Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
79,057 exploits
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALunder attackransomware08 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1676307 Mar 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC4
Module pack for #ProxyLogon (part. of my contribute for Metasploit-Framework) [CVE-2021-26855 && CVE-2021-27065]
CVE-2021-26855CRITICALunder attackransomware07 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC6
CVE-2021-26855 SSRF Exchange Server
CVE-2021-26855CRITICALunder attackransomware07 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC19
CVE-2021-21972 Unauthorized RCE in VMware vCenter metasploit exploit script
CVE-2021-21972CRITICALunder attackransomware07 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC3
A working PoC to CVE-2018-16763
CVE-2018-1676307 Mar 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware07 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC35
Microsoft Exchange Server SSRF漏洞(CVE-2021-26855)
CVE-2021-26855CRITICALunder attackransomware06 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC11
Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.
CVE-2021-27065HIGHunder attackransomware06 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware06 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALunder attackransomware06 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC24
This script helps to identify CVE-2021-26855 ssrf Poc
CVE-2021-26855CRITICALunder attackransomware06 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
0xKn/CVE-2007-2447
CVE-2007-244706 Mar 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALunder attackransomware06 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
struts2-rest-showcase 2.5.10
CVE-2017-9805HIGHunder attack05 Mar 2021
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
GitHub PoC10
Exploit for Joomla JCK Editor 6.4.4 (CVE-2018-17254)
CVE-2018-1725405 Mar 2021
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
60RISK
open
GitHub PoC99
Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065)
CVE-2021-26855CRITICALunder attackransomware05 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC424
CVE-2021-1732 Exploit
CVE-2021-1732HIGHunder attackransomware05 Mar 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-1732HIGHunder attackransomware05 Mar 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1725405 Mar 2021
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
60RISK
open
VulnCheck XDB
initial-access
CVE-2017-9805HIGHunder attack05 Mar 2021
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware04 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
Exploit-DB
e107 CMS 2.3.0 - CSRF
CVE-2021-27885webappsphp04 Mar 2021
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
23RISK
open
GitHub PoC3
CVE-2021-21972 related vulnerability code
CVE-2021-21972CRITICALunder attackransomware04 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, City
CVE-2020-2527003 Mar 2021
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, o
23RISK
open
GitHub PoC3
A repository hosting write ups for the 0 days CVE-2021-25679, CVE-2021-25680, and CVE-2021-25681
CVE-2021-2567903 Mar 2021
The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. T
23RISK
open
GitHub PoC22
A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865
CVE-2021-26855CRITICALunder attackransomware03 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
d3sh1n/cve-2021-21972
CVE-2021-21972CRITICALunder attackransomware03 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
Exploit-DBVexDay Proof
AnyDesk 5.5.2 - Remote Code Execution
CVE-2020-13160remotelinux03 Mar 2021
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execut
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware03 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
previouspage 721 / 2,636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.