Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
77,900 exploits
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware20 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2015-5122HIGHunder attack19 Sep 2021
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RISK
open
GitHub PoC102
Modified code so that we don´t need to rely on CAB archives
CVE-2021-40444HIGHunder attackransomware19 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware19 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2015-5119HIGHunder attack19 Sep 2021
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RISK
open
GitHub PoC1
Converted Metasploit exploits for Adobe Flash vulnerabilities CVE-2015-3090, CVE-2015-3105, CVE-2015-5119, and CVE-2015-5122 to a Python3 script.
CVE-2015-309019 Sep 2021
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
60RISK
open
GitHub PoC3
OMIGod / CVE-2021-38647 POC and Demo environment
CVE-2021-38647CRITICALunder attackransomware19 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Modifed ver of the original exploit to save some times on password reseting for unprivileged user
CVE-2021-2291119 Sep 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
GitHub PoC1
A Vagrant VM test lab to learn about CVE-2021-38647 in the Open Management Infrastructure agent (aka "omigod").
CVE-2021-38647CRITICALunder attackransomware18 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
[CVE-2021-26084] Confluence pre-auth RCE test script
CVE-2021-26084CRITICALunder attackransomware18 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC11
Scan for evidence of CVE-2021-30860 (FORCEDENTRY) exploit
CVE-2021-30860HIGHunder attack18 Sep 2021
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catali
93RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware18 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware18 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
Metasploit600
Hikvision IP Camera Unauthenticated Command Injection
CVE-2021-36260CRITICALunder attack18 Sep 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
Metasploit300
Wordpress BulletProof Security Backup Disclosure
CVE-2021-39327MEDIUM17 Sep 2021
BulletProof Security <= 5.1 Sensitive Information Disclosure
70RISK
open
GitHub PoC2
CVE-2021-40539 POC
CVE-2021-40539CRITICALunder attackransomware17 Sep 2021
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware17 Sep 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
Exploit-DB
WordPress Plugin WooCommerce Booster Plugin 5.4.3 - Authentication Bypass
CVE-2021-34646CRITICALwebappsphp17 Sep 2021
Booster for WooCommerce <= 5.4.3 Authentication Bypass
60RISK
open
GitHub PoC9
quynhle7821/CVE-2021-2302
CVE-2021-2302CRITICAL16 Sep 2021
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported
48RISK
open
GitHub PoC6
CVE-2021-2456
CVE-2021-2456CRITICAL16 Sep 2021
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana
70RISK
open
Metasploit600
ManageEngine ServiceDesk Plus CVE-2021-44077
CVE-2021-44077CRITICALunder attack16 Sep 2021
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC20
OMIGOD! OM I GOOD? A free scanner to detect VMs vulnerable to one of the "OMIGOD" vulnerabilities discovered by Wiz's threat research team, specifically CVE-2021-38647.
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC233
Proof on Concept Exploit for CVE-2021-38647 (OMIGOD)
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
A PoC exploit for CVE-2021-38647 RCE in OMI
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC8
CVE-2021-38647 POC for RCE
CVE-2021-38647CRITICALunder attackransomware15 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC5
CVE-2021-38647 AKA "OMIGOD" vulnerability in Windows OMI
CVE-2021-38647CRITICALunder attackransomware15 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
jaysharma786/CVE-2021-29003
CVE-2021-2900315 Sep 2021
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacter
35RISK
open
GitHub PoC824
CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit
CVE-2021-40444HIGHunder attackransomware15 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
previouspage 654 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.