Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
13,937 exploits
GitHub PoC4
Exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT.
CVE-2018-011403 Sep 2021
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
GitHub PoC
Just run command without brain
CVE-2021-26084CRITICALunder attackransomware02 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
This is exploit
CVE-2021-26084CRITICALunder attackransomware02 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC3
This nuclei template is to verify the vulnerability without executing any commands to the target machine
CVE-2021-26084CRITICALunder attackransomware02 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC5
CVE-2021-26084 Remote Code Execution on Confluence Servers, reference: https://github.com/httpvoid/writeups/blob/main/Confluence-RCE.md
CVE-2021-26084CRITICALunder attackransomware01 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
CVE-2021-26084 Remote Code Execution on Confluence Servers
CVE-2021-26084CRITICALunder attackransomware01 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC8
Remote Code Execution on Confluence Servers : CVE-2021-26084
CVE-2021-26084CRITICALunder attackransomware01 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC125
A basic PoC leak for CVE-2021-28663 (Internal of the Android kernel backdoor vulnerability)
CVE-2021-28663HIGHunder attack01 Sep 2021
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are m
76RISK
open
GitHub PoC
批量检测
CVE-2021-26084CRITICALunder attackransomware01 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC8
CVE-2021-26084 - Confluence Server Webwork OGNL injection (Pre-Auth RCE)
CVE-2021-26084CRITICALunder attackransomware01 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC53
dinhbaouit/CVE-2021-26084
CVE-2021-26084CRITICALunder attackransomware01 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
Atlassian Confluence Pre-Auth RCE
CVE-2021-26084CRITICALunder attackransomware01 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC317
Confluence Server Webwork OGNL injection
CVE-2021-26084CRITICALunder attackransomware01 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC1
CVE-2021-26084 - Confluence Pre-Auth RCE OGNL injection 回显
CVE-2021-26084CRITICALunder attackransomware01 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC72
CVE-2021-26084 Remote Code Execution on Confluence Servers
CVE-2021-26084CRITICALunder attackransomware01 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC2
9lyph/CVE-2021-45901
CVE-2021-4590101 Sep 2021
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending
28RISK
open
GitHub PoC1
PoC of CVE-2021-26084 written in Golang based on https://twitter.com/jas502n/status/1433044110277890057?s=20
CVE-2021-26084CRITICALunder attackransomware01 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC145
PrintNightMare LPE提权漏洞的CS 反射加载插件。开箱即用、通过内存加载、混淆加载的驱动名称来ByPass Defender/EDR。
CVE-2021-1675HIGHunder attackransomware01 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC5
Draytek CVE-2020-8515 PoC
CVE-2020-8515CRITICALunder attack01 Sep 2021
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RISK
open
GitHub PoC3
allenenosh/CVE-2021-40352
CVE-2021-4035201 Sep 2021
OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can re
23RISK
open
GitHub PoC4
Remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data.
CVE-2016-209831 Aug 2021
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISK
open
GitHub PoC48
ProxyToken (CVE-2021-33766) : An Authentication Bypass in Microsoft Exchange Server POC exploit
CVE-2021-33766HIGHunder attack31 Aug 2021
Microsoft Exchange Server Information Disclosure Vulnerability
100RISK
open
GitHub PoC53
alt3kx/CVE-2021-26084_PoC
CVE-2021-26084CRITICALunder attackransomware31 Aug 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC1
Remote Code Execution vulnerability in PHPMailer.
CVE-2016-10033CRITICALunder attack31 Aug 2021
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
GitHub PoC
https://www.exploit-db.com/exploits/49757
CVE-2011-252331 Aug 2021
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC21
CVE-2021-26084 - Confluence Pre-Auth RCE | OGNL injection
CVE-2021-26084CRITICALunder attackransomware31 Aug 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC19
Exploit code for CVE-2019-17662
CVE-2019-1766231 Aug 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISK
open
GitHub PoC
Strapi <= 3.0.0-beta.17.8 authenticated remote code execution
CVE-2019-1960930 Aug 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
GitHub PoC7
Strapi Framework Vulnerable to Remote Code Execution
CVE-2019-1960929 Aug 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
GitHub PoC11
CVE-2020-25223
CVE-2020-25223CRITICALunder attack29 Aug 2021
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISK
open
previouspage 361 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.