Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,721GitHub PoC 14,477VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
78,258 exploits
Metasploit300
Jetty WEB-INF File Disclosure
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
70RISK
open ↗Metasploit300
Jetty WEB-INF File Disclosure
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
70RISK
open ↗GitHub PoC
TheWay-hue/CVE-2017-5689-Checker
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RISK
open ↗GitHub PoC
Wordpress Most Popular Post plugin vuln
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RISK
open ↗GitHub PoC★ 1
1stPeak/CVE-2020-0796-Scanner
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open ↗VulnCheck XDB
initial-access
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RISK
open ↗Exploit-DB
Webmin 1.973 - 'save_user.cgi' Cross-Site Request Forgery (CSRF)
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users fea
23RISK
open ↗VulnCheck XDB
initial-access
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISK
open ↗Exploit-DB
Apache Tomcat 9.0.0.M1 - Open Redirect
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a r
60RISK
open ↗GitHub PoC
Cve-2021-1675 or cve-2021-34527? Detailed analysis and exploitation of windows print spooler 0day vulnerability!!!
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗Exploit-DB
OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated) (2)
Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote
28RISK
open ↗Exploit-DB
Apache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS)
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided
50RISK
open ↗GitHub PoC
CVE-2021-1675 / CVE-2021-34527 - PrintNightmare Python, C# and PowerShell Exploits Implementations (LPE & RCE)
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
denial-of-service
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open ↗VulnCheck XDB
denial-of-service
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open ↗GitHub PoC★ 2
A patch for PrintNightmare vulnerability that occurs to print spooler service for Windows machines [CVE-2021-34527]
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
h3x0v3rl0rd/CVE-2015-1635
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open ↗GitHub PoC★ 2
h3x0v3rl0rd/CVE-2015-1635-POC
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open ↗GitHub PoC
cve-2021-21985 powershell poc
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open ↗GitHub PoC★ 15
k8gege/cve-2021-1675
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
Scanner for CVE-2020-1938
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open ↗GitHub PoC★ 1
h3x0v3rl0rd/CVE-2011-1249
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis
23RISK
open ↗GitHub PoC
h3x0v3rl0rd/CVE-2019-6447
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open ↗GitHub PoC
Fix for PrintNightmare CVE-2021-34527
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
A collection of scripts to help set the appropriate registry keys for CVE-2021-34527
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 3
dywhoami/CVE-2021-34527-Scanner-Based-On-cube0x0-POC
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
h3x0v3rl0rd/CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.