Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,697GitHub PoC 14,455VulnCheck XDB 8,811Nuclei 4,349Metasploit 3,488✓ verified onlyrecentpopularrisk
77,900 exploits
Exploit-DB
WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS)
Select All Categories and Taxonomies < 1.3.2 - Reflected Cross-Site Scripting (XSS)
43RISK
open ↗Exploit-DB
WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting
Redirect 404 to Parent < 1.3.1 - Reflected Cross-Site Scripting (XSS)
43RISK
open ↗GitHub PoC★ 5
This docx exploit uses res files inside Microsoft .docx file to execute malicious files. This exploit is related to CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
According to researchers with Rapid7, over 110,000 devices appear on internet, which run stable Samba versions, while 92,500 seem to run unstable Samba versions, for which there is no fix. The newest Samba models, including the models 4.6.x before 4.6.4, 4.5.x before 4.5.10 and 3.5.0 before 4.4.13, was impacted by this error. May 24, 2017, Samba released version 4.6.4, which fixes a serious remote code execution vulnerability, vulnerability number CVE-2017-7494, which affected Samba 3.5.0 onwards. Vulnerability number: CVE-2017-7494 Severity Rating: High Affected software: • Samba Version < 4.6.4 • Samba Version < 4.5.10 • Samba Version < 4.4.14 Unaffected software: • Samba Version = 4.6.4 • Samba Version = 4.5.10 • Samba Version = 4.4.14
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open ↗GitHub PoC
漏洞复现与poc收集,CVE-2021-21975,cve-2021-22005,CVE-2021-26295,VMware vCenter任意文件读取
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open ↗GitHub PoC
CVE-2021-25162
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products
28RISK
open ↗GitHub PoC★ 14
CrackerCat/CVE-2021-30632
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISK
open ↗GitHub PoC★ 37
rwincey/CVE-2021-22005
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open ↗Exploit-DB
WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS)
Popup by Supsystic < 1.10.5 - Reflected Cross-Site scripting (XSS)
43RISK
open ↗Exploit-DB
WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
TranslatePress < 2.0.9 - Authenticated Stored Cross-Site Scripting
23RISK
open ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗Exploit-DB
WordPress Plugin Contact Form 1.7.14 - Reflected Cross-Site Scripting (XSS)
Contact Form by Supsystic < 1.7.15 - Reflected Cross-Site scripting (XSS)
43RISK
open ↗VulnCheck XDB
initial-access
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open ↗Exploit-DB
WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS)
Ultimate Maps by Supsystic < 1.2.5 - Reflected Cross-Site scripting (XSS)
43RISK
open ↗VulnCheck XDB
initial-access
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open ↗VulnCheck XDB
denial-of-service
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open ↗GitHub PoC★ 19
Windows HTTP协议栈远程代码执行漏洞 CVE-2021-31166
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 2
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open ↗Exploit-DB
XAMPP 7.4.3 - Local Privilege Escalation
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged
28RISK
open ↗GitHub PoC★ 1
CVE-2021-22005_PoC
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open ↗GitHub PoC
Sudo heap-based buffer overflow privilege escalation commands and mitigations.
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open ↗GitHub PoC★ 3
CVE-2019-19781
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open ↗VulnCheck XDB
initial-access
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open ↗GitHub PoC★ 209
Python implementation for PrintNightmare (CVE-2021-1675 / CVE-2021-34527)
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
Quick and dirty CVE-2021-38647 (Omigod) exploit written in Go.
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.