Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
77,900 exploits
VulnCheck XDB
local
CVE-2020-0787HIGHunder attackransomware16 Nov 2021
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISK
open
Exploit-DB
Online Learning System 2.0 - Remote Code Execution (RCE)
CVE-2021-42580webappsphp16 Nov 2021
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/adm
23RISK
open
GitHub PoC
Confluence server webwork OGNL injection
CVE-2021-26086MEDIUMunder attack16 Nov 2021
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RISK
open
GitHub PoC
Demonstration of CVE-2018-19571: GitLab SSRF CVE
CVE-2018-1957116 Nov 2021
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RISK
open
Exploit-DB
PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF)
CVE-2021-43617webappsphp15 Nov 2021
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val
28RISK
open
VulnCheck XDB
initial-access
CVE-2020-2883CRITICALunder attack15 Nov 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
Exploit-DB
WordPress Plugin WPSchoolPress 2.1.16 - 'Multiple' Cross Site Scripting (XSS)
CVE-2021-24664webappsphp15 Nov 2021
WPSchoolPress < 2.1.17 - Multiple Admin+ Stored Cross-Site Scripting
23RISK
open
Exploit-DB
Simple Subscription Website 1.0 - SQLi Authentication Bypass
CVE-2021-43140webappsphp15 Nov 2021
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
23RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware15 Nov 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC3
Repo demonstrating CVE-2021-43616 / https://github.com/npm/cli/issues/2701
CVE-2021-43616CRITICAL15 Nov 2021
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in pack
48RISK
open
GitHub PoC1
poc for CVE-2020-2555
CVE-2020-2555CRITICALunder attack15 Nov 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-4045CRITICAL15 Nov 2021
TP-LINK Tapo C200 remote code execution vulnerability
70RISK
open
GitHub PoC
POC for CVE-2020-2883
CVE-2020-2883CRITICALunder attack15 Nov 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open
GitHub PoC117
Exploit for command injection vulnerability found in uhttpd binary from TP-Link Tapo c200 IP camera
CVE-2021-4045CRITICAL15 Nov 2021
TP-LINK Tapo C200 remote code execution vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2020-2555CRITICALunder attack15 Nov 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-17562HIGHunder attack14 Nov 2021
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open
GitHub PoC1
kubota/POC-CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware14 Nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
xMohamed0/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware14 Nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
xMohamed0/CVE-2020-5504-phpMyAdmin
CVE-2020-550414 Nov 2021
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could
35RISK
open
GitHub PoC
xMohamed0/CVE-2021-42013-ApacheRCE
CVE-2021-42013CRITICALunder attackransomware14 Nov 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
xMohamed0/CVE-2021-21315-POC
CVE-2021-21315HIGHunder attack14 Nov 2021
Command Injection Vulnerability
100RISK
open
GitHub PoC8
Exploit for CVE-2017-17562 vulnerability, that allows RCE on GoAhead (< v3.6.5) if the CGI is enabled and a CGI program is dynamically linked.
CVE-2017-17562HIGHunder attack14 Nov 2021
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open
GitHub PoC
Python script to exploit webmin vulnerability cve-2006-3392
CVE-2006-339213 Nov 2021
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISK
open
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALunder attack13 Nov 2021
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
VulnCheck XDB
client-side
CVE-2021-22205CRITICALunder attackransomware13 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC
CVE-2021-3560 (Polkit - Local Privilege Escalation)
CVE-2021-3560HIGHunder attack12 Nov 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC1
Реализация использования уязвимости Moodle CVE-2014-3544.
CVE-2014-354412 Nov 2021
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before
23RISK
open
GitHub PoC1
CppXL/cve-2021-40449-poc
CVE-2021-40449HIGHunder attackransomware12 Nov 2021
Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC2
On the 11/11/21 the apache 2.4.49-2.4.50 remote command execution POC has been published online and this is a loader so that you can mass exploit servers using this.
CVE-2021-41773HIGHunder attackransomware11 Nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC237
GitLab CE/EE Preauth RCE using ExifTool
CVE-2021-22205CRITICALunder attackransomware11 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
previouspage 639 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.