Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
79,041 exploits
VulnCheck XDB
infoleak
CVE-2021-21975HIGHunder attackransomware01 Apr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-949601 Apr 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
GitHub PoC1
Vulnmachines/apache-ofbiz-CVE-2020-9496
CVE-2020-949601 Apr 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
GitHub PoC27
Nmap script to check vulnerability CVE-2021-21975
CVE-2021-21975HIGHunder attackransomware01 Apr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
GitHub PoC
Pommaq/CVE-1999-0016-POC
CVE-1999-001601 Apr 2021
Land IP denial of service.
45RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack31 Mar 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC13
CVE-2021-21975 vRealize Operations Manager SSRF
CVE-2021-21975HIGHunder attackransomware31 Mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
GitHub PoC9
hev0x/CVE-2021-26828_ScadaBR_RCE
CVE-2021-26828HIGHunder attack31 Mar 2021
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe
83RISK
open
GitHub PoC2
dorkerdevil/CVE-2021-21975
CVE-2021-21975HIGHunder attackransomware31 Mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
GitHub PoC12
VMWare vRealize SSRF-CVE-2021-21975
CVE-2021-21975HIGHunder attackransomware31 Mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-21975HIGHunder attackransomware31 Mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-21975HIGHunder attackransomware31 Mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-21975HIGHunder attackransomware31 Mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
GitHub PoC3
CVE-2020-14882部署冰蝎内存马
CVE-2020-14882CRITICALunder attack31 Mar 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Metasploit600
VMware vRealize Operations (vROps) Manager SSRF RCE
CVE-2021-21975HIGHunder attackransomware30 Mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
Metasploit600
VMware vRealize Operations (vROps) Manager SSRF RCE
CVE-2021-2198330 Mar 2021
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authent
50RISK
open
GitHub PoC1
CVE-2021-3156漏洞修复Shell
CVE-2021-3156HIGHunder attack30 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC4
D-Link DCS系列账号密码信息泄露漏洞,通过脚本获取账号密码,可批量。
CVE-2020-25078HIGHunder attack30 Mar 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RISK
open
VulnCheck XDB
local
CVE-2019-13272HIGHunder attack30 Mar 2021
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
VulnCheck XDB
local
CVE-2018-100000130 Mar 2021
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISK
open
VulnCheck XDB
local
CVE-2015-754730 Mar 2021
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISK
open
GitHub PoC1
CVE-2018-9995 هک دوربین مداربسته با آسیب پذیری
CVE-2018-999530 Mar 2021
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
VulnCheck XDB
local
CVE-2014-3153HIGHunder attack30 Mar 2021
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware30 Mar 2021
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-25078HIGHunder attack30 Mar 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RISK
open
VulnCheck XDB
local
CVE-2017-100036730 Mar 2021
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-999530 Mar 2021
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
VulnCheck XDB
local
CVE-2013-2094HIGHunder attack30 Mar 2021
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RISK
open
VulnCheck XDB
local
CVE-2016-072830 Mar 2021
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack30 Mar 2021
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
previouspage 714 / 2,635next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.