Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
78,258 exploits
Exploit-DB
FlatCore CMS 2.0.7 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-39608webappsphp06 Sep 2021
Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a rem
35RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware05 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
Confluence OGNL Injection [CVE-2021-26084].
CVE-2021-26086MEDIUMunder attack05 Sep 2021
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMunder attackransomware04 Sep 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open
GitHub PoC120
Proof of Concept for CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207
CVE-2021-34473CRITICALunder attackransomware04 Sep 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Setting up POC for CVE-2021-26084
CVE-2021-26084CRITICALunder attackransomware04 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC42
A Python replicated exploit for Webmin 1.580 /file/show.cgi Remote Code Execution
CVE-2012-298204 Sep 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALunder attackransomware04 Sep 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC2
CVE-2021-34646 PoC
CVE-2021-34646CRITICAL04 Sep 2021
Booster for WooCommerce <= 5.4.3 Authentication Bypass
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALunder attackransomware04 Sep 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALunder attackransomware04 Sep 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
Anonimo501/SMBGhost_CVE-2020-0796_checker
CVE-2020-0796CRITICALunder attackransomware04 Sep 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
BabyTeam1024/cve-2018-2628
CVE-2018-2628CRITICALunder attack04 Sep 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC1
Wordpress Plainview Activity Monitor Plugin RCE (20161228)
CVE-2018-1587704 Sep 2021
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RISK
open
VulnCheck XDB
local
CVE-2021-21551HIGHunder attack03 Sep 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware03 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC3
CVE-2021-26084 Confluence OGNL injection
CVE-2021-26084CRITICALunder attackransomware03 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
local
CVE-2021-22555HIGHunder attack03 Sep 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
GitHub PoC
cve-2021-26084 EXP
CVE-2021-26084CRITICALunder attackransomware03 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC32
Dell Driver EoP (CVE-2021-21551)
CVE-2021-21551HIGHunder attack03 Sep 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISK
open
GitHub PoC4
Exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT.
CVE-2018-011403 Sep 2021
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
GitHub PoC
CVE-2021-26084
CVE-2021-26084CRITICALunder attackransomware03 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC3
This nuclei template is to verify the vulnerability without executing any commands to the target machine
CVE-2021-26084CRITICALunder attackransomware02 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
Just run command without brain
CVE-2021-26084CRITICALunder attackransomware02 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
Exploit-DB
Compro Technology IP Camera - 'Multiple' Credential Disclosure
CVE-2021-40380webappshardware02 Sep 2021
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. cameralist.cgi and set
28RISK
open
GitHub PoC
This is exploit
CVE-2021-26084CRITICALunder attackransomware02 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
Exploit-DB
Compro Technology IP Camera - RTSP stream disclosure (Unauthenticated)
CVE-2021-40379webappshardware02 Sep 2021
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 doe
28RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware02 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware02 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware02 Sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
previouspage 665 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.