Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
79,057 exploits
GitHub PoC69
Exploit for CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware27 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC79
WebLogic T3/IIOP RCE ExternalizableHelper.class of coherence.jar
CVE-2020-14756CRITICAL27 Jan 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versio
70RISK
open
GitHub PoC1
unauth401/CVE-2021-3156
CVE-2021-3156HIGHunder attack27 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC3
This simple bash script will patch the recently discovered sudo heap overflow vulnerability.
CVE-2021-3156HIGHunder attack27 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC35
mr-r3b00t/CVE-2021-3156
CVE-2021-3156HIGHunder attack26 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC2
CVE-2021-3441 CVE Check is a python script to search targets for indicators of compromise to CVE-2021-3441
CVE-2021-344126 Jan 2021
A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross
23RISK
open
Exploit-DB
Oracle WebLogic Server 12.2.1.0 - RCE (Unauthenticated)
CVE-2020-14882CRITICALunder attackwebappsjava26 Jan 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Exploit-DB
Tenda AC5 AC1200 Wireless - 'WiFi Name & Password' Stored Cross Site Scripting
CVE-2021-3186webappshardware26 Jan 2021
A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_m
23RISK
open
Metasploit600
Sudo Heap-Based Buffer Overflow
CVE-2021-3156HIGHunder attack26 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware25 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC5
用于对WebLogic(10.3.6.0.0 ;12.1.3.0.0 ;12.2.1.3.0; 12.2.1.4.0 ;14.1.1.0.0)进行验证及利用
CVE-2020-14883HIGHunder attack25 Jan 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
Quick and dirty bruteforcer for CVE-2018-7669 (Directory Traversal Vulnerability in Sitecore)
CVE-2018-766925 Jan 2021
An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application
28RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware25 Jan 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC6
SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.
CVE-2017-11882HIGHunder attackransomware25 Jan 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC78
SecPros-Team/laravel-CVE-2021-3129-EXP
CVE-2021-3129CRITICALunder attackransomware25 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
Exploit-DBVexDay Proof
Klog Server 2.4.1 - Unauthenticated Command Injection (Metasploit)
CVE-2020-35729webappsphp25 Jan 2021
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RISK
open
VulnCheck XDB
local
CVE-2020-27950MEDIUMunder attack24 Jan 2021
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RISK
open
VulnCheck XDB
initial-access
CVE-2020-17144HIGHunder attack24 Jan 2021
Microsoft Exchange Remote Code Execution Vulnerability
83RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-17144HIGHunder attack24 Jan 2021
Microsoft Exchange Remote Code Execution Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack24 Jan 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALunder attack24 Jan 2021
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
VulnCheck XDB
client-side
CVE-2020-820924 Jan 2021
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix Xe
50RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack24 Jan 2021
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-3452HIGHunder attack24 Jan 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALunder attack24 Jan 2021
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
GitHub PoC6
CVE-2020-8597 in RM2100
CVE-2020-8597CRITICAL24 Jan 2021
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RISK
open
GitHub PoC
killmonday/CVE-2020-17530-s2-061
CVE-2020-17530CRITICALunder attack24 Jan 2021
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
GitHub PoC1
findcool/cve-2021-1647
CVE-2021-1647HIGHunder attack23 Jan 2021
Microsoft Defender Remote Code Execution Vulnerability
83RISK
open
Exploit-DB
Atlassian Confluence Widget Connector Macro - SSTI
CVE-2019-3396CRITICALunder attackransomwarewebappsmultiple22 Jan 2021
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC135
Laravel debug rce
CVE-2021-3129CRITICALunder attackransomware22 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
previouspage 729 / 2,636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.