Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
77,900 exploits
GitHub PoC9
apache httpd path traversal checker(CVE-2021-41773 / CVE-2021-42013)
CVE-2021-41773HIGHunder attackransomware15 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
Docker container lab to play/learn with CVE-2021-42013
CVE-2021-42013CRITICALunder attackransomware14 Oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
zomy22/CVE-2020-16846-Saltstack-Salt-API
CVE-2020-16846CRITICALunder attack14 Oct 2021
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien
100RISK
open
GitHub PoC
Docker container lab to play/learn with CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware14 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
My take on CVE-2021-30858 for ps4 8.xx
CVE-2021-30858HIGHunder attack14 Oct 2021
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, m
76RISK
open
GitHub PoC1
Testing CVE-2021-30858 Rev3
CVE-2021-30858HIGHunder attack14 Oct 2021
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, m
76RISK
open
VulnCheck XDB
infoleak
CVE-2021-30858HIGHunder attack14 Oct 2021
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, m
76RISK
open
VulnCheck XDB
infoleak
CVE-2021-30858HIGHunder attack14 Oct 2021
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, m
76RISK
open
VulnCheck XDB
infoleak
CVE-2021-3674914 Oct 2021
Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALunder attackransomware14 Oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware13 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-42013CRITICALunder attackransomware13 Oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack13 Oct 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
Exploit-DB
Sonicwall SonicOS 7.0 - Host Header Injection
CVE-2021-20031webappshardware13 Oct 2021
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management
43RISK
open
GitHub PoC61
Tool check: CVE-2021-41773, CVE-2021-42013, CVE-2020-17519
CVE-2021-41773HIGHunder attackransomware13 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
musergi/CVE-2021-3156
CVE-2021-3156HIGHunder attack13 Oct 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
Hasintha-98/Sudo-Vulnerability-Exploit-CVE-2019-14287
CVE-2019-1428713 Oct 2021
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
VulnCheck XDB
infoleak
CVE-2020-1077013 Oct 2021
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack13 Oct 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC8
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
CVE-2020-1077013 Oct 2021
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RISK
open
GitHub PoC61
Tool check: CVE-2021-41773, CVE-2021-42013, CVE-2020-17519
CVE-2020-17519CRITICALunder attack13 Oct 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE)
CVE-2021-42013CRITICALunder attackransomwarewebappsmultiple13 Oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
Exploit-DB
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
CVE-2020-10770webappsjava13 Oct 2021
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RISK
open
GitHub PoC13
hoav18/CVE-2021-22941
CVE-2021-22941CRITICALunder attackransomware12 Oct 2021
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacke
90RISK
open
Metasploit400
Win32k NtGdiResetDC Use After Free Local Privilege Elevation
CVE-2021-40449HIGHunder attackransomware12 Oct 2021
Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
nxlog ubuntu CVE-2020-35488
CVE-2020-3548812 Oct 2021
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of
23RISK
open
VulnCheck XDB
initial-access
CVE-2019-1881812 Oct 2021
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
VulnCheck XDB
local
CVE-2021-34486HIGHunder attack12 Oct 2021
Windows Event Tracing Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC51
Windows Etw LPE
CVE-2021-34486HIGHunder attack12 Oct 2021
Windows Event Tracing Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC1
critical: Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) (CVE-2021-42013)
CVE-2021-41773HIGHunder attackransomware12 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
previouspage 646 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.