Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
78,258 exploits
Metasploit300
Jetty WEB-INF File Disclosure
CVE-2021-34429MEDIUM15 Jul 2021
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
70RISK
open
Metasploit300
Jetty WEB-INF File Disclosure
CVE-2021-28164MEDIUM15 Jul 2021
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
70RISK
open
GitHub PoC
TheWay-hue/CVE-2017-5689-Checker
CVE-2017-5689CRITICALunder attack14 Jul 2021
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RISK
open
GitHub PoC
Wordpress Most Popular Post plugin vuln
CVE-2021-42362HIGH14 Jul 2021
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RISK
open
GitHub PoC1
1stPeak/CVE-2020-0796-Scanner
CVE-2020-0796CRITICALunder attackransomware14 Jul 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-5689CRITICALunder attack14 Jul 2021
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RISK
open
Exploit-DB
Webmin 1.973 - 'save_user.cgi' Cross-Site Request Forgery (CSRF)
CVE-2021-31762webappslinux14 Jul 2021
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users fea
23RISK
open
VulnCheck XDB
initial-access
CVE-2021-3046114 Jul 2021
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware13 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
Apache Tomcat 9.0.0.M1 - Open Redirect
CVE-2018-11784webappsmultiple13 Jul 2021
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a r
60RISK
open
GitHub PoC
Cve-2021-1675 or cve-2021-34527? Detailed analysis and exploitation of windows print spooler 0day vulnerability!!!
CVE-2021-34527HIGHunder attackransomware13 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated) (2)
CVE-2018-15139webappsphp13 Jul 2021
Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote
28RISK
open
Exploit-DB
Apache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS)
CVE-2019-0221webappsmultiple13 Jul 2021
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided
50RISK
open
GitHub PoC
CVE-2021-1675 / CVE-2021-34527 - PrintNightmare Python, C# and PowerShell Exploits Implementations (LPE & RCE)
CVE-2021-1675HIGHunder attackransomware12 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware12 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALunder attack12 Jul 2021
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALunder attack12 Jul 2021
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
GitHub PoC2
A patch for PrintNightmare vulnerability that occurs to print spooler service for Windows machines [CVE-2021-34527]
CVE-2021-34527HIGHunder attackransomware12 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
h3x0v3rl0rd/CVE-2015-1635
CVE-2015-1635CRITICALunder attack12 Jul 2021
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
GitHub PoC2
h3x0v3rl0rd/CVE-2015-1635-POC
CVE-2015-1635CRITICALunder attack12 Jul 2021
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
GitHub PoC
cve-2021-21985 powershell poc
CVE-2021-21985CRITICALunder attackransomware11 Jul 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC15
k8gege/cve-2021-1675
CVE-2021-1675HIGHunder attackransomware11 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Scanner for CVE-2020-1938
CVE-2020-1938CRITICALunder attack11 Jul 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC1
h3x0v3rl0rd/CVE-2011-1249
CVE-2011-124910 Jul 2021
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis
23RISK
open
GitHub PoC
h3x0v3rl0rd/CVE-2019-6447
CVE-2019-644709 Jul 2021
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open
GitHub PoC
Fix for PrintNightmare CVE-2021-34527
CVE-2021-34527HIGHunder attackransomware09 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
A collection of scripts to help set the appropriate registry keys for CVE-2021-34527
CVE-2021-34527HIGHunder attackransomware09 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
dywhoami/CVE-2021-34527-Scanner-Based-On-cube0x0-POC
CVE-2021-34527HIGHunder attackransomware09 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-34527HIGHunder attackransomware09 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
h3x0v3rl0rd/CVE-2019-5736
CVE-2019-573608 Jul 2021
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
previouspage 675 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.