Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,295cataloged exploits
36,048CVEs with public exploitation
24,695lab-tested
78,258 exploits
GitHub PoC2
CVE-2019-11043
CVE-2019-11043HIGHunder attackransomware10 Aug 2021
Underflow in PHP-FPM can lead to RCE
100RISK
open
Exploit-DB
Xiaomi browser 10.2.4.g - Browser Search History Disclosure
CVE-2018-20523localandroid10 Aug 2021
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider
28RISK
open
GitHub PoC
CVE-2021-2109 basic scanner
CVE-2021-2109HIGH09 Aug 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RISK
open
VulnCheck XDB
client-side
CVE-2013-3900MEDIUMunder attack08 Aug 2021
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
GitHub PoC9
BabyTeam1024/CVE-2021-2394
CVE-2021-2394CRITICAL08 Aug 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
70RISK
open
GitHub PoC
Very basic bash script to exploit the CVE-2019-6447.
CVE-2019-644708 Aug 2021
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open
GitHub PoC
Modified version of CVE-2019-5736-PoC by Frichetten
CVE-2019-573607 Aug 2021
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack07 Aug 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Metasploit300
Canon Driver Privilege Escalation
CVE-2021-3808507 Aug 2021
The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer pro
18RISK
open
GitHub PoC1
this script is exploit for wordpress old plugin gwolle
CVE-2015-835106 Aug 2021
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RISK
open
GitHub PoC
CVE-2020-35847, CVE-2020-35848 : Account Takeover
CVE-2020-3584706 Aug 2021
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
60RISK
open
VulnCheck XDB
initial-access
CVE-2015-835106 Aug 2021
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RISK
open
VulnCheck XDB
initial-access
CVE-2017-1000486CRITICALunder attack05 Aug 2021
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISK
open
GitHub PoC4
Pastea/CVE-2017-1000486
CVE-2017-1000486CRITICALunder attack05 Aug 2021
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISK
open
Exploit-DB
CMSuno 1.7 - 'tgo' Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-36654webappsphp05 Aug 2021
CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while
23RISK
open
GitHub PoC
Windows Elevation of Privilege Vulnerability CVE-2021-36934
CVE-2021-36934HIGHunder attack04 Aug 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC4
s4dbrd/CVE-2020-9496
CVE-2020-949604 Aug 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware04 Aug 2021
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC1
An implementation of CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware04 Aug 2021
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
Exploit-DB
ApacheOfBiz 17.12.01 - Remote Command Execution (RCE)
CVE-2020-9496webappsjava04 Aug 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
Metasploit300
Pi-Hole Top Domains API Authenticated Exec
CVE-2021-32706HIGH04 Aug 2021
(Authenticated) Remote Code Execution Possible in Web Interface 5.5
48RISK
open
Exploit-DBVexDay Proof
qdPM 9.1 - Remote Code Execution (Authenticated)
CVE-2020-7246webappsphp04 Aug 2021
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISK
open
GitHub PoC1
An implementation of CVE-2016-8740
CVE-2016-874003 Aug 2021
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2
45RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack02 Aug 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC20
POC of CVE-2021-2394
CVE-2021-2394CRITICAL02 Aug 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
70RISK
open
GitHub PoC2
POC experiments with Volume Shadow copy Service (VSS)
CVE-2021-36934HIGHunder attack02 Aug 2021
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC40
POC of CVE-2021-2394
CVE-2021-2394CRITICAL02 Aug 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
70RISK
open
GitHub PoC3
PenTestical/CVE-2021-22204
CVE-2021-22204MEDIUMunder attack02 Aug 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
GitHub PoC27
AssassinUKG/CVE-2021-22204
CVE-2021-22204MEDIUMunder attack02 Aug 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
GitHub PoC
CVE-2018-20250
CVE-2018-20250HIGHunder attackransomware02 Aug 2021
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
previouspage 670 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.