Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,295cataloged exploits
36,048CVEs with public exploitation
24,695lab-tested
78,258 exploits
GitHub PoC3
WordPress File Upload Vulnerability, Modern Events Calendar Lite WordPress plugin before 5.16.5
CVE-2021-2414514 Aug 2021
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALunder attackransomware13 Aug 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALunder attackransomware13 Aug 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Sudo Heap Overflow Baron Samedit
CVE-2021-3156HIGHunder attack13 Aug 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
WpDiscuz 7.0.4 Arbitrary File Upload Exploit
CVE-2020-24186CRITICAL13 Aug 2021
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISK
open
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALunder attackransomware13 Aug 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMunder attackransomware13 Aug 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALunder attackransomware13 Aug 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMunder attackransomware13 Aug 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack13 Aug 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack12 Aug 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
Exploit-DB
Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE)
CVE-2021-37425webappsmultiple12 Aug 2021
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workfl
35RISK
open
GitHub PoC3
Exploit for CVE-2021-36934
CVE-2021-36934HIGHunder attack12 Aug 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC
Jerry-zhuang/CVE-2017-1000117
CVE-2017-100011711 Aug 2021
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RISK
open
GitHub PoC
Zeek Package to detect cve-2017-2741
CVE-2017-274111 Aug 2021
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RISK
open
GitHub PoC5
Scanner for CVE-2021-34473, ProxyShell, A Microsoft Exchange On-premise Vulnerability
CVE-2021-34473CRITICALunder attackransomware11 Aug 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALunder attackransomware10 Aug 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack10 Aug 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
infoleak
CVE-2021-31207MEDIUMunder attackransomware10 Aug 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open
GitHub PoC46
nuclei scanner for proxyshell ( CVE-2021-34473 )
CVE-2021-34473CRITICALunder attackransomware10 Aug 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-11043HIGHunder attackransomware10 Aug 2021
Underflow in PHP-FPM can lead to RCE
100RISK
open
VulnCheck XDB
client-side
CVE-2020-1020HIGHunder attack10 Aug 2021
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RISK
open
GitHub PoC2
CVE-2019-11043
CVE-2019-11043HIGHunder attackransomware10 Aug 2021
Underflow in PHP-FPM can lead to RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-1272510 Aug 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
GitHub PoC
ZeroShell命令执行漏洞批量扫描poc+exp
CVE-2019-1272510 Aug 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
Exploit-DB
Cockpit CMS 0.11.1 - 'Username Enumeration & Password Reset' NoSQL Injection
CVE-2020-35848webappsmultiple10 Aug 2021
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALunder attackransomware10 Aug 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
Amica Prodigy 1.7 - Privilege Escalation
CVE-2021-35312localwindows10 Aug 2021
A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Serv
23RISK
open
Exploit-DB
Xiaomi browser 10.2.4.g - Browser Search History Disclosure
CVE-2018-20523localandroid10 Aug 2021
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider
28RISK
open
GitHub PoC10
Windows Font Driver Type 1 VToHOrigin stack corruption
CVE-2020-1020HIGHunder attack10 Aug 2021
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RISK
open
previouspage 669 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.