Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
13,937 exploits
GitHub PoC3
To fight against Windows security breach PrintNightmare! (CVE-2021-34527, CVE-2021-1675)
CVE-2021-34527HIGHunder attackransomware28 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
NYCY_homework_&_meeting
CVE-2021-3560HIGHunder attack28 Jul 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC7
HiveNightmare aka SeriousSAM
CVE-2021-36934HIGHunder attack27 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC1
An implementation of CVE-2017-12617
CVE-2017-12617HIGHunder attack27 Jul 2021
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
GitHub PoC
Exodusro/CVE-2021-3156
CVE-2021-3156HIGHunder attack26 Jul 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC3
haidv35/CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware26 Jul 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC1
0x0D1n/CVE-2021-36934
CVE-2021-36934HIGHunder attack26 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC
This PowerShell script will take the mitigation measures for CVE-2021-36934 described by Microsoft and the US CERT team. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36934 https://kb.cert.org/vuls/id/506989 USE AT YOUR OWN RISK -- BACKUPS MAY BREAK.
CVE-2021-36934HIGHunder attack25 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC5
PoC for CVE-2021-36934 Aka HiveNightmare/SeriousSAM written in python3
CVE-2021-36934HIGHunder attack25 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC3
C# PoC for CVE-2021-36934/HiveNightmare/SeriousSAM
CVE-2021-36934HIGHunder attack24 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC1
This Repo is PoC environment of CVE-2014-6271(https://nvd.nist.gov/vuln/detail/cve-2014-6271).
CVE-2014-6271CRITICALunder attack24 Jul 2021
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Exploit Analysis of The WhatsApp Double-Free Vulnerability (CVE-2019-11932) Using the GEF-GDB Debugger
CVE-2019-1193223 Jul 2021
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
GitHub PoC
3t4n/samba-3.0.24-CVE-2007-2447-vunerable-
CVE-2007-244723 Jul 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC2
Windows Elevation of Privilege Vulnerability (SeriousSAM)
CVE-2021-36934HIGHunder attack22 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC9
HiveNightmare a.k.a. SeriousSam Local Privilege Escalation in Windows – CVE-2021-36934
CVE-2021-36934HIGHunder attack22 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC1
A capability to identify and remediate CVE-2021-36934 (HiveNightmare)
CVE-2021-36934HIGHunder attack22 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC1
CVE-2021-36934 PowerShell Fix
CVE-2021-36934HIGHunder attack22 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC1
CVE-2021-36934 PowerShell scripts
CVE-2021-36934HIGHunder attack22 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC8
Small and dirty PoC for CVE-2021-36934
CVE-2021-36934HIGHunder attack22 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC35
PoC for CVE-2021-36934, which enables a standard user to be able to retrieve the SAM, Security, and Software Registry hives in Windows 10 version 1809 or newer
CVE-2021-36934HIGHunder attack22 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC3
see https://github.com/cube0x0/CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware22 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
magichk/cve-2021-22146
CVE-2021-2214622 Jul 2021
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.
28RISK
open
GitHub PoC1
idea-oss/laravel-CVE-2021-3129-EXP
CVE-2021-3129CRITICALunder attackransomware22 Jul 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC5
Detection and Mitigation script for CVE-2021-36934 (HiveNightmare aka. SeriousSam)
CVE-2021-36934HIGHunder attack21 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC9
Fix for the CVE-2021-36934
CVE-2021-36934HIGHunder attack21 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC210
Pure Nim implementation for exploiting CVE-2021-36934, the SeriousSAM local privilege escalation
CVE-2021-36934HIGHunder attack20 Jul 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC1
Winter3un/CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware20 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
h3x0v3rl0rd/CVE-2019-16278
CVE-2019-16278CRITICALunder attack19 Jul 2021
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC
zha0/Microsoft-CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware18 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
systeminformation
CVE-2021-21315HIGHunder attack18 Jul 2021
Command Injection Vulnerability
100RISK
open
previouspage 364 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.