Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
13,947 exploits
GitHub PoC1
PoC for CVE-2015-1769
CVE-2015-1769MEDIUMunder attack17 Feb 2021
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,
63RISK
open
GitHub PoC2
FunPhishing/Laravel-8.4.2-rce-CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware14 Feb 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC3
OpenSSL Heartbleed Bug CVE-2014-0160 Toolkit. Built with ❤ by Christopher Ngo.
CVE-2014-0160HIGHunder attack14 Feb 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC11
OpenSMTPD 6.4.0 - 6.6.1 Remote Code Execution PoC exploit
CVE-2020-7247CRITICALunder attack13 Feb 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
GitHub PoC4
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker.
CVE-2021-21014CRITICAL13 Feb 2021
Magento Commerce Arbitrary Folder Empty Could Lead To Arbitrary Code Execution
48RISK
open
GitHub PoC8
Test for CVE-2000-0649, and return an IP address if vulnerable
CVE-2000-064911 Feb 2021
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RISK
open
GitHub PoC40
synacktiv/CVE-2021-1782
CVE-2021-1782HIGHunder attack10 Feb 2021
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-00
71RISK
open
GitHub PoC
보안취약점 확인
CVE-2021-3156HIGHunder attack09 Feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC205
CVE-2021-3156非交互式执行命令
CVE-2021-3156HIGHunder attack09 Feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC16
sudo heap overflow to LPE, in Go
CVE-2021-3156HIGHunder attack09 Feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC51
CVE-2021-3156: Sudo heap overflow exploit for Debian 10
CVE-2021-3156HIGHunder attack08 Feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
Fixed version of the Python script to exploit CVE-2018-19571 and CVE-2018-19585 (GitLab 11.4.7 - Authenticated Remote Code Execution) that is available at https://www.exploit-db.com/exploits/49263 (Python 3.9).
CVE-2018-1957108 Feb 2021
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RISK
open
GitHub PoC2
Grayhaxor/CVE-2021-21148
CVE-2021-21148HIGHunder attack07 Feb 2021
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap
76RISK
open
GitHub PoC
Apple Safari Remote Code Execution
CVE-2020-27930HIGHunder attack07 Feb 2021
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, wat
76RISK
open
GitHub PoC10
CVE-2020-7384
CVE-2020-7384HIGH07 Feb 2021
Client-Side Command Injection in Rapid7 Metasploit
68RISK
open
GitHub PoC7
1N53C/CVE-2021-3156-PoC
CVE-2021-3156HIGHunder attack06 Feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
46o60/CVE-2019-3396_Confluence
CVE-2019-3396CRITICALunder attackransomware05 Feb 2021
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC2
Poc for CVE-2020-14181
CVE-2020-1418105 Feb 2021
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
60RISK
open
GitHub PoC
DXY0411/CVE-2019-16113
CVE-2019-1611305 Feb 2021
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISK
open
GitHub PoC3
Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215
CVE-2019-2215HIGHunder attack05 Feb 2021
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC
Custom version of sudo 1.8.3p1 with CVE-2021-3156 patches applied
CVE-2021-3156HIGHunder attack05 Feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
raymontag/cve-2021-1782
CVE-2021-1782HIGHunder attack04 Feb 2021
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-00
71RISK
open
GitHub PoC12
CVE-2021-1994、CVE-2021-2047、CVE-2021-2064、CVE-2021-2108、CVE-2021-2075、CVE-2019-17195、CVE-2020-14756、CVE-2021-2109
CVE-2020-14756CRITICAL04 Feb 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versio
70RISK
open
GitHub PoC67
CVE-2020-3992 & CVE-2019-5544
CVE-2020-3992CRITICALunder attackransomware04 Feb 2021
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-
100RISK
open
GitHub PoC67
CVE-2020-3992 & CVE-2019-5544
CVE-2019-5544CRITICALunder attackransomware04 Feb 2021
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of
100RISK
open
GitHub PoC1
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution for Python3
CVE-2017-12617HIGHunder attack04 Feb 2021
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
GitHub PoC
forse01/CVE-2020-25213-Wordpress
CVE-2020-25213CRITICALunder attack04 Feb 2021
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
GitHub PoC2
simple bash script of CVE-2020-3452 Cisco ASA / Firepower Read-Only Path Traversal Vulnerability checker
CVE-2020-3452HIGHunder attack04 Feb 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC2
simple bash script of F5 BIG-IP TMUI Vulnerability CVE-2020-5902 checker
CVE-2020-5902CRITICALunder attackransomware04 Feb 2021
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
GitHub PoC12
CVE-2021-1994、CVE-2021-2047、CVE-2021-2064、CVE-2021-2108、CVE-2021-2075、CVE-2019-17195、CVE-2020-14756、CVE-2021-2109
CVE-2021-1994CRITICAL04 Feb 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported ver
48RISK
open
previouspage 379 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.