Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
78,056 exploits
Exploit-DB
WordPress Plugin Fitness Calculators 1.9.5 - Cross-Site Request Forgery (CSRF)
CVE-2021-24272webappsphp23 Sep 2021
Fitness Calculators < 1.9.6 - Cross-Site Request Forgery to Cross-Site Scripting (XSS)
23RISK
open
GitHub PoC1
pisut4152/Sigma-Rule-for-CVE-2021-22005-scanning-activity
CVE-2021-22005CRITICALunder attackransomware23 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
GitHub PoC8
1ZRR4H/CVE-2021-22005
CVE-2021-22005CRITICALunder attackransomware23 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
Exploit-DB
Gurock Testrail 7.2.0.3014 - 'files.md5' Improper Access Control
CVE-2021-40875webappsmultiple23 Sep 2021
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat ac
50RISK
open
Metasploit600
Microsoft Office Word Malicious MSHTML RCE
CVE-2021-40444HIGHunder attackransomware23 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
OpenCats 0.9.4-2 - 'docx ' XML External Entity Injection (XXE)
CVE-2019-13358webappsphp22 Sep 2021
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying opera
28RISK
open
GitHub PoC
https://github.com/corelight/CVE-2021-38647 without the bloat
CVE-2021-38647CRITICALunder attackransomware22 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
Cloudron 6.2 - 'returnTo ' Cross Site Scripting (Reflected)
CVE-2021-40868webappsmultiple22 Sep 2021
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
38RISK
open
Metasploit600
VMware vCenter Server Analytics (CEIP) Service File Upload
CVE-2021-22005CRITICALunder attackransomware21 Sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
Metasploit0
VMware vCenter vScalation Priv Esc
CVE-2021-2201521 Sep 2021
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and
18RISK
open
VulnCheck XDB
client-side
CVE-2021-30632HIGHunder attack20 Sep 2021
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware20 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC68
CVE-2021-38647 - POC to exploit unauthenticated RCE #OMIGOD
CVE-2021-38647CRITICALunder attackransomware20 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
WordPress 5.7 - 'Media Library' XML External Entity Injection (XXE) (Authenticated)
CVE-2021-29447HIGHwebappsphp20 Sep 2021
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC102
Modified code so that we don´t need to rely on CAB archives
CVE-2021-40444HIGHunder attackransomware19 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2015-5122HIGHunder attack19 Sep 2021
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RISK
open
VulnCheck XDB
client-side
CVE-2015-5119HIGHunder attack19 Sep 2021
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RISK
open
GitHub PoC1
Converted Metasploit exploits for Adobe Flash vulnerabilities CVE-2015-3090, CVE-2015-3105, CVE-2015-5119, and CVE-2015-5122 to a Python3 script.
CVE-2015-309019 Sep 2021
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware19 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
OMIGod / CVE-2021-38647 POC and Demo environment
CVE-2021-38647CRITICALunder attackransomware19 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Modifed ver of the original exploit to save some times on password reseting for unprivileged user
CVE-2021-2291119 Sep 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
GitHub PoC3
[CVE-2021-26084] Confluence pre-auth RCE test script
CVE-2021-26084CRITICALunder attackransomware18 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware18 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware18 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
Metasploit600
Hikvision IP Camera Unauthenticated Command Injection
CVE-2021-36260CRITICALunder attack18 Sep 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC1
A Vagrant VM test lab to learn about CVE-2021-38647 in the Open Management Infrastructure agent (aka "omigod").
CVE-2021-38647CRITICALunder attackransomware18 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC11
Scan for evidence of CVE-2021-30860 (FORCEDENTRY) exploit
CVE-2021-30860HIGHunder attack18 Sep 2021
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catali
93RISK
open
Exploit-DB
WordPress Plugin WooCommerce Booster Plugin 5.4.3 - Authentication Bypass
CVE-2021-34646CRITICALwebappsphp17 Sep 2021
Booster for WooCommerce <= 5.4.3 Authentication Bypass
60RISK
open
GitHub PoC2
CVE-2021-40539 POC
CVE-2021-40539CRITICALunder attackransomware17 Sep 2021
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open
Metasploit300
Wordpress BulletProof Security Backup Disclosure
CVE-2021-39327MEDIUM17 Sep 2021
BulletProof Security <= 5.1 Sensitive Information Disclosure
70RISK
open
previouspage 657 / 2,602next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.