Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
13,947 exploits
GitHub PoC
CVE-2015-3224
CVE-2015-322427 Feb 2021
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RISK
open
GitHub PoC1
VMware vCenter CVE-2021-21972 Tools
CVE-2021-21972CRITICALunder attackransomware27 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC28
Nmap script to check vulnerability CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware26 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC44
ZeusBox/CVE-2021-21017
CVE-2021-21017HIGHunder attack26 Feb 2021
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
93RISK
open
GitHub PoC28
VMware vCenter 未授权RCE(CVE-2021-21972)
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC1
A vulnerability scanner that detects CVE-2021-21972 vulnerabilities.
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC
A vulnerability scanner that detects CVE-2020-14883 vulnerabilities.
CVE-2020-14883HIGHunder attack25 Feb 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC1
L-pin/CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC15
Nibbleblog 4.0.3 - Arbitrary File Upload (CVE-2015-6967)
CVE-2015-696725 Feb 2021
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RISK
open
GitHub PoC2
CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC54
alt3kx/CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC33
CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC11
VMware vCenter Server远程代码执行漏洞 (CVE-2021-21972)批量检测脚本
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC
A vulnerability scanner that detects CVE-2020-17519 vulnerabilities.
CVE-2020-17519CRITICALunder attack25 Feb 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
GitHub PoC8
CVE-2020-14882
CVE-2020-14882CRITICALunder attack25 Feb 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC500
CVE-2021-21972 Exploit
CVE-2021-21972CRITICALunder attackransomware24 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC8
yaunsky/CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware24 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC137
QmF0c3UK/CVE-2021-21972-vCenter-6.5-7.0-RCE-POC
CVE-2021-21972CRITICALunder attackransomware24 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC271
Proof of Concept Exploit for vCenter CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware24 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC3
lsw29475/CVE-2019-17026
CVE-2019-17026HIGHunder attack24 Feb 2021
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are
83RISK
open
GitHub PoC
oneoy/CVE-2021-3156
CVE-2021-3156HIGHunder attack23 Feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC3
Python implementation of 'Username' map script' RCE Exploit for Samba 3.0.20 < 3.0.25rc3 (CVE-2007-2447).
CVE-2007-244722 Feb 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC1
Nicoslo/Windows-Exploitation-Web-Server-Tomcat-8.5.39-CVE-2019-0232
CVE-2019-023221 Feb 2021
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
GitHub PoC1
Nicoslo/Windows-exploitation-Apache-Tomcat-8.5.19-CVE-2019-0232-
CVE-2019-023220 Feb 2021
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
GitHub PoC1
Nicoslo/Windows-exploitation-Rejetto-HTTP-File-Server-HFS-2.3.x-CVE-2014-6287
CVE-2014-6287CRITICALunder attack20 Feb 2021
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
GitHub PoC
roninAPT/CVE-2018-0802
CVE-2018-0802HIGHunder attack20 Feb 2021
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISK
open
GitHub PoC
Eternit7/CVE-2019-1458
CVE-2019-1458HIGHunder attackransomware19 Feb 2021
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
GitHub PoC
Full exploit code for CVE-2019-25024 an unauthenticated command injection flaw in OpenRepeater.
CVE-2019-2502419 Feb 2021
OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_sy
28RISK
open
GitHub PoC163
Laravel <= v8.4.2 debug mode: Remote code execution (CVE-2021-3129)
CVE-2021-3129CRITICALunder attackransomware18 Feb 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC1
Nicoslo/Windows-exploitation-BadBlue-2.7-CVE-2007-6377
CVE-2007-637718 Feb 2021
Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attacker
50RISK
open
previouspage 378 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.