Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,958 exploits
Exploit-DB
FUDForum 3.1.0 - 'srch' Reflected XSS
CVE-2021-27519webappsphp03 Jun 2021
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "
38RISK
open
Exploit-DB
FUDForum 3.1.0 - 'author' Reflected XSS
CVE-2021-27520webappsphp03 Jun 2021
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "
38RISK
open
GitHub PoC
PHPFusion 9.03.50 - Remote Code Execution
CVE-2020-2494903 Jun 2021
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr
50RISK
open
Metasploit600
Polkit D-Bus Authentication Bypass
CVE-2021-3560HIGHunder attack03 Jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
initial-access
CVE-2021-21985CRITICALunder attackransomware03 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
Exploit-DB
4Images 1.8 - 'redirect' Reflected XSS
CVE-2021-27308webappsphp03 Jun 2021
A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to in
23RISK
open
VulnCheck XDB
initial-access
CVE-2020-2494903 Jun 2021
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr
50RISK
open
VulnCheck XDB
initial-access
CVE-2020-7247CRITICALunder attack02 Jun 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
VulnCheck XDB
local
CVE-2021-21551HIGHunder attack02 Jun 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISK
open
Exploit-DB
GetSimple CMS 3.3.4 - Information Disclosure
CVE-2014-8722webappsphp02 Jun 2021
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<user
28RISK
open
Exploit-DB
Seo Panel 4.8.0 - 'search_name' Reflected XSS
CVE-2021-28417webappsphp02 Jun 2021
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and t
23RISK
open
VulnCheck XDB
initial-access
CVE-2018-1616702 Jun 2021
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
60RISK
open
GitHub PoC
This vulnerability exists in OpenBSD’s mail server OpenSMTPD’s “smtp_mailaddr()” function, and affects OpenBSD version 6.6. This allows an attacker to execute arbitrary shell commands like “sleep 66” as root user
CVE-2020-7247CRITICALunder attack02 Jun 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
Exploit-DB
Seo Panel 4.8.0 - 'category' Reflected XSS
CVE-2021-28418webappsphp02 Jun 2021
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and
23RISK
open
GitHub PoC
LogonTracer v1.2.0 RCE
CVE-2018-1616702 Jun 2021
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
60RISK
open
GitHub PoC9
bluefrostsecurity/CVE-2021-28476
CVE-2021-28476CRITICAL02 Jun 2021
Windows Hyper-V Remote Code Execution Vulnerability
60RISK
open
GitHub PoC23
An extended proof-of-concept for the CVE-2021-21551 Dell ‘dbutil_2_3.sys’ Kernel Exploit
CVE-2021-21551HIGHunder attack02 Jun 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISK
open
Exploit-DB
Apache Airflow 1.10.10 - 'Example Dag' Remote Code Execution
CVE-2020-11978HIGHunder attackwebappsmultiple02 Jun 2021
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was disco
100RISK
open
Exploit-DB
Apache Airflow 1.10.10 - 'Example Dag' Remote Code Execution
CVE-2020-13927CRITICALunder attackwebappsmultiple02 Jun 2021
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th
100RISK
open
Exploit-DB
Products.PluggableAuthService 2.6.0 - Open Redirect
CVE-2021-21337MEDIUMwebappspython02 Jun 2021
URL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService
33RISK
open
Exploit-DB
LogonTracer 1.2.0 - Remote Code Execution (Unauthenticated)
CVE-2018-16167webappsmultiple01 Jun 2021
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
60RISK
open
VulnCheck XDB
infoleak
CVE-2021-21985CRITICALunder attackransomware01 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-21985CRITICALunder attackransomware01 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC3
Wordpress XXE injection 구축 자동화 및 PoC
CVE-2021-29447HIGH01 Jun 2021
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC
This script check the CVE-2021-21985 vulnerability and patch on vCenter Server.
CVE-2021-21985CRITICALunder attackransomware01 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC2
CVE-2021-21985 Checker.
CVE-2021-21985CRITICALunder attackransomware01 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC
rnnsz/CVE-2017-15950
CVE-2017-1595031 May 2021
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary co
23RISK
open
GitHub PoC3
python3 POC for CVE-2019-2729 WebLogic Deserialization Vulnerability and CVE-2017-10271 amongst others
CVE-2019-2729CRITICAL31 May 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISK
open
GitHub PoC226
PoC for CVE-2021-28476 a guest-to-host "Hyper-V Remote Code Execution Vulnerability" in vmswitch.sys.
CVE-2021-28476CRITICAL31 May 2021
Windows Hyper-V Remote Code Execution Vulnerability
60RISK
open
GitHub PoC3
python3 POC for CVE-2019-2729 WebLogic Deserialization Vulnerability and CVE-2017-10271 amongst others
CVE-2017-10271HIGHunder attackransomware31 May 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
previouspage 702 / 2,632next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.