Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
79,057 exploits
GitHub PoC429
PoC for CVE-2021-3156 (sudo heap overflow)
CVE-2021-3156HIGHunder attack30 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack30 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Exploit-DB
Quick.CMS 6.7 - Remote Code Execution (Authenticated)
CVE-2020-35754webappsphp29 Jan 2021
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequentl
28RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack29 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Metasploit600
Wordpress Plugin Modern Events Calendar - Authenticated Remote Code Execution
CVE-2021-2414529 Jan 2021
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISK
open
GitHub PoC116
This python file will decrypt the configurationFile used by hikvision cameras vulnerable to CVE-2017-7921.
CVE-2017-7921CRITICALunder attack29 Jan 2021
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
Exploit-DB
MyBB Hide Thread Content Plugin 1.0 - Information Disclosure
CVE-2021-3337webappsphp29 Jan 2021
The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading re
28RISK
open
GitHub PoC
freeFV/CVE-2021-3156
CVE-2021-3156HIGHunder attack29 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC39
Notes regarding CVE-2021-3156: Heap-Based Buffer Overflow in Sudo
CVE-2021-3156HIGHunder attack29 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC1
binw2018/CVE-2021-3156-SCRIPT
CVE-2021-3156HIGHunder attack29 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
pwn3z/CVE-2020-14882-WebLogic
CVE-2020-14882CRITICALunder attack29 Jan 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack29 Jan 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
local
CVE-2017-7921CRITICALunder attack29 Jan 2021
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC2
👻CVE-2017-16995
CVE-2017-1699528 Jan 2021
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
Exploit-DB
Fuel CMS 1.4.1 - Remote Code Execution (2)
CVE-2018-16763webappsphp28 Jan 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC3
CVE-2021-3156
CVE-2021-3156HIGHunder attack28 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Exploit-DB
CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
CVE-2020-25538webappsphp28 Jan 2021
An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and r
23RISK
open
GitHub PoC5
cve-2021-3156;sudo堆溢出漏洞;漏洞检测
CVE-2021-3156HIGHunder attack28 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC4
baka9moe/CVE-2021-3156-Exp
CVE-2021-3156HIGHunder attack28 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack28 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Exploit-DB
CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
CVE-2020-25557webappsphp28 Jan 2021
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. A
23RISK
open
GitHub PoC18
1day research effort
CVE-2021-3156HIGHunder attack28 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Exploit-DB
Metasploit Framework 6.0.11 - msfvenom APK template command injection
CVE-2020-7384HIGHlocalmultiple28 Jan 2021
Client-Side Command Injection in Rapid7 Metasploit
68RISK
open
GitHub PoC18
crisprss/Laravel_CVE-2021-3129_EXP
CVE-2021-3129CRITICALunder attackransomware27 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC79
WebLogic T3/IIOP RCE ExternalizableHelper.class of coherence.jar
CVE-2020-14756CRITICAL27 Jan 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versio
70RISK
open
GitHub PoC1
unauth401/CVE-2021-3156
CVE-2021-3156HIGHunder attack27 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC69
Exploit for CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware27 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC112
CVE-2021-3156
CVE-2021-3156HIGHunder attack27 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware27 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC3
This simple bash script will patch the recently discovered sudo heap overflow vulnerability.
CVE-2021-3156HIGHunder attack27 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
previouspage 728 / 2,636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.