Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
78,137 exploits
GitHub PoC2
A PoC exploit for CVE-2021-38647 RCE in OMI
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC20
OMIGOD! OM I GOOD? A free scanner to detect VMs vulnerable to one of the "OMIGOD" vulnerabilities discovered by Wiz's threat research team, specifically CVE-2021-38647.
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-38647CRITICALunder attackransomware16 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC6
CVE-2021-2456
CVE-2021-2456CRITICAL16 Sep 2021
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana
70RISK
open
GitHub PoC9
quynhle7821/CVE-2021-2302
CVE-2021-2302CRITICAL16 Sep 2021
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported
48RISK
open
GitHub PoC10
CVE-2021-33766-poc
CVE-2021-33766HIGHunder attack15 Sep 2021
Microsoft Exchange Server Information Disclosure Vulnerability
100RISK
open
GitHub PoC824
CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit
CVE-2021-40444HIGHunder attackransomware15 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC5
CVE-2021-38647 AKA "OMIGOD" vulnerability in Windows OMI
CVE-2021-38647CRITICALunder attackransomware15 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
jaysharma786/CVE-2021-29003
CVE-2021-2900315 Sep 2021
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacter
35RISK
open
GitHub PoC8
CVE-2021-38647 POC for RCE
CVE-2021-38647CRITICALunder attackransomware15 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-33766HIGHunder attack15 Sep 2021
Microsoft Exchange Server Information Disclosure Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware15 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALunder attackransomware15 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware14 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC19
k8gege/CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware14 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Malicious document builder for CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware14 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
CVE-2018-15473 Exploit
CVE-2018-15473MEDIUM14 Sep 2021
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
Metasploit600
Microsoft OMI Management Interface Authentication Bypass
CVE-2021-38647CRITICALunder attackransomware14 Sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
Metasploit600
Microsoft OMI Management Interface Authentication Bypass
CVE-2021-38648HIGHunder attack14 Sep 2021
Open Management Infrastructure Elevation of Privilege Vulnerability
91RISK
open
Exploit-DB
Facebook ParlAI 1.0.0 - Deserialization of Untrusted Data in parlai
CVE-2021-24040localpython13 Sep 2021
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files c
28RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware13 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC8
CVE-2021-40875: Tools to Inspect Gurock Testrail Servers for Vulnerabilities related to CVE-2021-40875.
CVE-2021-4087513 Sep 2021
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat ac
50RISK
open
VulnCheck XDB
info-leak
CVE-2020-2865313 Sep 2021
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v
60RISK
open
GitHub PoC1
POC for CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware13 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Reverse engineering the "A Letter Before Court 4.docx" malicious files exploting cve-2021-40444
CVE-2021-40444HIGHunder attackransomware12 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC168
This repo contain builders of cab file, html file, and docx file for CVE-2021-40444 exploit
CVE-2021-40444HIGHunder attackransomware12 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC16
Mass exploitation of CVE-2021-24499 unauthenticated upload leading to remote code execution in Workreap theme.
CVE-2021-2449912 Sep 2021
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISK
open
GitHub PoC
W1kyri3/Exploit-PoC-CVE-2021-40444-inject-ma-doc-vao-docx
CVE-2021-40444HIGHunder attackransomware12 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
CVE-2021-21972 vCenter-6.5-7.0 RCE POC
CVE-2021-21972CRITICALunder attackransomware12 Sep 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
previouspage 660 / 2,605next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.