Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
77,900 exploits
GitHub PoC4
CVE-2021-41773 Grabber
CVE-2021-41773HIGHunder attackransomware11 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE
CVE-2021-41773HIGHunder attackransomware11 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
client-side
CVE-2021-33044CRITICALunder attack11 Oct 2021
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
GitHub PoC8
dongpohezui/cve-2021-33045
CVE-2021-33045CRITICALunder attack11 Oct 2021
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-33045CRITICALunder attack11 Oct 2021
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
GitHub PoC188
Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.
CVE-2021-33044CRITICALunder attack11 Oct 2021
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
GitHub PoC
rasyidfox/CVE-2019-18818
CVE-2019-1881811 Oct 2021
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-1881811 Oct 2021
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware11 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
local
CVE-2021-30883HIGHunder attack11 Oct 2021
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0
76RISK
open
GitHub PoC
CyberTuz/CVE-2019-15107_detection
CVE-2019-15107CRITICALunder attackransomware10 Oct 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware09 Oct 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware09 Oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC23
Apache (Linux) CVE-2021-41773/2021-42013 Mass Vulnerability Checker
CVE-2021-41773HIGHunder attackransomware09 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
local
CVE-2021-30807HIGHunder attack09 Oct 2021
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS
76RISK
open
GitHub PoC147
CVE-2021-41773 CVE-2021-42013漏洞批量检测工具
CVE-2021-41773HIGHunder attackransomware09 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
cve-2021-41773 即 cve-2021-42013 批量检测脚本
CVE-2021-41773HIGHunder attackransomware09 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
Apache 2.4.49 Path Traversal Vulnerability Checker
CVE-2021-41773HIGHunder attackransomware09 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC133
Exploit for CVE-2021-30807
CVE-2021-30807HIGHunder attack09 Oct 2021
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS
76RISK
open
VulnCheck XDB
local
CVE-2020-0796CRITICALunder attackransomware09 Oct 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
client-side
CVE-2021-41773HIGHunder attackransomware09 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC5
Remote Code Execution POC for CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware09 Oct 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
Murasame-nc/CVE-2020-0796-LPE-POC
CVE-2020-0796CRITICALunder attackransomware09 Oct 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Exploit-DB
django-unicorn 0.35.3 - Stored Cross-Site Scripting (XSS)
CVE-2021-42053webappspython08 Oct 2021
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.
23RISK
open
VulnCheck XDB
client-side
CVE-2016-9079HIGHunder attack08 Oct 2021
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-40870CRITICALunder attack08 Oct 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISK
open
Exploit-DB
Maian-Cart 3.8 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2021-32172webappsphp08 Oct 2021
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the
50RISK
open
GitHub PoC
A Python script to check if an Apache web server is vulnerable to CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware08 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
A Zeek package which raises notices for Path Traversal/RCE in Apache HTTP Server 2.4.49 (CVE-2021-41773) and 2.4.50 (CVE-2021-42013)
CVE-2021-41773HIGHunder attackransomware08 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
I have come-up with a POC for Payara Micro Community 5.2021.6 - Directory Traversal, Please refer above reference field.
CVE-2021-4138108 Oct 2021
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
50RISK
open
previouspage 647 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.