Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,509cataloged exploits
34,970CVEs with public exploitation
24,695lab-tested
13,941 exploits
GitHub PoC13
freeide/CVE-2021-31955-POC
CVE-2021-31955MEDIUMunder attack26 Jun 2021
Windows Kernel Information Disclosure Vulnerability
85RISK
open
GitHub PoC
compiled CVE-2015-1328
CVE-2015-132826 Jun 2021
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
GitHub PoC1
donghyunlee00/CVE-2021-3156
CVE-2021-3156HIGHunder attack25 Jun 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC9
Hudi233/CVE-2020-3580
CVE-2020-3580MEDIUMunder attackransomware25 Jun 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
100RISK
open
GitHub PoC12
GravCMS Unauthenticated Arbitrary YAML Write/Update leads to Code Execution (CVE-2021-21425)
CVE-2021-21425CRITICAL24 Jun 2021
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISK
open
GitHub PoC1
Remote Command Execution through Unvalidated File Upload in SeedDMS versions <5.1.11
CVE-2019-1274424 Jun 2021
SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a differe
28RISK
open
GitHub PoC
Badbird3/CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware24 Jun 2021
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC11
Zeroscan is a Domain Controller vulnerability scanner, that currently includes checks for Zerologon (CVE-2020-1472), MS-PAR/MS-RPRN and SMBv2 Signing.
CVE-2020-1472MEDIUMunder attackransomware23 Jun 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
m3terpreter/CVE-2016-4437
CVE-2016-4437CRITICALunder attack22 Jun 2021
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISK
open
GitHub PoC
pywc/CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware21 Jun 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC126
Privilege escalation with polkit - CVE-2021-3560
CVE-2021-3560HIGHunder attack19 Jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC1
POC-CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware19 Jun 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC2
PoC exploit for CVE-2020-7247 OpenSMTPD 6.4.0 < 6.6.1 Remote Code Execution
CVE-2020-7247CRITICALunder attack19 Jun 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
GitHub PoC
h3x0v3rl0rd/CVE-2019-14287
CVE-2019-1428717 Jun 2021
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC
Polkit - Local Privilege Escalation (CVE-2021-3560)
CVE-2021-3560HIGHunder attack15 Jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC1
spyx/cve-2019-17240
CVE-2019-17240LOW15 Jun 2021
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
GitHub PoC124
secnigma/CVE-2021-3560-Polkit-Privilege-Esclation
CVE-2021-3560HIGHunder attack14 Jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC
polkit exploit script v1.0
CVE-2021-3560HIGHunder attack14 Jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC8
CVE-2018-19422 Authenticated Remote Code Execution
CVE-2018-1942214 Jun 2021
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RISK
open
GitHub PoC
sujaygr8/CVE-2020-3187
CVE-2020-3187CRITICAL14 Jun 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISK
open
GitHub PoC1
CVE-2021–22201 Arbitrary file read on Gitlab
CVE-2021-22201CRITICAL13 Jun 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file
48RISK
open
GitHub PoC2
ZeroShell 3.9.0 Remote Command Injection
CVE-2019-1272513 Jun 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
GitHub PoC19
wpDiscuz 7.0.4 Remote Code Execution
CVE-2020-24186CRITICAL13 Jun 2021
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISK
open
GitHub PoC40
a reliable C based exploit and writeup for CVE-2021-3560.
CVE-2021-3560HIGHunder attack12 Jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC8
Python3 POC for CVE 2020-11060
CVE-2020-11060HIGH11 Jun 2021
Remote Code Execution in GLPI
46RISK
open
GitHub PoC5
Automatic Explotation PoC for Polkit CVE-2021-3560
CVE-2021-3560HIGHunder attack11 Jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC82
CVE-2021-3560 Local PrivEsc Exploit
CVE-2021-3560HIGHunder attack11 Jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC2
CrackerCat/CVE-2020-1020-Exploit
CVE-2020-1020HIGHunder attack10 Jun 2021
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RISK
open
GitHub PoC
sujaygr8/CVE-2020-3452
CVE-2020-3452HIGHunder attack10 Jun 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC10
freeide2017/CVE-2021-33739-POC
CVE-2021-33739HIGHunder attack09 Jun 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RISK
open
previouspage 368 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.