Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,207cataloged exploits
36,011CVEs with public exploitation
24,695lab-tested
77,900 exploits
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALunder attackransomware31 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALunder attackransomware31 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC13
CVE-2021-22205 RCE
CVE-2021-22205CRITICALunder attackransomware31 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC23
CVE-2021-22205 Gitlab 未授权远程代码执行漏洞 EXP, 移除了对djvumake & djvulibre的依赖,可在win平台使用
CVE-2021-22205CRITICALunder attackransomware30 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
Metasploit300
ChurchInfo 1.2.13-1.3.0 Authenticated RCE
CVE-2021-43258HIGH30 Oct 2021
CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requir
41RISK
open
GitHub PoC21
XMLRPC - RCE in MovableTypePoC
CVE-2021-2083730 Oct 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open
GitHub PoC2
PoC in single line bash
CVE-2021-22205CRITICALunder attackransomware30 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-2083730 Oct 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open
VulnCheck XDB
infoleak
CVE-2017-822530 Oct 2021
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
28RISK
open
GitHub PoC2
kienquoc102/CVE-2017-8225
CVE-2017-822530 Oct 2021
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
28RISK
open
GitHub PoC
C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode in…
CVE-2021-26855CRITICALunder attackransomware30 Oct 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
scopion/CVE-2018-8947
CVE-2018-894729 Oct 2021
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easi
23RISK
open
GitHub PoC
scopion/CVE-2020-10963
CVE-2020-1096329 Oct 2021
FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution)
28RISK
open
GitHub PoC
Setup vulnerable enviornment
CVE-2021-41773HIGHunder attackransomware29 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Exploit-DB
WebCTRL OEM 6.5 - 'locale' Reflected Cross-Site Scripting (XSS)
CVE-2021-31682webappsmultiple29 Oct 2021
The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for re
43RISK
open
VulnCheck XDB
infoleak
CVE-2019-18935CRITICALunder attackransomware29 Oct 2021
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC7
Gitlab CE/EE RCE 未授权远程代码执行漏洞 POC && EXP CVE-2021-22205
CVE-2021-22205CRITICALunder attackransomware29 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
Exploit-DBVexDay Proof
Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit)
CVE-2021-20837webappscgi29 Oct 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open
GitHub PoC286
CVE-2021-22205& GitLab CE/EE RCE
CVE-2021-22205CRITICALunder attackransomware29 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC
0xAgun/CVE-2019-18935-checker
CVE-2019-18935CRITICALunder attackransomware29 Oct 2021
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALunder attackransomware29 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
client-side
CVE-2019-573629 Oct 2021
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack28 Oct 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALunder attackransomware28 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC86
Pocsuite3 For CVE-2021-22205
CVE-2021-22205CRITICALunder attackransomware28 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC69
CVE-2021-22205 Unauthorized RCE
CVE-2021-22205CRITICALunder attackransomware28 Oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC1
批量扫描CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware28 Oct 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC9
An attempt to reproduce Microsoft MSHTML Remote Code Execution (RCE) Vulnerability and using Metasploit Framework.
CVE-2021-40444HIGHunder attackransomware28 Oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
BabyTeam1024/CVE-2021-40438
CVE-2021-40438CRITICALunder attackransomware28 Oct 2021
mod_proxy SSRF
100RISK
open
GitHub PoC
rafaelcaria/drupalgeddon2-CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware27 Oct 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
previouspage 642 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.