Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
13,937 exploits
GitHub PoC2
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
CVE-2018-1676327 Sep 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC1
CVE-2021-22005_PoC
CVE-2021-22005CRITICALunder attackransomware27 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
GitHub PoC3
CVE-2019-19781
CVE-2019-19781CRITICALunder attackransomware27 Sep 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC19
Windows HTTP协议栈远程代码执行漏洞 CVE-2021-31166
CVE-2021-31166CRITICALunder attack27 Sep 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Sudo heap-based buffer overflow privilege escalation commands and mitigations.
CVE-2021-3156HIGHunder attack27 Sep 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC209
Python implementation for PrintNightmare (CVE-2021-1675 / CVE-2021-34527)
CVE-2021-1675HIGHunder attackransomware26 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Quick and dirty CVE-2021-38647 (Omigod) exploit written in Go.
CVE-2021-38647CRITICALunder attackransomware26 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
GitHub PoC10
C# PrintNightmare (CVE-2021-1675)
CVE-2021-1675HIGHunder attackransomware26 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
AmesianX/CVE-2021-21220
CVE-2021-21220HIGHunder attack26 Sep 2021
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
98RISK
open
GitHub PoC17
CVE-2021-3156 - sudo exploit for ubuntu 18.04 & 20.04
CVE-2021-3156HIGHunder attack25 Sep 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC1
Python script to obtain RCE on Mantis Bug Tracker prior to version 1.2.x Check CVE-2008-4687 for additional information
CVE-2008-468725 Sep 2021
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISK
open
GitHub PoC13
CVE-2021-22005批量验证python脚本
CVE-2021-22005CRITICALunder attackransomware25 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
GitHub PoC1
CVE-2021-38647 is an unauthenticated RCE vulnerability effecting the OMI agent as root.
CVE-2021-38647CRITICALunder attackransomware24 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
CVE-2021-22005
CVE-2021-22005CRITICALunder attackransomware24 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
GitHub PoC5
CVE-2021-33739 PoC Analysis
CVE-2021-33739HIGHunder attack24 Sep 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC1
Windows Kernel Registry Elevation of Privilege Vulnerability
CVE-2018-841024 Sep 2021
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory
23RISK
open
GitHub PoC
CVE 2021 40444 Windows Exploit services.dll
CVE-2021-40444HIGHunder attackransomware24 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
BeneficialCode/CVE-2021-1732
CVE-2021-1732HIGHunder attackransomware24 Sep 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC8
1ZRR4H/CVE-2021-22005
CVE-2021-22005CRITICALunder attackransomware23 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
GitHub PoC1
pisut4152/Sigma-Rule-for-CVE-2021-22005-scanning-activity
CVE-2021-22005CRITICALunder attackransomware23 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
GitHub PoC
https://github.com/corelight/CVE-2021-38647 without the bloat
CVE-2021-38647CRITICALunder attackransomware22 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
GitHub PoC68
CVE-2021-38647 - POC to exploit unauthenticated RCE #OMIGOD
CVE-2021-38647CRITICALunder attackransomware20 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
OMIGod / CVE-2021-38647 POC and Demo environment
CVE-2021-38647CRITICALunder attackransomware19 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Converted Metasploit exploits for Adobe Flash vulnerabilities CVE-2015-3090, CVE-2015-3105, CVE-2015-5119, and CVE-2015-5122 to a Python3 script.
CVE-2015-309019 Sep 2021
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
60RISK
open
GitHub PoC102
Modified code so that we don´t need to rely on CAB archives
CVE-2021-40444HIGHunder attackransomware19 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Modifed ver of the original exploit to save some times on password reseting for unprivileged user
CVE-2021-2291119 Sep 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
GitHub PoC1
A Vagrant VM test lab to learn about CVE-2021-38647 in the Open Management Infrastructure agent (aka "omigod").
CVE-2021-38647CRITICALunder attackransomware18 Sep 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
[CVE-2021-26084] Confluence pre-auth RCE test script
CVE-2021-26084CRITICALunder attackransomware18 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC11
Scan for evidence of CVE-2021-30860 (FORCEDENTRY) exploit
CVE-2021-30860HIGHunder attack18 Sep 2021
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catali
93RISK
open
GitHub PoC2
CVE-2021-40539 POC
CVE-2021-40539CRITICALunder attackransomware17 Sep 2021
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open
previouspage 358 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.