Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
13,947 exploits
GitHub PoC20
Hancheng-Lei/Hacking-Vulnerability-CVE-2020-1938-Ghostcat
CVE-2020-1938CRITICALunder attack28 Mar 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC1
Another implementation for linux privilege escalation exploit via snap(d) (CVE-2019-7304)
CVE-2019-7304HIGH28 Mar 2021
Local privilege escalation via snapd socket
53RISK
open
GitHub PoC38
CVE-2021-22192 靶场: 未授权用户 RCE 漏洞
CVE-2021-22192CRITICAL27 Mar 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticat
53RISK
open
GitHub PoC
siramk/CVE-2018-1335
CVE-2018-133526 Mar 2021
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
GitHub PoC8
F5 BIG-IP远程代码执行;cve-2021-22986,批量检测;命令执行利用
CVE-2021-22986CRITICALunder attackransomware26 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC
Proof of concept for CVE-2020-11819 and CVE-2020-15946
CVE-2020-1181925 Mar 2021
In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve
28RISK
open
GitHub PoC1
Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995
CVE-2018-999525 Mar 2021
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC30
Vulnerability analysis and PoC for the Apache Tomcat - CGIServlet enableCmdLineArguments Remote Code Execution (RCE)
CVE-2019-023225 Mar 2021
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
GitHub PoC10
Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc
CVE-2021-2789025 Mar 2021
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
28RISK
open
GitHub PoC10
CVE-2017-0100、MS17-012、Eop
CVE-2017-010024 Mar 2021
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RISK
open
GitHub PoC52
Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.
CVE-2021-26855CRITICALunder attackransomware24 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
analytics ProxyLogo Mail exchange RCE
CVE-2021-26855CRITICALunder attackransomware23 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
CVE-2021-22986 Checker Script in Python3
CVE-2021-22986CRITICALunder attackransomware23 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC
kiri-48/CVE-2021-22986
CVE-2021-22986CRITICALunder attackransomware22 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC
Bypass bludit mitigation login form and upload malicious to call a rev shell
CVE-2019-17240LOW22 Mar 2021
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
GitHub PoC18
EEsshq/CVE-2017-0144---EtneralBlue-MS17-010-Remote-Code-Execution
CVE-2017-0144HIGHunder attackransomware22 Mar 2021
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
F5 BIG-IP/BIG-IQ iControl Rest API SSRF to RCE
CVE-2021-22986CRITICALunder attackransomware22 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC91
CVE-2021-22986 & F5 BIG-IP RCE
CVE-2021-22986CRITICALunder attackransomware22 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC
Microsoft Exchange Proxylogon Exploit Chain EXP分析
CVE-2021-26855CRITICALunder attackransomware21 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC4
CVE-2021-22986 F5 BIG-IP iControl 命令执行漏洞
CVE-2021-22986CRITICALunder attackransomware21 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC
A vulnerability scanner that detects CVE-2021-22986 vulnerabilities.
CVE-2021-22986CRITICALunder attackransomware20 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC1
Exploiting CVE-2016-2555 enumerating and dumping the underlying Database.
CVE-2016-255520 Mar 2021
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISK
open
GitHub PoC3
Zoho ManageEngine ServiceDesk Plus MSP - Active Directory User Enumeration (CVE-2021-31159) - https://ricardojoserf.github.io/CVE-2021-31159/
CVE-2021-3115919 Mar 2021
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-messag
28RISK
open
GitHub PoC27
cve-2021-22986 f5 rce 漏洞批量检测 poc
CVE-2021-22986CRITICALunder attackransomware19 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC4
Exploit generator for sudo CVE-2021-3156
CVE-2021-3156HIGHunder attack19 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC4
Jquery File Tree 1.6.6 Path Traversal exploit (CVE-2017-1000170)
CVE-2017-100017019 Mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RISK
open
GitHub PoC27
Whatsapp remote code execution CVE-2019-11932 https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/
CVE-2019-1193219 Mar 2021
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
GitHub PoC9
CutePHP Cute News 2.1.2 RCE PoC
CVE-2019-1144718 Mar 2021
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
GitHub PoC
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
CVE-2019-20361HIGH18 Mar 2021
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b
78RISK
open
GitHub PoC
antichown/Scan-Vuln-CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware18 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
previouspage 375 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.