Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
78,056 exploits
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware27 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware27 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
CVE-2021-22005_PoC
CVE-2021-22005CRITICALunder attackransomware27 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware27 Sep 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC3
CVE-2019-19781
CVE-2019-19781CRITICALunder attackransomware27 Sep 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1676327 Sep 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC
Sudo heap-based buffer overflow privilege escalation commands and mitigations.
CVE-2021-3156HIGHunder attack27 Sep 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALunder attackransomware26 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware26 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware26 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Quick and dirty CVE-2021-38647 (Omigod) exploit written in Go.
CVE-2021-38647CRITICALunder attackransomware26 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware26 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC209
Python implementation for PrintNightmare (CVE-2021-1675 / CVE-2021-34527)
CVE-2021-1675HIGHunder attackransomware26 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
AmesianX/CVE-2021-21220
CVE-2021-21220HIGHunder attack26 Sep 2021
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
100RISK
open
GitHub PoC10
C# PrintNightmare (CVE-2021-1675)
CVE-2021-1675HIGHunder attackransomware26 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-34527HIGHunder attackransomware26 Sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-22005CRITICALunder attackransomware25 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
GitHub PoC13
CVE-2021-22005批量验证python脚本
CVE-2021-22005CRITICALunder attackransomware25 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
GitHub PoC17
CVE-2021-3156 - sudo exploit for ubuntu 18.04 & 20.04
CVE-2021-3156HIGHunder attack25 Sep 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC1
Python script to obtain RCE on Mantis Bug Tracker prior to version 1.2.x Check CVE-2008-4687 for additional information
CVE-2008-468725 Sep 2021
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISK
open
GitHub PoC
CVE 2021 40444 Windows Exploit services.dll
CVE-2021-40444HIGHunder attackransomware24 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC5
CVE-2021-33739 PoC Analysis
CVE-2021-33739HIGHunder attack24 Sep 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC1
BeneficialCode/CVE-2021-1732
CVE-2021-1732HIGHunder attackransomware24 Sep 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-33739HIGHunder attack24 Sep 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware24 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware24 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Windows Kernel Registry Elevation of Privilege Vulnerability
CVE-2018-841024 Sep 2021
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory
23RISK
open
GitHub PoC1
CVE-2021-38647 is an unauthenticated RCE vulnerability effecting the OMI agent as root.
CVE-2021-38647CRITICALunder attackransomware24 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
CVE-2021-22005
CVE-2021-22005CRITICALunder attackransomware24 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
Metasploit600
Microsoft Office Word Malicious MSHTML RCE
CVE-2021-40444HIGHunder attackransomware23 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
previouspage 656 / 2,602next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.