Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
8,225 exploits
VulnCheck XDB
client-side
CVE-2015-5119HIGHunder attack19 Sep 2021
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RISK
open
VulnCheck XDB
client-side
CVE-2015-5122HIGHunder attack19 Sep 2021
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware19 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware18 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware18 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware17 Sep 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware15 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware15 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-33766HIGHunder attack15 Sep 2021
Microsoft Exchange Server Information Disclosure Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware14 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware13 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
info-leak
CVE-2020-2865313 Sep 2021
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v
60RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack12 Sep 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware12 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware12 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack12 Sep 2021
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-1960911 Sep 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
VulnCheck XDB
infoleak
CVE-2020-25078HIGHunder attack10 Sep 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware10 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-9054CRITICALunder attack09 Sep 2021
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
100RISK
open
VulnCheck XDB
client-side
CVE-2019-11708CRITICALunder attack08 Sep 2021
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RISK
open
VulnCheck XDB
infoleak
CVE-2020-5410HIGHunder attack08 Sep 2021
Directory Traversal with spring-cloud-config-server
100RISK
open
VulnCheck XDB
client-side
CVE-2021-26084CRITICALunder attackransomware08 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware07 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
local
CVE-2018-100000107 Sep 2021
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISK
open
VulnCheck XDB
initial-access
CVE-2021-21315HIGHunder attack07 Sep 2021
Command Injection Vulnerability
100RISK
open
previouspage 213 / 275next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.