Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
13,947 exploits
GitHub PoC1
PoC Python script as an exercice from tryhackme.
CVE-2012-298218 Mar 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
GitHub PoC51
This is a Poc for BIGIP iControl unauth RCE
CVE-2021-22986CRITICALunder attackransomware17 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC4
CVE-2021-26855 proxyLogon metasploit exploit script
CVE-2021-26855CRITICALunder attackransomware17 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC124
ProxyLogon(CVE-2021-26855+CVE-2021-27065) Exchange Server RCE(SSRF->GetWebShell)
CVE-2021-26855CRITICALunder attackransomware17 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Exploit Code for CVE-2019-11447 aka CuteNews 2.1.2 Avatar upload RCE (Authenticated)
CVE-2019-1144717 Mar 2021
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
GitHub PoC33
ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin. We have also chained this bug with another post-auth arbitrary-file-write vulnerability, CVE-2021-27065, to get code execution.
CVE-2021-26855CRITICALunder attackransomware16 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
Chaining CVE-2021-26855 and CVE-2021-26857 to exploit Microsoft Exchange
CVE-2021-26855CRITICALunder attackransomware16 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
automate me!
CVE-2021-21973MEDIUMunder attack16 Mar 2021
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of UR
100RISK
open
GitHub PoC28
CVE-2021-26855 & CVE-2021-27065
CVE-2021-26855CRITICALunder attackransomware15 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC6
Mr-xn/CVE-2021-26855-d
CVE-2021-26855CRITICALunder attackransomware15 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC4
patched to work
CVE-2021-26855CRITICALunder attackransomware15 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC803
Sudo Baron Samedit Exploit
CVE-2021-3156HIGHunder attack15 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC9
RCE exploit for ProxyLogon vulnerability in Microsoft Exchange
CVE-2021-26855CRITICALunder attackransomware14 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC22
RCE exploit for Microsoft Exchange Server (CVE-2021-26855).
CVE-2021-26855CRITICALunder attackransomware14 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Exploit Samba
CVE-2007-244714 Mar 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC30
CVE-2021-26855: PoC (Not a HoneyPoC for once!)
CVE-2021-26855CRITICALunder attackransomware14 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
Scanner and PoC for CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware12 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Will write a python script for exploiting this vulnerability
CVE-2020-25213CRITICALunder attack12 Mar 2021
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
GitHub PoC
vonderchild/CVE-2016-3088
CVE-2016-3088CRITICALunder attack12 Mar 2021
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC5
Apache ActiveMQ Remote Code Execution Exploit
CVE-2016-3088CRITICALunder attack11 Mar 2021
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC5
CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065
CVE-2021-26855CRITICALunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC111
proxylogon exploit - CVE-2021-26857
CVE-2021-26857HIGHunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
93RISK
open
GitHub PoC61
PoC of proxylogon chain SSRF(CVE-2021-26855) to write file by testanull, censored by github
CVE-2021-26855CRITICALunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC12
CVE-2021-26855, also known as Proxylogon, is a server-side request forgery (SSRF) vulnerability in Exchange that allows an attacker to send arbitrary HTTP requests and authenticate as the Exchange server.
CVE-2021-26855CRITICALunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1,077
Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-UltraVires/Redis-Unauthorized-RCE/TDOA-V11.7-GetOnlineCookie/VMware-vCenter-GetAnyFile/yongyou-GRP-U8-XXE/Oracle-WebLogic-CVE-2020-14883/Oracle-WebLogic-CVE-2020-14882/Apache-Solr-GetAnyFile/F5-BIG-IP-CVE-2021-22986/Sonicwall-SSL-VPN-RCE/GitLab-Graphql-CNVD-2021-14193/D-Link-DCS-CVE-2020-25078/WLAN-AP-WEA453e-RCE/360TianQing-Unauthorized/360TianQing-SQLinjection/FanWeiOA-V8-SQLinjection/QiZhiBaoLeiJi-AnyUserLogin/QiAnXin-WangKangFirewall-RCE/金山-V8-终端安全系统/NCCloud-SQLinjection/ShowDoc-RCE
CVE-2020-14883HIGHunder attack11 Mar 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC53
alt3kx/CVE-2021-26855_PoC
CVE-2021-26855CRITICALunder attackransomware10 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065
CVE-2021-26855CRITICALunder attackransomware09 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
This script test the CVE-2021-26855 vulnerability on Exchange Server.
CVE-2021-26855CRITICALunder attackransomware09 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC100
h4x0r-dz/CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware09 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC17
PoC exploit code for CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware09 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
previouspage 376 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.