Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
77,900 exploits
GitHub PoC
Dockerized Proof-of-Concept of CVE-2021-40438 in Apache 2.4.48.
CVE-2021-40438CRITICALunder attackransomware11 Nov 2021
mod_proxy SSRF
100RISK
open
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
CVE-2021-42013CRITICALunder attackransomwarewebappsmultiple11 Nov 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
CVE-2021-41773HIGHunder attackransomwarewebappsmultiple11 Nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC237
GitLab CE/EE Preauth RCE using ExifTool
CVE-2021-22205CRITICALunder attackransomware11 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
Exploit-DB
FormaLMS 2.4.4 - Authentication Bypass
CVE-2021-43136webappsmultiple11 Nov 2021
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain
28RISK
open
GitHub PoC
Ce programme permet de détecter une faille RCE sur les serveurs Apache 2.4.49 et Apache 2.4.50
CVE-2021-41773HIGHunder attackransomware11 Nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
bu1xuan2/CVE-2018-15961
CVE-2018-15961CRITICALunder attack10 Nov 2021
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-15961CRITICALunder attack10 Nov 2021
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open
GitHub PoC1
rust noob tried write easy exploit code with rust lang
CVE-2021-21315HIGHunder attack10 Nov 2021
Command Injection Vulnerability
100RISK
open
GitHub PoC3
VMWARE VCENTER SERVER VIRTUAL SAN HEALTH CHECK PLUG-IN RCE (CVE-2021-21985)
CVE-2021-21985CRITICALunder attackransomware09 Nov 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC1
This Metasploit module exploits an unauthenticated remote code execution vulnerability which exists in Apache version 2.4.49 (CVE-2021-41773). If files outside of the document root are not protected by ‘require all denied’ and CGI has been explicitly enabled, it can be used to execute arbitrary commands. This vulnerability has been reintroduced in the Apache 2.4.50 fix (CVE-2021-42013).
CVE-2021-41773HIGHunder attackransomware09 Nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC6
faisalfs10x/GitLab-CVE-2021-22205-scanner
CVE-2021-22205CRITICALunder attackransomware09 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC18
A Zeek package to detect CVE-2021-42292, a Microsoft Excel local privilege escalation exploit.
CVE-2021-42292HIGHunder attack09 Nov 2021
Microsoft Excel Security Feature Bypass Vulnerability
83RISK
open
Metasploit300
Wordpress Secure Copy Content Protection and Content Locking sccp_id Unauthenticated SQLi
CVE-2021-2493108 Nov 2021
Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection
60RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware08 Nov 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
FusionPBX 4.5.29 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-43405webappsphp08 Nov 2021
An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained t
35RISK
open
GitHub PoC1
Contains the offensive (exploit and auxiliary) modules for the CVE-2021-40444.
CVE-2021-40444HIGHunder attackransomware08 Nov 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC15
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-252307 Nov 2021
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
VulnCheck XDB
local
CVE-2021-30657MEDIUMunder attack07 Nov 2021
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2
90RISK
open
GitHub PoC52
Exploit for CVE-2021-40449
CVE-2021-40449HIGHunder attackransomware07 Nov 2021
Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC29
A sample POC for CVE-2021-30657 affecting MacOS
CVE-2021-30657MEDIUMunder attack07 Nov 2021
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2
90RISK
open
VulnCheck XDB
local
CVE-2021-40449HIGHunder attackransomware07 Nov 2021
Win32k Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware06 Nov 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
JWT Exploit
CVE-2018-011406 Nov 2021
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
GitHub PoC
mmeza-developer/CVE-2019-5420-RCE
CVE-2019-542006 Nov 2021
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALunder attackransomware05 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC
hh-hunter/cve-2021-22205
CVE-2021-22205CRITICALunder attackransomware05 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC3
Exploit for GitLab CVE-2021-22205 Unauthenticated Remote Code Execution
CVE-2021-22205CRITICALunder attackransomware05 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC4
Pickle Serialization Remote Code Execution - Memcached Poisoning
CVE-2021-33026CRITICAL05 Nov 2021
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code e
48RISK
open
GitHub PoC2
Modification of gitlab exploit anything under 13.10
CVE-2021-22204MEDIUMunder attack04 Nov 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
previouspage 640 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.