Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,697GitHub PoC 14,455VulnCheck XDB 8,811Nuclei 4,349Metasploit 3,488✓ verified onlyrecentpopularrisk
77,900 exploits
GitHub PoC★ 4
CVE-2021-41773 Grabber
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC
Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗VulnCheck XDB
client-side
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open ↗GitHub PoC★ 8
dongpohezui/cve-2021-33045
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open ↗VulnCheck XDB
initial-access
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open ↗GitHub PoC★ 188
Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open ↗GitHub PoC
rasyidfox/CVE-2019-18818
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open ↗VulnCheck XDB
initial-access
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗VulnCheck XDB
local
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0
76RISK
open ↗GitHub PoC
CyberTuz/CVE-2019-15107_detection
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open ↗VulnCheck XDB
local
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open ↗GitHub PoC★ 23
Apache (Linux) CVE-2021-41773/2021-42013 Mass Vulnerability Checker
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗VulnCheck XDB
local
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS
76RISK
open ↗GitHub PoC★ 147
CVE-2021-41773 CVE-2021-42013漏洞批量检测工具
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 2
cve-2021-41773 即 cve-2021-42013 批量检测脚本
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 1
Apache 2.4.49 Path Traversal Vulnerability Checker
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 133
Exploit for CVE-2021-30807
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS
76RISK
open ↗VulnCheck XDB
local
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open ↗VulnCheck XDB
client-side
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 5
Remote Code Execution POC for CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open ↗GitHub PoC
Murasame-nc/CVE-2020-0796-LPE-POC
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open ↗Exploit-DB
django-unicorn 0.35.3 - Stored Cross-Site Scripting (XSS)
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.
23RISK
open ↗VulnCheck XDB
client-side
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RISK
open ↗VulnCheck XDB
initial-access
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISK
open ↗Exploit-DB
Maian-Cart 3.8 - Remote Code Execution (RCE) (Unauthenticated)
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the
50RISK
open ↗GitHub PoC
A Python script to check if an Apache web server is vulnerable to CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 1
A Zeek package which raises notices for Path Traversal/RCE in Apache HTTP Server 2.4.49 (CVE-2021-41773) and 2.4.50 (CVE-2021-42013)
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 2
I have come-up with a POC for Payara Micro Community 5.2021.6 - Directory Traversal, Please refer above reference field.
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.