Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
77,900 exploits
Exploit-DB
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
CVE-2021-42566webappsmultiple19 Oct 2021
myfactory.FMS before 7.1-912 allows XSS via the Error parameter.
38RISK
open
VulnCheck XDB
initial-access
CVE-2019-398019 Oct 2021
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to
23RISK
open
VulnCheck XDB
infoleak
CVE-2021-21234HIGH19 Oct 2021
Directory Traversal
61RISK
open
GitHub PoC4
xiaojiangxl/CVE-2021-40438
CVE-2021-40438CRITICALunder attackransomware18 Oct 2021
mod_proxy SSRF
100RISK
open
GitHub PoC3
Dahua IPC/VTH/VTO devices auth bypass exploit
CVE-2021-33044CRITICALunder attack18 Oct 2021
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
Exploit-DB
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
CVE-2020-11738HIGHunder attackwebappsphp18 Oct 2021
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traver
100RISK
open
Exploit-DB
Plastic SCM 10.0.16.5622 - WebAdmin Server Access
CVE-2021-41382webappsmultiple18 Oct 2021
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
23RISK
open
GitHub PoC1
Lab setup for CVE-2021-41773 (Apache httpd 2.4.49) and CVE-2021-42013 (Apache httpd 2.4.50).
CVE-2021-41773HIGHunder attackransomware18 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
CVE-2018-16060webappshardware18 Oct 2021
Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listi
28RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack18 Oct 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
CVE-2018-16061webappshardware18 Oct 2021
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
23RISK
open
GitHub PoC1
Exploit For CVE-2019-17662
CVE-2019-1766218 Oct 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISK
open
GitHub PoC17
CVE-2021-36260
CVE-2021-36260CRITICALunder attack18 Oct 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC11
Scanner for CVE-2022-22948 an Information Disclosure in VMWare vCenter
CVE-2022-22948MEDIUMunder attack17 Oct 2021
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious act
83RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware17 Oct 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALunder attack16 Oct 2021
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
GitHub PoC2
Simple honeypot for CVE-2021-41773 vulnerability
CVE-2021-41773HIGHunder attackransomware16 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC478
Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)
CVE-2021-40449HIGHunder attackransomware16 Oct 2021
Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC35
Little thing put together quickly to demonstrate this CVE
CVE-2020-11022MEDIUM16 Oct 2021
jQuery has a potential XSS vulnerability
55RISK
open
GitHub PoC
TIC4301 Project - CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware16 Oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack16 Oct 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
local
CVE-2021-40449HIGHunder attackransomware16 Oct 2021
Win32k Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2020-11022MEDIUM16 Oct 2021
jQuery has a potential XSS vulnerability
55RISK
open
Exploit-DB
i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS)
CVE-2021-41878webappsphp15 Oct 2021
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enable
38RISK
open
GitHub PoC9
apache httpd path traversal checker(CVE-2021-41773 / CVE-2021-42013)
CVE-2021-41773HIGHunder attackransomware15 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
CVE-2020-25078账号密码信息泄露批量脚本Batch script of D-Link DCS series camera account password information disclosure
CVE-2020-25078HIGHunder attack15 Oct 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RISK
open
GitHub PoC5
The first vulnerability with the CVE identifier CVE-2021-41773 is a path traversal flaw that exists in Apache HTTP Server 2.4.49.
CVE-2021-41773HIGHunder attackransomware15 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.
CVE-2021-4207115 Oct 2021
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharac
50RISK
open
GitHub PoC
metehangenel/MSHTML-CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware15 Oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware15 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
previouspage 645 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.