Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
78,208 exploits
GitHub PoC
KnoooW/CVE-2021-40444-docx-Generate
CVE-2021-40444HIGHunder attackransomware11 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC11
A malicious .cab creation tool for CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware11 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC4
fengjixuchui/CVE-2021-40444-docx-Generate
CVE-2021-40444HIGHunder attackransomware11 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-1960911 Sep 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware10 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-25078HIGHunder attack10 Sep 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RISK
open
GitHub PoC1
koharin/CVE-2020-0041
CVE-2020-0041HIGHunder attack10 Sep 2021
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISK
open
GitHub PoC1,743
CVE-2021-40444 PoC
CVE-2021-40444HIGHunder attackransomware10 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
CVE-2021-40444 Sample
CVE-2021-40444HIGHunder attackransomware10 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Immersive-Labs-Sec/cve-2021-40444-analysis
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
vysecurity/CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
CVE-2020-9054 PoC for Zyxel
CVE-2020-9054CRITICALunder attack09 Sep 2021
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
100RISK
open
GitHub PoC
Confluence OGNL injection
CVE-2021-26084CRITICALunder attackransomware09 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC3
maguireja/CVE-2020-25223
CVE-2020-25223CRITICALunder attack09 Sep 2021
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISK
open
GitHub PoC
Something I wrote for CVE-2019-15107, a Webmin backdoor
CVE-2019-15107CRITICALunder attackransomware09 Sep 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC7
CVE-2021-40444 POC
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC16
rfcxv/CVE-2021-40444-POC
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
根据已知样本反编译代码
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware09 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-9054CRITICALunder attack09 Sep 2021
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-5410HIGHunder attack08 Sep 2021
Directory Traversal with spring-cloud-config-server
100RISK
open
GitHub PoC16
Microsoft MSHTML Remote Code Execution Vulnerability CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware08 Sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
Exploit chain for CVE-2019-9791 & CVE-2019-11708 against firefox 65.0 on windows 64bit
CVE-2019-979108 Sep 2021
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects w
28RISK
open
VulnCheck XDB
client-side
CVE-2019-11708CRITICALunder attack08 Sep 2021
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RISK
open
VulnCheck XDB
client-side
CVE-2021-26084CRITICALunder attackransomware08 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC1
CVE-2021-26084 patch as provided in "Confluence Security Advisory - 2021-08-25"
CVE-2021-26084CRITICALunder attackransomware08 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC2
Patched Confluence 7.12.2 (CVE-2021-26084)
CVE-2021-26084CRITICALunder attackransomware08 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21315HIGHunder attack07 Sep 2021
Command Injection Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware07 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
previouspage 662 / 2,607next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.