Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,958 exploits
Exploit-DB
Wordpress Plugin XCloner 4.2.12 - Remote Code Execution (Authenticated)
CVE-2020-35948CRITICALwebappsphp01 Jul 2021
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated atta
53RISK
open
GitHub PoC56
PrintNightmare , Local Privilege Escalation of CVE-2021-1675 or CVE-2021-34527
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
puckiestyle/CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC23
cybersecurityworks553/CVE-2021-1675_PrintNightMare
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Fix without disabling Print Spooler
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1,100
Pure PowerShell implementation of CVE-2021-1675 Print Spooler Local Privilege Escalation (PrintNightmare)
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Proof of Concept Exploit for CVE-2021-35956, AKCP sensorProbe - 'Multiple' Cross Site Scripting (XSS)
CVE-2021-3595601 Jul 2021
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote aut
23RISK
open
GitHub PoC2
h3x0v3rl0rd/distccd_rce_CVE-2004-2687
CVE-2004-268701 Jul 2021
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISK
open
GitHub PoC325
Local Privilege Escalation Edition for CVE-2021-1675/CVE-2021-34527
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC88
openam-CVE-2021-35464 tomcat 执行命令回显
CVE-2021-35464CRITICALunder attackransomware01 Jul 2021
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RISK
open
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-35464CRITICALunder attackransomware01 Jul 2021
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-15961CRITICALunder attack30 Jun 2021
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open
GitHub PoC1
TheFlash2k/CVE-2021-3156
CVE-2021-3156HIGHunder attack30 Jun 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC3
CVE-2007-2447 - Samba usermap script
CVE-2007-244730 Jun 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC214
CVE-2021-1675 Detection Info
CVE-2021-1675HIGHunder attackransomware30 Jun 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Create your malicious engine in seconds
CVE-2020-711530 Jun 2021
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon succ
35RISK
open
GitHub PoC2
kondah/patch-cve-2021-1675
CVE-2021-1675HIGHunder attackransomware30 Jun 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
Exploit for CVE-2018-15961, a unrestricted file upload vulnerability in Adobe ColdFusion 2018 leading to RCE
CVE-2018-15961CRITICALunder attack30 Jun 2021
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open
GitHub PoC4
OpenEMR < 5.0.2 - (Authenticated) Path Traversal - Local File Disclosure
CVE-2019-1453030 Jun 2021
An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can
50RISK
open
VulnCheck XDB
client-side
CVE-2017-1000353CRITICALunder attack30 Jun 2021
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack30 Jun 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-22214MEDIUM29 Jun 2021
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE
53RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-34527HIGHunder attackransomware29 Jun 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
CVE-2021-1675 exploit
CVE-2021-1675HIGHunder attackransomware29 Jun 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1,990
C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527
CVE-2021-1675HIGHunder attackransomware29 Jun 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC24
AssassinUKG/Polkit-CVE-2021-3560
CVE-2021-3560HIGHunder attack29 Jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
previouspage 697 / 2,632next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.