Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
8,225 exploits
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack22 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack22 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack22 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack22 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack21 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack20 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack20 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware20 Jul 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
client-side
CVE-2020-1938CRITICALunder attack20 Jul 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack19 Jul 2021
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-36942HIGHunder attackransomware18 Jul 2021
Windows LSA Spoofing Vulnerability
98RISK
open
VulnCheck XDB
initial-access
CVE-2021-21315HIGHunder attack18 Jul 2021
Command Injection Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2022-39197MEDIUMunder attack17 Jul 2021
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISK
open
VulnCheck XDB
local
CVE-2021-22555HIGHunder attack16 Jul 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALunder attack16 Jul 2021
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack16 Jul 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware16 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware15 Jul 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware15 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-5689CRITICALunder attack14 Jul 2021
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3046114 Jul 2021
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware13 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware12 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALunder attack12 Jul 2021
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALunder attack12 Jul 2021
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-34527HIGHunder attackransomware09 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-1956HIGHunder attack08 Jul 2021
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the
100RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack07 Jul 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware07 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware07 Jul 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
previouspage 217 / 275next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.