Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
13,947 exploits
GitHub PoC8
Python3 POC for CVE 2020-11060
CVE-2020-11060HIGH11 Jun 2021
Remote Code Execution in GLPI
46RISK
open
GitHub PoC82
CVE-2021-3560 Local PrivEsc Exploit
CVE-2021-3560HIGHunder attack11 Jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC5
Automatic Explotation PoC for Polkit CVE-2021-3560
CVE-2021-3560HIGHunder attack11 Jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC2
CrackerCat/CVE-2020-1020-Exploit
CVE-2020-1020HIGHunder attack10 Jun 2021
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RISK
open
GitHub PoC
sujaygr8/CVE-2020-3452
CVE-2020-3452HIGHunder attack10 Jun 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC10
freeide2017/CVE-2021-33739-POC
CVE-2021-33739HIGHunder attack09 Jun 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
CVE-2017-9554 Exploit Tool
CVE-2017-955408 Jun 2021
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RISK
open
GitHub PoC4
kienquoc102/CVE-2018-9995-2
CVE-2018-999507 Jun 2021
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC7
suprise4u/CVE-2019-1388
CVE-2019-1388HIGHunder attackransomware07 Jun 2021
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RISK
open
GitHub PoC
Bludit 3.9.2 - Auth Brute Force Mitigation Bypass. CVE-2019-17240
CVE-2019-17240LOW07 Jun 2021
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
GitHub PoC4
Unsafe Twig processing of static pages leading to RCE in Grav CMS 1.7.10
CVE-2021-29440HIGH06 Jun 2021
Twig allowing dangerous PHP functions by default
53RISK
open
GitHub PoC
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
CVE-2020-949606 Jun 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
GitHub PoC1
Drupal 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
CVE-2018-7600CRITICALunder attackransomware05 Jun 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC29
testanull/Project_CVE-2021-21985_PoC
CVE-2021-21985CRITICALunder attackransomware05 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC60
Pre-Auth Blind NoSQL Injection leading to Remote Code Execution in Rocket Chat 3.12.1
CVE-2021-2291105 Jun 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
GitHub PoC181
mr-r3bot/Gitlab-CVE-2021-22205
CVE-2021-22205CRITICALunder attackransomware05 Jun 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC70
This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists of embedded payload. The exploit was made public as CVE-2010-1240.
CVE-2010-124005 Jun 2021
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISK
open
GitHub PoC2
CVE-2021-21985 vmware 6.7-9.8 RCE
CVE-2021-21985CRITICALunder attackransomware04 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC115
cve-2021-21985 exploit
CVE-2021-21985CRITICALunder attackransomware03 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC
PHPFusion 9.03.50 - Remote Code Execution
CVE-2020-2494903 Jun 2021
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr
50RISK
open
GitHub PoC
This vulnerability exists in OpenBSD’s mail server OpenSMTPD’s “smtp_mailaddr()” function, and affects OpenBSD version 6.6. This allows an attacker to execute arbitrary shell commands like “sleep 66” as root user
CVE-2020-7247CRITICALunder attack02 Jun 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
GitHub PoC23
An extended proof-of-concept for the CVE-2021-21551 Dell ‘dbutil_2_3.sys’ Kernel Exploit
CVE-2021-21551HIGHunder attack02 Jun 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISK
open
GitHub PoC
LogonTracer v1.2.0 RCE
CVE-2018-1616702 Jun 2021
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
60RISK
open
GitHub PoC9
bluefrostsecurity/CVE-2021-28476
CVE-2021-28476CRITICAL02 Jun 2021
Windows Hyper-V Remote Code Execution Vulnerability
60RISK
open
GitHub PoC3
Wordpress XXE injection 구축 자동화 및 PoC
CVE-2021-29447HIGH01 Jun 2021
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC2
CVE-2021-21985 Checker.
CVE-2021-21985CRITICALunder attackransomware01 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC
This script check the CVE-2021-21985 vulnerability and patch on vCenter Server.
CVE-2021-21985CRITICALunder attackransomware01 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC
rnnsz/CVE-2017-15950
CVE-2017-1595031 May 2021
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary co
23RISK
open
GitHub PoC3
python3 POC for CVE-2019-2729 WebLogic Deserialization Vulnerability and CVE-2017-10271 amongst others
CVE-2017-10271HIGHunder attackransomware31 May 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC226
PoC for CVE-2021-28476 a guest-to-host "Hyper-V Remote Code Execution Vulnerability" in vmswitch.sys.
CVE-2021-28476CRITICAL31 May 2021
Windows Hyper-V Remote Code Execution Vulnerability
60RISK
open
previouspage 369 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.