Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,937VulnCheck XDB 8,510Nuclei 4,239Metasploit 3,468✓ verified onlyrecentpopularrisk
13,937 exploits
GitHub PoC★ 9
quynhle7821/CVE-2021-2302
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported
48RISK
open ↗GitHub PoC★ 6
CVE-2021-2456
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana
70RISK
open ↗GitHub PoC★ 2
A PoC exploit for CVE-2021-38647 RCE in OMI
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 233
Proof on Concept Exploit for CVE-2021-38647 (OMIGOD)
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 20
OMIGOD! OM I GOOD? A free scanner to detect VMs vulnerable to one of the "OMIGOD" vulnerabilities discovered by Wiz's threat research team, specifically CVE-2021-38647.
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 8
CVE-2021-38647 POC for RCE
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 5
CVE-2021-38647 AKA "OMIGOD" vulnerability in Windows OMI
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 10
CVE-2021-33766-poc
Microsoft Exchange Server Information Disclosure Vulnerability
100RISK
open ↗GitHub PoC
jaysharma786/CVE-2021-29003
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacter
35RISK
open ↗GitHub PoC★ 824
CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
Malicious document builder for CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 19
k8gege/CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 3
CVE-2018-15473 Exploit
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open ↗GitHub PoC★ 8
CVE-2021-40875: Tools to Inspect Gurock Testrail Servers for Vulnerabilities related to CVE-2021-40875.
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat ac
50RISK
open ↗GitHub PoC★ 1
POC for CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
W1kyri3/Exploit-PoC-CVE-2021-40444-inject-ma-doc-vao-docx
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
Reverse engineering the "A Letter Before Court 4.docx" malicious files exploting cve-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 16
Mass exploitation of CVE-2021-24499 unauthenticated upload leading to remote code execution in Workreap theme.
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISK
open ↗GitHub PoC★ 168
This repo contain builders of cab file, html file, and docx file for CVE-2021-40444 exploit
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
2021 kernel vulnerability in Ubuntu.
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗GitHub PoC
CVE-2021-21972 vCenter-6.5-7.0 RCE POC
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open ↗GitHub PoC
Strapi Remote Code Execution
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open ↗GitHub PoC★ 4
fengjixuchui/CVE-2021-40444-docx-Generate
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
KnoooW/CVE-2021-40444-docx-Generate
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 11
A malicious .cab creation tool for CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
Hunting CVE-2018-13379
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open ↗GitHub PoC
sbladiamond/CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open ↗GitHub PoC★ 1
koharin/CVE-2020-0041
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISK
open ↗GitHub PoC★ 1
CVE-2021-40444 Sample
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1,743
CVE-2021-40444 PoC
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.