XSS)
23RISK
open
GitHub PoC
Exploit CVE-2017-9248 Telerik ReMix from Paul Taylor's script. Exploit Telerik lastest version fixed vuln. ReMix by TinoKa & Shaco JX
CVE-2017-9248CRITICALunder attack24 May 2021
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9248CRITICALunder attack24 May 2021
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISK
open
GitHub PoC4
WordPress XXE vulnerability
CVE-2021-29447HIGH23 May 2021
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC
bgsilvait/WIn-CVE-2021-31166
CVE-2021-31166CRITICALunder attack23 May 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Qualcomm GPU / ARM Mali GPU
CVE-2021-1905HIGHunder attack23 May 2021
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon A
71RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware22 May 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-1272522 May 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
GitHub PoC8
PoC of how to exploit a RCE vulnerability of the example DAGs in Apache Airflow <1.10.11
CVE-2020-11978HIGHunder attack22 May 2021
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was disco
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-11978HIGHunder attack22 May 2021
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was disco
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALunder attackransomware22 May 2021
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-3674922 May 2021
Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)
60RISK
open
GitHub PoC176
漏洞POC、EXP合集,持续更新。Apache Druid-任意文件读取(CVE-2021-36749)、ConfluenceRCE(CVE-2021-26084)、ZeroShell防火墙RCE(CVE-2019-12725)、ApacheSolr任意文件读取、蓝凌OA任意文件读取、phpStudyRCE、ShowDoc任意文件上传、原创先锋后台未授权、Kyan账号密码泄露、TerraMasterTos任意文件读取、TamronOS-IPTV系统RCE、Wayos防火墙账号密码泄露
CVE-2019-1272522 May 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
Exploit-DB
Microsoft Exchange 2019 - Unauthenticated Email Download (Metasploit)
CVE-2021-26855CRITICALunder attackransomwarewebappswindows21 May 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-21551HIGHunder attack21 May 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISK
open
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMunder attack21 May 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack21 May 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
tuo4n8/CVE-2020-2950
CVE-2020-2950CRITICAL21 May 2021
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana
70RISK
open
GitHub PoC24
ch3rn0byl/CVE-2021-21551
CVE-2021-21551HIGHunder attack21 May 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISK
open
GitHub PoC8
POC for exiftool vuln (CVE-2021-22204).
CVE-2021-22204MEDIUMunder attack21 May 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
Exploit-DB
Solaris SunSSH 11.0 x86 - libpam Remote Root (2)
CVE-2020-14871CRITICALunder attackremotesolaris21 May 2021
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISK
open
Exploit-DB
DELL dbutil_2_3.sys 2.3 - Arbitrary Write to Local Privilege Escalation (LPE)
CVE-2021-21551HIGHunder attacklocalwindows21 May 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISK
open
GitHub PoC1
RCE
CVE-2019-7238CRITICALunder attack20 May 2021
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISK
open
GitHub PoC1
Docker image that lets me study the exploitation of the VIM exploit
CVE-2019-1273520 May 2021
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RISK
open
GitHub PoC
CVE-2019-14287
CVE-2019-1428720 May 2021
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack20 May 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Local Privilege Escalation is a way to take advantage of flaws in code or service administration that can manage regular or guest users for particular device activities or transfer root user privileges to master or client. User rights admin. The licenses or privileges may be violated by such undesired amendments, as the system may be disrupted by frequent users unless they have shell or root authorization. So, someone, someone, it may become dangerous and be used to obtain access to a higher level.
CVE-2019-13272HIGHunder attack20 May 2021
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
VulnCheck XDB
initial-access
CVE-2019-7238CRITICALunder attack20 May 2021
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISK
open
Exploit-DB
WordPress Plugin Stop Spammers 2021.8 - 'log' Reflected Cross-site Scripting (XSS)
CVE-2021-24245webappsphp19 May 2021
Stop Spammers < 2021.9 - Reflected Cross-Site Scripting (XSS)
38RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack19 May 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
previouspage 687 / 2,611next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.