Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
77,813 exploits
VulnCheck XDB
remote-with-credentials
CVE-2020-3452HIGHunder attack10 Jan 2022
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALunder attackransomware10 Jan 2022
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack10 Jan 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
Veids/CVE-2020-3452_auto
CVE-2020-3452HIGHunder attack10 Jan 2022
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware08 Jan 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-44228CRITICALunder attackransomware08 Jan 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
h3x0v3rl0rd/CVE-2018-16763
CVE-2018-1676308 Jan 2022
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
VulnCheck XDB
initial-access
CVE-2018-1676308 Jan 2022
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC2
Log4jshell - CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware07 Jan 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALunder attackransomware05 Jan 2022
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
Exploit-DB
WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection
CVE-2021-24750webappsphp05 Jan 2022
WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection
50RISK
open
Exploit-DB
WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read (Unauthenticated)
CVE-2021-39312HIGHwebappsphp05 Jan 2022
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISK
open
GitHub PoC
alexpena5635/CVE-2021-44228_scanner-main-Modified-
CVE-2021-44228CRITICALunder attackransomware05 Jan 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Exploit-DB
SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS)
CVE-2021-45425webappsphp05 Jan 2022
Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScrip
23RISK
open
Exploit-DB
Gerapy 0.9.7 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-43857CRITICALremotepython05 Jan 2022
Gerapy may contain remote code execution vulnerability
60RISK
open
Exploit-DB
Automox Agent 32 - Local Privilege Escalation
CVE-2021-43326localwindows05 Jan 2022
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
23RISK
open
Exploit-DB
ConnectWise Control 19.2.24707 - Username Enumeration
CVE-2019-16516remotemultiple05 Jan 2022
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumer
28RISK
open
Exploit-DB
Nettmp NNT 5.1 - SQLi Authentication Bypass
CVE-2021-45814webappsphp05 Jan 2022
Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel
23RISK
open
GitHub PoC
the name of virus is the detection of microsoft defender, is the tipic antivirus
CVE-2017-0147HIGHunder attackransomware04 Jan 2022
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
Bassmaster Plugin NodeJS RCE
CVE-2014-720504 Jan 2022
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RISK
open
GitHub PoC
Atmail XSS-CSRF-RCE Exploit Chain
CVE-2012-259304 Jan 2022
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote atta
23RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-2509403 Jan 2022
Tatsu < 3.3.12 - Unauthenticated RCE
60RISK
open
GitHub PoC
the name of virus is the detection of microsoft defender, is the tipic antivirus
CVE-2012-0158HIGHunder attackransomware03 Jan 2022
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls
100RISK
open
GitHub PoC
Log4j2 LDAP 취약점 테스트 (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware03 Jan 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC9
darkpills/CVE-2021-25094-tatsu-preauth-rce
CVE-2021-2509403 Jan 2022
Tatsu < 3.3.12 - Unauthenticated RCE
60RISK
open
GitHub PoC
This repository contains a Spring Boot web application vulnerable to CVE-2021-44228, known as log4shell.
CVE-2021-44228CRITICALunder attackransomware31 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Presents how to exploit CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALunder attackransomware30 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware30 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
trganda/CVE-2021-22204
CVE-2021-22204MEDIUMunder attack29 Dec 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1154629 Dec 2021
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailing
50RISK
open
previouspage 617 / 2,594next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.