Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,958 exploits
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware12 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
h3x0v3rl0rd/CVE-2015-1635
CVE-2015-1635CRITICALunder attack12 Jul 2021
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
GitHub PoC2
h3x0v3rl0rd/CVE-2015-1635-POC
CVE-2015-1635CRITICALunder attack12 Jul 2021
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALunder attack12 Jul 2021
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALunder attack12 Jul 2021
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
GitHub PoC1
Scanner for CVE-2020-1938
CVE-2020-1938CRITICALunder attack11 Jul 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC15
k8gege/cve-2021-1675
CVE-2021-1675HIGHunder attackransomware11 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
cve-2021-21985 powershell poc
CVE-2021-21985CRITICALunder attackransomware11 Jul 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC1
h3x0v3rl0rd/CVE-2011-1249
CVE-2011-124910 Jul 2021
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis
23RISK
open
VulnCheck XDB
infoleak
CVE-2021-34527HIGHunder attackransomware09 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
dywhoami/CVE-2021-34527-Scanner-Based-On-cube0x0-POC
CVE-2021-34527HIGHunder attackransomware09 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Fix for PrintNightmare CVE-2021-34527
CVE-2021-34527HIGHunder attackransomware09 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
A collection of scripts to help set the appropriate registry keys for CVE-2021-34527
CVE-2021-34527HIGHunder attackransomware09 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
h3x0v3rl0rd/CVE-2019-6447
CVE-2019-644709 Jul 2021
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open
GitHub PoC40
MS17-010_CVE-2017-0143
CVE-2017-0143HIGHunder attackransomware08 Jul 2021
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
h3x0v3rl0rd/CVE-2019-5736
CVE-2019-573608 Jul 2021
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC
Mitigation for CVE-2021-34527 RCE by setting WRITE ACLs
CVE-2021-34527HIGHunder attackransomware08 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
A CVE-2013-2028 implementation
CVE-2013-202808 Jul 2021
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RISK
open
GitHub PoC
CVE-2021-34527 implementation
CVE-2021-34527HIGHunder attackransomware08 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
bartimusprimed/CVE-2021-1675-Yara
CVE-2021-1675HIGHunder attackransomware08 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-1956HIGHunder attack08 Jul 2021
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the
100RISK
open
GitHub PoC
CVE-2020-1956
CVE-2020-1956HIGHunder attack08 Jul 2021
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the
100RISK
open
GitHub PoC1
haidv35/CVE-2021-21985
CVE-2021-21985CRITICALunder attackransomware08 Jul 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
Metasploit600
Geutebruck Multiple Remote Command Execution
CVE-2021-33548HIGH08 Jul 2021
UDP Technology/Geutebrück camera devices: Command injection in preserve parameter leading to RCE
48RISK
open
Metasploit600
Geutebruck Multiple Remote Command Execution
CVE-2021-33544HIGH08 Jul 2021
UDP Technology/Geutebrück camera devices: command injection leading to RCE
58RISK
open
Metasploit600
Geutebruck instantrec Remote Command Execution
CVE-2021-33549HIGH08 Jul 2021
UDP Technology/Geutebrück camera devices: Buffer overflow in action parameter leading to RCE
48RISK
open
Metasploit600
Geutebruck Multiple Remote Command Execution
CVE-2021-33551HIGH08 Jul 2021
UDP Technology/Geutebrück camera devices: Command injection in environment.lang parameter leading to RCE
48RISK
open
Metasploit600
Geutebruck Multiple Remote Command Execution
CVE-2021-33552HIGH08 Jul 2021
UDP Technology/Geutebrück camera devices: Command injection in date parameter leading to RCE
48RISK
open
Metasploit600
Geutebruck Multiple Remote Command Execution
CVE-2021-33543CRITICAL08 Jul 2021
UDP Technology/Geutebrück camera devices: Authentication Bypass
65RISK
open
Metasploit600
Geutebruck Multiple Remote Command Execution
CVE-2021-33550HIGH08 Jul 2021
UDP Technology/Geutebrück camera devices: Command injection in date parameter leading to RCE
48RISK
open
previouspage 694 / 2,632next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.