Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,051cataloged exploits
35,924CVEs with public exploitation
24,695lab-tested
77,813 exploits
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware06 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware04 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware04 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
Metasploit600
Docker cgroups Container Escape
CVE-2022-0492HIGHunder attack04 Feb 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISK
open
Exploit-DB
Servisnet Tessa - Privilege Escalation (Metasploit)
CVE-2022-22833webappsmultiple04 Feb 2022
An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request.
28RISK
open
Exploit-DB
Servisnet Tessa - MQTT Credentials Dump (Unauthenticated) (Metasploit)
CVE-2022-22832webappsmultiple04 Feb 2022
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/u
28RISK
open
GitHub PoC
IAmNewbieZ/CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware04 Feb 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC8
PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec in Python
CVE-2021-4034HIGHunder attackransomware04 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
giardinas-dev/audit-xss-cve-2020-7934
CVE-2020-793404 Feb 2022
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA
23RISK
open
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALunder attackransomware03 Feb 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC196
L4ys/CVE-2022-21882
CVE-2022-21882HIGHunder attackransomware03 Feb 2022
Win32k Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware03 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
Kayky-cmd/CVE-2019-6447--.
CVE-2019-644703 Feb 2022
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open
GitHub PoC1
Apache HTTP Server 2.4.50 - RCE Lab
CVE-2021-42013CRITICALunder attackransomware03 Feb 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
local
CVE-2022-21882HIGHunder attackransomware03 Feb 2022
Win32k Elevation of Privilege Vulnerability
98RISK
open
Exploit-DB
PHP Unit 4.8.28 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2017-9841CRITICALunder attackwebappsphp02 Feb 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
Exploit-DB
WordPress Plugin Product Slider for WooCommerce 1.13.21 - Cross Site Scripting (XSS)
CVE-2021-24300webappsphp02 Feb 2022
PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)
43RISK
open
Exploit-DB
Chamilo LMS 1.11.14 - Account Takeover
CVE-2021-37391webappsphp02 Feb 2022
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator
23RISK
open
Exploit-DB
WordPress Plugin Post Grid 2.1.1 - Cross Site Scripting (XSS)
CVE-2021-24488webappsphp02 Feb 2022
Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)
43RISK
open
Exploit-DB
WordPress Plugin Domain Check 1.0.16 - Reflected Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-24926webappsphp02 Feb 2022
Domain Check < 1.0.17 - Reflected Cross-Site Scripting
43RISK
open
Exploit-DB
WordPress Plugin Contact Form Check Tester 1.0.2 - Broken Access Control
CVE-2021-24247webappsphp02 Feb 2022
Contact Form Check Tester <= 1.0.2 - Broken Access Control to Cross-Site Scripting (XSS)
23RISK
open
Exploit-DB
Wordpress Plugin 404 to 301 2.0.2 - SQL-Injection (Authenticated)
CVE-2015-9323webappsphp02 Feb 2022
The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
50RISK
open
Exploit-DB
Wordpress Plugin Download Monitor WordPress V 4.4.4 - SQL Injection (Authenticated)
CVE-2021-24786HIGHwebappsphp02 Feb 2022
Download Monitor < 4.4.5 - Admin+ SQL Injection
61RISK
open
Exploit-DB
WordPress Plugin Learnpress 4.1.4.1 - Arbitrary Image Renaming
CVE-2022-0377webappsphp02 Feb 2022
LearnPress < 4.1.5 - Arbitrary Image Renaming
23RISK
open
Exploit-DB
Mozilla Firefox 67 - Array.pop JIT Type Confusion
CVE-2019-11707HIGHunder attacklocalwindows02 Feb 2022
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware02 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware02 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
Metasploit400
Cisco RV340 SSL VPN Unauthenticated Remote Code Execution
CVE-2022-20699CRITICALunder attack02 Feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RISK
open
Exploit-DB
Moodle 3.11.4 - SQL Injection
CVE-2022-0332webappsphp02 Feb 2022
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web serv
35RISK
open
Metasploit400
Zyxel Unauthenticated LAN Remote Code Execution
CVE-2023-28769CRITICAL01 Feb 2022
The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware v
43RISK
open
previouspage 609 / 2,594next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.