Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
13,937 exploits
GitHub PoC1
confluence远程代码执行RCE / Code By:Jun_sheng
CVE-2021-26084CRITICALunder attackransomware25 Oct 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC45
LPE exploit for a UAF in Windows (CVE-2021-40449).
CVE-2021-40449HIGHunder attackransomware25 Oct 2021
Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC18
PoC for the CVE-2021-20837 : RCE in MovableType
CVE-2021-2083725 Oct 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open
GitHub PoC
Script fo testing CVE-2000-0649 for Apache and MS IIS servers
CVE-2000-064925 Oct 2021
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RISK
open
GitHub PoC12
CVE-2021-40438 exploit PoC with Docker setup.
CVE-2021-40438CRITICALunder attackransomware24 Oct 2021
mod_proxy SSRF
100RISK
open
GitHub PoC1
Serv-U-FTP CVE-2021-35211 exploit
CVE-2021-35211CRITICALunder attackransomware24 Oct 2021
Serv-U Remote Memory Escape Vulnerability
100RISK
open
GitHub PoC
tiagob0b/CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware24 Oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
tiagob0b/CVE-2021-22005
CVE-2021-22005CRITICALunder attackransomware24 Oct 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
GitHub PoC7
PoC CVE-2021-42013 reverse shell Apache 2.4.50 with CGI
CVE-2021-42013CRITICALunder attackransomware24 Oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
Poc CVE-2021-41773 - Apache 2.4.49 with CGI enabled
CVE-2021-41773HIGHunder attackransomware23 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
Poc CVE-2021-42013 - Apache 2.4.50 without CGI
CVE-2021-42013CRITICALunder attackransomware23 Oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC2
cve-2021-41773.py is a python script that will help in finding Path Traversal or Remote Code Execution vulnerability in Apache 2.4.49
CVE-2021-41773HIGHunder attackransomware23 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
BabyTeam1024/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware22 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
scopion/CVE-2017-3241
CVE-2017-324122 Oct 2021
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RISK
open
GitHub PoC1
Exploit CVE 2021 26084 Confluence
CVE-2021-26084CRITICALunder attackransomware20 Oct 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC2
Just a simple CVE-2021-31166 exploit tool
CVE-2021-31166CRITICALunder attack20 Oct 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
GitHub PoC98
windows 10 14393 LPE
CVE-2021-40449HIGHunder attackransomware20 Oct 2021
Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
THIS IS NOT AN ORIGINAL EXPLOIT. THIS IS AN AUDITED VERSION FOR A THM BOX
CVE-2020-10915CRITICAL20 Oct 2021
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.
85RISK
open
GitHub PoC
LayarKacaSiber/CVE-2021-42013
CVE-2021-42013CRITICALunder attackransomware20 Oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
LayarKacaSiber/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware20 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
CVE-2021-3156 exploit
CVE-2021-3156HIGHunder attack20 Oct 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
bibo318/kali-CVE-2019-0708-lab
CVE-2019-0708CRITICALunder attackransomware19 Oct 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
Lab setup for CVE-2021-41773 (Apache httpd 2.4.49) and CVE-2021-42013 (Apache httpd 2.4.50).
CVE-2021-41773HIGHunder attackransomware18 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC17
CVE-2021-36260
CVE-2021-36260CRITICALunder attack18 Oct 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC1
Exploit For CVE-2019-17662
CVE-2019-1766218 Oct 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISK
open
GitHub PoC4
xiaojiangxl/CVE-2021-40438
CVE-2021-40438CRITICALunder attackransomware18 Oct 2021
mod_proxy SSRF
100RISK
open
GitHub PoC3
Dahua IPC/VTH/VTO devices auth bypass exploit
CVE-2021-33044CRITICALunder attack18 Oct 2021
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
GitHub PoC11
Scanner for CVE-2022-22948 an Information Disclosure in VMWare vCenter
CVE-2022-22948MEDIUMunder attack17 Oct 2021
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious act
83RISK
open
GitHub PoC35
Little thing put together quickly to demonstrate this CVE
CVE-2020-11022MEDIUM16 Oct 2021
jQuery has a potential XSS vulnerability
55RISK
open
GitHub PoC
TIC4301 Project - CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware16 Oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
previouspage 353 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.