Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
79,057 exploits
GitHub PoC
d3sh1n/cve-2021-21972
CVE-2021-21972CRITICALunder attackransomware03 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
Metasploit300
Microsoft Exchange ProxyLogon Collector
CVE-2021-26855CRITICALunder attackransomware02 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Metasploit600
VMware View Planner Unauthenticated Log File Upload RCE
CVE-2021-2197802 Mar 2021
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input val
60RISK
open
Metasploit300
Microsoft Exchange ProxyLogon Scanner
CVE-2021-26855CRITICALunder attackransomware02 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Metasploit600
Microsoft Exchange ProxyLogon RCE
CVE-2021-27065HIGHunder attackransomware02 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Metasploit600
Microsoft Exchange ProxyLogon RCE
CVE-2021-26855CRITICALunder attackransomware02 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Exploit-DBVexDay Proof
Zen Cart 1.5.7b - Remote Code Execution (Authenticated)
CVE-2021-3291webappsphp02 Mar 2021
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
28RISK
open
Exploit-DB
Tiny Tiny RSS - Remote Code Execution
CVE-2020-25787webappsphp02 Mar 2021
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting
28RISK
open
GitHub PoC1
andyfeili/-CVE-2019-7214
CVE-2019-721401 Mar 2021
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RISK
open
GitHub PoC1
Modified the test PoC from Secura, CVE-2020-1472, to change the machine password to null
CVE-2020-1472MEDIUMunder attackransomware01 Mar 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC2
CVE-2020-12351
CVE-2020-1235101 Mar 2021
Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a
23RISK
open
GitHub PoC160
CVE 2021-21315 PoC
CVE-2021-21315HIGHunder attack01 Mar 2021
Command Injection Vulnerability
100RISK
open
Metasploit600
Veritas Backup Exec Agent Remote Code Execution
CVE-2021-27876HIGHunder attackransomware01 Mar 2021
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc
91RISK
open
Metasploit600
Veritas Backup Exec Agent Remote Code Execution
CVE-2021-27878HIGHunder attackransomware01 Mar 2021
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc
91RISK
open
Exploit-DB
VMware vCenter Server 7.0 - Unauthenticated File Upload
CVE-2021-21972CRITICALunder attackransomwarewebappsmultiple01 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
Metasploit600
Veritas Backup Exec Agent Remote Code Execution
CVE-2021-27877HIGHunder attackransomware01 Mar 2021
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authenticat
98RISK
open
VulnCheck XDB
initial-access
CVE-2021-21315HIGHunder attack01 Mar 2021
Command Injection Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware01 Mar 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
Exploit-DBVexDay Proof
FortiLogger 4.4.2.2 - Unauthenticated Arbitrary File Upload (Metasploit)
CVE-2021-3378webappsmultiple01 Mar 2021
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware01 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC11
漏洞利用,Vmware vCenter 6.5-7.0 RCE(CVE-2021-21972),上传冰蝎3,getshell
CVE-2021-21972CRITICALunder attackransomware01 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware28 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware27 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
client-side
CVE-2020-1350CRITICALunder attack27 Feb 2021
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware27 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC1
VMware vCenter CVE-2021-21972 Tools
CVE-2021-21972CRITICALunder attackransomware27 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-21972CRITICALunder attackransomware27 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC
JMousqueton/Detect-CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware27 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC
CVE-2015-3224
CVE-2015-322427 Feb 2021
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RISK
open
GitHub PoC44
ZeusBox/CVE-2021-21017
CVE-2021-21017HIGHunder attack26 Feb 2021
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
93RISK
open
previouspage 722 / 2,636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.