Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
77,900 exploits
GitHub PoC2
Modification of gitlab exploit anything under 13.10
CVE-2021-22204MEDIUMunder attack04 Nov 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALunder attackransomware04 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-22204MEDIUMunder attack04 Nov 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
GitHub PoC
CVE-2021-22205& GitLab CE/EE RCE
CVE-2021-22205CRITICALunder attackransomware04 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC6
Some docker images to play with CVE-2021-41773 and CVE-2021-42013
CVE-2021-41773HIGHunder attackransomware04 Nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
Exploit Apache 2.4.50(CVE-2021-42013)
CVE-2021-42013CRITICALunder attackransomware03 Nov 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC6
POC for CVE-2021-34429 - Eclipse Jetty 11.0.5 Sensitive File Disclosure
CVE-2021-34429MEDIUM03 Nov 2021
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
70RISK
open
GitHub PoC
It is a simple tool to exploit local file include . vulnerabilities
CVE-2006-339203 Nov 2021
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack03 Nov 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-40539CRITICALunder attackransomware03 Nov 2021
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open
GitHub PoC20
the metasploit script(POC) about CVE-2021-36260
CVE-2021-36260CRITICALunder attack03 Nov 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC48
Exploitation code for CVE-2021-40539
CVE-2021-40539CRITICALunder attackransomware03 Nov 2021
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-3452HIGHunder attack03 Nov 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
Exploit-DB
Fuel CMS 1.4.1 - Remote Code Execution (3)
CVE-2018-16763webappsphp03 Nov 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC6
Fuel CMS 1.4.1 - Remote Code Execution
CVE-2018-1676303 Nov 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
VulnCheck XDB
initial-access
CVE-2018-1676303 Nov 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC
It is a simple tool to exploit local file include . vulnerabilities
CVE-2006-339203 Nov 2021
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISK
open
GitHub PoC1
Test vulnerability of CVE-2020-3452
CVE-2020-3452HIGHunder attack03 Nov 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC4
Proof-of-Concept tool for CVE-2021-29156, an LDAP injection vulnerability in ForgeRock OpenAM v13.0.0.
CVE-2021-2915603 Nov 2021
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacke
60RISK
open
Exploit-DB
Eclipse Jetty 11.0.5 - Sensitive File Disclosure
CVE-2021-34429MEDIUMwebappsjava03 Nov 2021
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
70RISK
open
Exploit-DB
OpenAM 13.0 - LDAP Injection
CVE-2021-29156webappsjava03 Nov 2021
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacke
60RISK
open
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALunder attackransomware03 Nov 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
Metasploit600
Cisco RV Series Authentication Bypass and Command Injection
CVE-2022-20707CRITICAL02 Nov 2021
Cisco Small Business RV Series Routers Vulnerabilities
85RISK
open
Exploit-DB
Ericsson Network Location MPS GMPC21 - Privilege Escalation (Metasploit)
CVE-2021-43338webappsmultiple02 Nov 2021
20RISK
open
Metasploit600
Sitecore Experience Platform (XP) PreAuth Deserialization RCE
CVE-2021-42237CRITICALunder attackransomware02 Nov 2021
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it
100RISK
open
Metasploit600
Cisco RV Series Authentication Bypass and Command Injection
CVE-2022-20705CRITICAL02 Nov 2021
Cisco Small Business RV Series Routers Vulnerabilities
85RISK
open
GitHub PoC
MovableType XMLRPC - RCE
CVE-2021-2083701 Nov 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack01 Nov 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
Exploit and Demo system for CVE-2021-3156
CVE-2021-3156HIGHunder attack01 Nov 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC3
CVE-2021-22205-getshell
CVE-2021-22205CRITICALunder attackransomware01 Nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
previouspage 641 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.