Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
13,937 exploits
GitHub PoC
Exploit and Demo system for CVE-2021-3156
CVE-2021-3156HIGHunder attack01 Nov 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
MovableType XMLRPC - RCE
CVE-2021-2083701 Nov 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open
GitHub PoC3
CVE-2021-22205-getshell
CVE-2021-22205CRITICALunder attackransomware01 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC13
CVE-2021-22205 RCE
CVE-2021-22205CRITICALunder attackransomware31 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC23
CVE-2021-22205 Gitlab 未授权远程代码执行漏洞 EXP, 移除了对djvumake & djvulibre的依赖,可在win平台使用
CVE-2021-22205CRITICALunder attackransomware30 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC2
PoC in single line bash
CVE-2021-22205CRITICALunder attackransomware30 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC
C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode in…
CVE-2021-26855CRITICALunder attackransomware30 Oct 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC21
XMLRPC - RCE in MovableTypePoC
CVE-2021-2083730 Oct 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open
GitHub PoC2
kienquoc102/CVE-2017-8225
CVE-2017-822530 Oct 2021
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
28RISK
open
GitHub PoC
scopion/CVE-2020-10963
CVE-2020-1096329 Oct 2021
FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution)
28RISK
open
GitHub PoC
0xAgun/CVE-2019-18935-checker
CVE-2019-18935CRITICALunder attackransomware29 Oct 2021
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC
scopion/CVE-2018-8947
CVE-2018-894729 Oct 2021
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easi
28RISK
open
GitHub PoC7
Gitlab CE/EE RCE 未授权远程代码执行漏洞 POC && EXP CVE-2021-22205
CVE-2021-22205CRITICALunder attackransomware29 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC285
CVE-2021-22205& GitLab CE/EE RCE
CVE-2021-22205CRITICALunder attackransomware29 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC
Setup vulnerable enviornment
CVE-2021-41773HIGHunder attackransomware29 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC69
CVE-2021-22205 Unauthorized RCE
CVE-2021-22205CRITICALunder attackransomware28 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC1
批量扫描CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware28 Oct 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC86
Pocsuite3 For CVE-2021-22205
CVE-2021-22205CRITICALunder attackransomware28 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC2
BabyTeam1024/CVE-2021-40438
CVE-2021-40438CRITICALunder attackransomware28 Oct 2021
mod_proxy SSRF
100RISK
open
GitHub PoC9
An attempt to reproduce Microsoft MSHTML Remote Code Execution (RCE) Vulnerability and using Metasploit Framework.
CVE-2021-40444HIGHunder attackransomware28 Oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC21
VMware vCenter Server任意文件上传漏洞 / Code By:Jun_sheng
CVE-2021-22005CRITICALunder attackransomware27 Oct 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
GitHub PoC
b1tg/CVE-2021-34486-exp
CVE-2021-34486HIGHunder attack27 Oct 2021
Windows Event Tracing Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC27
cve-2021-42013.py is a python script that will help in finding Path Traversal or Remote Code Execution vulnerability in Apache 2.4.50
CVE-2021-42013CRITICALunder attackransomware27 Oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
RB4C/drupalgeddon2-CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware27 Oct 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
rafaelcaria/drupalgeddon2-CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware27 Oct 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC296
command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
CVE-2021-36260CRITICALunder attack27 Oct 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC7
CVE-2021-26084,Atlassian Confluence OGNL注入漏洞
CVE-2021-26084CRITICALunder attackransomware26 Oct 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC11
Remote Code Execution exploit for Apache servers. Affected versions: Apache 2.4.49, Apache 2.4.50
CVE-2021-41773HIGHunder attackransomware26 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
A automatic scanner to apache 2.4.49
CVE-2021-41773HIGHunder attackransomware25 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC45
LPE exploit for a UAF in Windows (CVE-2021-40449).
CVE-2021-40449HIGHunder attackransomware25 Oct 2021
Win32k Elevation of Privilege Vulnerability
100RISK
open
previouspage 352 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.