Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
77,900 exploits
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware06 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware06 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware06 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware06 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware06 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware06 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
POC: CVE-2019-12840 (Authenticated RCE - Webmin Package Updates)
CVE-2019-1284005 Oct 2021
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware05 Oct 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Exploit para CVE-2019-15107 (Webmin 1.890-1.920) sin credenciales RCE escrito en PYTHON.
CVE-2019-15107CRITICALunder attackransomware05 Oct 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC1
The plugin does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly
CVE-2021-2456305 Oct 2021
Frontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting
28RISK
open
GitHub PoC25
Atlassian Jira Server/Data Center 8.4.0 - Arbitrary File read (CVE-2021-26086)
CVE-2021-26086MEDIUMunder attack05 Oct 2021
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RISK
open
GitHub PoC17
ZephrFish/CVE-2021-41773-PoC
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC9
Path traversal in Apache HTTP Server 2.4.49 (CVE-2021-41773)
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC8
CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC38
CVE-2021-41773 Path Traversal vulnerability in Apache 2.4.49.
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
Working PowerShell POC
CVE-2021-1675HIGHunder attackransomware05 Oct 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
Metasploit300
WordPress Plugin Perfect Survey 1.5.1 SQLi (Unauthenticated)
CVE-2021-2476205 Oct 2021
Perfect Survey < 1.5.2 - Unauthenticated SQL Injection
60RISK
open
GitHub PoC6
Poc.py
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC39
lorddemon/CVE-2021-41773-PoC
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC13
Exploitation of CVE-2021-41773 a Directory Traversal in Apache 2.4.49.
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
masahiro331/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC52
iilegacyyii/PoC-CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware05 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware05 Oct 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
bypass all stages of the password reset flow
CVE-2021-27651CRITICAL05 Oct 2021
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp
75RISK
open
VulnCheck XDB
infoleak
CVE-2021-26085MEDIUMunder attackransomware05 Oct 2021
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RISK
open
previouspage 650 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.