Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,813 exploits
GitHub PoC5
Hotel Druid 3.0.3 Code Injection to Remote Code Execution
CVE-2022-2290917 Feb 2022
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attack
35RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack17 Feb 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware16 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
Exploit-DB
WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated)
CVE-2021-24966webappsphp16 Feb 2022
Error Log Viewer Plugin <= 1.1.1 - Admin+ Arbitrary File Clearing
23RISK
open
GitHub PoC
POC en Python para el CVE-2012-2982 mejorado del original por el usuario @OstojaOfficial
CVE-2012-298216 Feb 2022
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
GitHub PoC
Rust implementation of the Log 4 Shell (log 4 j - CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware16 Feb 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Exploit-DB
ServiceNow - Username Enumeration
CVE-2021-45901webappsmultiple16 Feb 2022
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending
28RISK
open
GitHub PoC
Build the struts-2.3.31 (CVE-2017-5638) environment
CVE-2017-5638CRITICALunder attackransomware15 Feb 2022
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC4
SQL Injection Vulnerability on PhpIPAM v1.4.4
CVE-2022-2304615 Feb 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware15 Feb 2022
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC51
SAP memory pipes(MPI) desynchronization vulnerability CVE-2022-22536.
CVE-2022-22536CRITICALunder attack15 Feb 2022
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISK
open
VulnCheck XDB
local
CVE-2020-0787HIGHunder attackransomware15 Feb 2022
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware15 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware15 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-1732HIGHunder attackransomware15 Feb 2022
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2022-21882HIGHunder attackransomware14 Feb 2022
Win32k Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
initial-access
CVE-2022-20699CRITICALunder attack14 Feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RISK
open
GitHub PoC6
r1l4-i3pur1l4/CVE-2022-21882
CVE-2022-21882HIGHunder attackransomware14 Feb 2022
Win32k Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
info-leak
CVE-2021-21311HIGHunder attack14 Feb 2022
SSRF in adminer
100RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack13 Feb 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware13 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware13 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware13 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware13 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
Python exploit for CVE-2017-8917 - Joomla 3.7.0 'com_fields' SQL Injection
CVE-2017-891713 Feb 2022
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
GitHub PoC3
Log4j vulner testing environment based on CVE-2021-44228. It provide guidance to build the sample infrastructure and the exploit scripts. Supporting cooki3 script as the main exploit tools & integration
CVE-2021-44228CRITICALunder attackransomware12 Feb 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
purple-WL/Jenkins_CVE-2019-1003000
CVE-2019-100300012 Feb 2022
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
VulnCheck XDB
infoleak
CVE-2022-21661HIGH12 Feb 2022
SQL injection in WordPress
78RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware12 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
CVE-2014-1767在win7_x64平台的EXP和分析文章
CVE-2014-176712 Feb 2022
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Wind
28RISK
open
previouspage 607 / 2,594next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.