Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,958 exploits
GitHub PoC7
Exploit for MS Http Protocol Stack RCE vulnerability (CVE-2021-31166)
CVE-2021-31166CRITICALunder attack03 Jul 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
GitHub PoC4
Apache ActiveMQ PUT RCE Scan
CVE-2016-3088CRITICALunder attack03 Jul 2021
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC173
PrintNightmare - Windows Print Spooler RCE/LPE Vulnerability (CVE-2021-34527, CVE-2021-1675) proof of concept exploits
CVE-2021-34527HIGHunder attackransomware03 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-34527HIGHunder attackransomware03 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2020-1350CRITICALunder attack03 Jul 2021
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack03 Jul 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2016-3088CRITICALunder attack03 Jul 2021
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC2
结合14882的未授权访问漏洞,通过14883可远程执行任意代码
CVE-2020-14882CRITICALunder attack03 Jul 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack03 Jul 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC1
随便放点自己弄的小东西
CVE-2020-0674HIGHunder attack03 Jul 2021
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISK
open
Exploit-DB
Wordpress Plugin Modern Events Calendar 5.16.2 - Remote Code Execution (Authenticated)
CVE-2021-24145webappsphp02 Jul 2021
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
Wordpress Plugin Modern Events Calendar 5.16.2 - Event export (Unauthenticated)
CVE-2021-24146webappsphp02 Jul 2021
Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export
50RISK
open
GitHub PoC9
corelight/CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
mrezqi/CVE-2021-1675_CarbonBlack_HuntingQuery
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC318
JohnHammond/CVE-2021-34527
CVE-2021-34527HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC9
Vulnerability Scanner for CVE-2021-1675/PrintNightmare
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
ubuntu new PrivEsc race condition vulnerability
CVE-2021-3560HIGHunder attack02 Jul 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
Exploit-DB
AKCP sensorProbe SPX476 - 'Multiple' Cross-Site Scripting (XSS)
CVE-2021-35956webappshardware02 Jul 2021
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote aut
23RISK
open
GitHub PoC2
killtr0/CVE-2021-1675-PrintNightmare
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
thomasgeens/CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
Kritische Sicherheitslücke PrintNightmare CVE-2021-34527
CVE-2021-34527HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
A small powershell script to disable print spooler service using desired state configuration
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
CVE-2019-15107 Webmin Exploit in C
CVE-2019-15107CRITICALunder attackransomware02 Jul 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC
CVE-2021-1675: ZERO-DAY VULNERABILITY IN WINDOWS PRINTER SERVICE WITH AN EXPLOIT AVAILABLE IN ALL OPERATING SYSTEM VERSIONS
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
Scratch Desktop 3.17 - Remote Code Execution
CVE-2020-7750CRITICALwebappsmultiple02 Jul 2021
Cross-site Scripting (XSS)
48RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware02 Jul 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
local
CVE-2021-34527HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC264
Techniques based on named pipes for pool overflow exploitation targeting the most recent (and oldest) Windows versions demonstrated on CVE-2020-17087 and an off-by-one overflow
CVE-2020-17087HIGHunder attack02 Jul 2021
Windows Kernel Local Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC1
Proof of Concept Exploit for CVE-2021-35956, AKCP sensorProbe - 'Multiple' Cross Site Scripting (XSS)
CVE-2021-3595601 Jul 2021
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote aut
23RISK
open
previouspage 696 / 2,632next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.