Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
77,900 exploits
VulnCheck XDB
initial-access
CVE-2020-11978HIGHunder attack28 Nov 2021
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was disco
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-22205CRITICALunder attackransomware27 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC
Strapi Framework, 3.0.0-beta.17.4
CVE-2019-1960927 Nov 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42321HIGHunder attackransomware27 Nov 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-1960927 Nov 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
GitHub PoC1
NSE script to fingerprint if GitLab is vulnerable to cve-2021-22205-nse
CVE-2021-22205CRITICALunder attackransomware27 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-7247CRITICALunder attack26 Nov 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21985CRITICALunder attackransomware26 Nov 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC
Detect with python and tracking IP
CVE-2018-7600CRITICALunder attackransomware26 Nov 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC2
Proof of concept for CVE-2020-7247 for educational purposes.
CVE-2020-7247CRITICALunder attack26 Nov 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
GitHub PoC
lisinan988/CVE-2018-8174-exp
CVE-2018-8174HIGHunder attackransomware25 Nov 2021
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
GitHub PoC
lisinan988/CVE-2017-11882-exp
CVE-2017-11882HIGHunder attackransomware25 Nov 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC3
A CVE-2021-22205 Gitlab RCE POC written in Golang
CVE-2021-22205CRITICALunder attackransomware25 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC
lisinan988/CVE-2020-0796-exp
CVE-2020-0796CRITICALunder attackransomware25 Nov 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALunder attackransomware25 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware25 Nov 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALunder attackransomware25 Nov 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
client-side
CVE-2018-8174HIGHunder attackransomware25 Nov 2021
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
GitHub PoC
lisinan988/CVE-2019-0708-scan
CVE-2019-0708CRITICALunder attackransomware25 Nov 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware25 Nov 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
lisinan988/CVE-2021-40444-exp
CVE-2021-40444HIGHunder attackransomware25 Nov 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Metabase GeoJSON map local file inclusion
CVE-2021-41277CRITICALunder attack24 Nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISK
open
GitHub PoC
plugin made for LeakiX
CVE-2021-41277CRITICALunder attack23 Nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISK
open
GitHub PoC4
Vulnmachines/Metabase_CVE-2021-41277
CVE-2021-41277CRITICALunder attack23 Nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISK
open
GitHub PoC83
Microsoft Exchange Server Poc
CVE-2021-42321HIGHunder attackransomware23 Nov 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Python 3 script to identify CVE-2021-26084 via network requests.
CVE-2021-26084CRITICALunder attackransomware23 Nov 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
Exploit-DB
Linux Kernel 5.1.x - 'PTRACE_TRACEME' pkexec Local Privilege Escalation (2)
CVE-2019-13272HIGHunder attacklocallinux23 Nov 2021
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42321HIGHunder attackransomware23 Nov 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42321HIGHunder attackransomware23 Nov 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack23 Nov 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
previouspage 637 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.