Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
77,813 exploits
GitHub PoC3
trganda/CVE-2021-22204
CVE-2021-22204MEDIUMunder attack29 Dec 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1154629 Dec 2021
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailing
50RISK
open
GitHub PoC
"Lavel Exploit CVE-2018-15133 is a powerful exploit that allows attackers to gain unauthorized access to vulnerable systems. This exploit was originally developed as part of a Capture The Flag (CTF) challenge and has since been used by security researchers and ethical hackers to identify and address vulnerabilities in web applications.
CVE-2018-15133HIGHunder attack28 Dec 2021
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-15133HIGHunder attack28 Dec 2021
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC5
Auerswald COMpact 8.0B Backdoors exploit
CVE-2021-4085928 Dec 2021
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web
60RISK
open
GitHub PoC2
Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit
CVE-2021-40444HIGHunder attackransomware28 Dec 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC11
CVE-2019-9053 Exploit for Python 3
CVE-2019-905328 Dec 2021
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware28 Dec 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC209
A tool for detect&exploit vmware product log4j(cve-2021-44228) vulnerability.Support VMware HCX/vCenter/NSX/Horizon/vRealize Operations Manager
CVE-2021-44228CRITICALunder attackransomware28 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
A spigot plugin to fix CVE-2021-44228 Log4j remote code execution vulnerability, to protect Minecraft clients.
CVE-2021-44228CRITICALunder attackransomware28 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware28 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-1154627 Dec 2021
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailing
50RISK
open
GitHub PoC
Ravid-CheckMarx/CVE-2021-44228-Apache-Log4j-Rce-main
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
log4j-paylaod generator : A generic payload generator for Apache log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Quick and dirty scanner, hitting common ports looking for Log4Shell (CVE-2021-44228) vulnerability
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Log4Shell (CVE-2021-44228) is a zero-day vulnerability in Log4j
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Log4Shell (Cve-2021-44228) Proof Of Concept
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
IOCs for CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Regra ModSec para proteção log4j2 - CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Detection script for CVE-2021-42278 and CVE-2021-42287
CVE-2021-42278HIGHunder attackransomware27 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
initial-access
CVE-2021-2083726 Dec 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open
GitHub PoC100
Collection of materials relating to FORCEDENTRY
CVE-2021-30860HIGHunder attack25 Dec 2021
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catali
93RISK
open
VulnCheck XDB
initial-access
CVE-2020-14871CRITICALunder attack25 Dec 2021
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack25 Dec 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC2
This is a basic ROP based exploit for CVE 2020-14871. CVE 2020-14871 is a vulnerability in Sun Solaris systems libpam library, and exploitable over ssh
CVE-2020-14871CRITICALunder attack25 Dec 2021
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISK
open
GitHub PoC
this repository contains a POC of CVE-2021-44228 (log4j2shell) as part of a security research
CVE-2021-44228CRITICALunder attackransomware25 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC170
Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Spring Boot web application vulnerable to CVE-2021-44228, nicknamed Log4Shell.
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 618 / 2,594next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.