Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
13,937 exploits
GitHub PoC16
rfcxv/CVE-2021-40444-POC
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC7
CVE-2021-40444 POC
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Immersive-Labs-Sec/cve-2021-40444-analysis
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
根据已知样本反编译代码
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
maguireja/CVE-2020-25223
CVE-2020-25223CRITICALunder attack09 Sep 2021
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISK
open
GitHub PoC3
vysecurity/CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Confluence OGNL injection
CVE-2021-26084CRITICALunder attackransomware09 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
Something I wrote for CVE-2019-15107, a Webmin backdoor
CVE-2019-15107CRITICALunder attackransomware09 Sep 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC3
CVE-2020-9054 PoC for Zyxel
CVE-2020-9054CRITICALunder attack09 Sep 2021
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
100RISK
open
GitHub PoC2
Exploit chain for CVE-2019-9791 & CVE-2019-11708 against firefox 65.0 on windows 64bit
CVE-2019-979108 Sep 2021
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects w
28RISK
open
GitHub PoC1
CVE-2021-26084 patch as provided in "Confluence Security Advisory - 2021-08-25"
CVE-2021-26084CRITICALunder attackransomware08 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC16
Microsoft MSHTML Remote Code Execution Vulnerability CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware08 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
Patched Confluence 7.12.2 (CVE-2021-26084)
CVE-2021-26084CRITICALunder attackransomware08 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC1
A quick and dirty PoC of cve-2021-26084 as none of the existing ones worked for me.
CVE-2021-26084CRITICALunder attackransomware07 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC30
Atlassian Confluence CVE-2021-26084 one-liner mass checker
CVE-2021-26084CRITICALunder attackransomware07 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC1
Modified Verion of CVE-2016-0792
CVE-2016-079207 Sep 2021
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RISK
open
GitHub PoC4
alikarimi999/CVE-2021-21315
CVE-2021-21315HIGHunder attack07 Sep 2021
Command Injection Vulnerability
100RISK
open
GitHub PoC5
A vulnerability can allow an attacker to guess the automatically generated development mode secret token.
CVE-2019-542006 Sep 2021
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
GitHub PoC
Confluence OGNL Injection [CVE-2021-26084].
CVE-2021-26086MEDIUMunder attack05 Sep 2021
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RISK
open
GitHub PoC2
CVE-2021-34646 PoC
CVE-2021-34646CRITICAL04 Sep 2021
Booster for WooCommerce <= 5.4.3 Authentication Bypass
60RISK
open
GitHub PoC1
Wordpress Plainview Activity Monitor Plugin RCE (20161228)
CVE-2018-1587704 Sep 2021
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RISK
open
GitHub PoC
Setting up POC for CVE-2021-26084
CVE-2021-26084CRITICALunder attackransomware04 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC2
Anonimo501/SMBGhost_CVE-2020-0796_checker
CVE-2020-0796CRITICALunder attackransomware04 Sep 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
BabyTeam1024/cve-2018-2628
CVE-2018-2628CRITICALunder attack04 Sep 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC42
A Python replicated exploit for Webmin 1.580 /file/show.cgi Remote Code Execution
CVE-2012-298204 Sep 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
GitHub PoC120
Proof of Concept for CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207
CVE-2021-34473CRITICALunder attackransomware04 Sep 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
CVE-2021-26084
CVE-2021-26084CRITICALunder attackransomware03 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC3
CVE-2021-26084 Confluence OGNL injection
CVE-2021-26084CRITICALunder attackransomware03 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC4
Exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT.
CVE-2018-011403 Sep 2021
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
GitHub PoC
cve-2021-26084 EXP
CVE-2021-26084CRITICALunder attackransomware03 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
previouspage 360 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.