Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
78,258 exploits
VulnCheck XDB
remote-with-credentials
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC264
Techniques based on named pipes for pool overflow exploitation targeting the most recent (and oldest) Windows versions demonstrated on CVE-2020-17087 and an off-by-one overflow
CVE-2020-17087HIGHunder attack02 Jul 2021
Windows Kernel Local Elevation of Privilege Vulnerability
71RISK
open
Exploit-DB
Wordpress Plugin Modern Events Calendar 5.16.2 - Event export (Unauthenticated)
CVE-2021-24146webappsphp02 Jul 2021
Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export
50RISK
open
Exploit-DB
AKCP sensorProbe SPX476 - 'Multiple' Cross-Site Scripting (XSS)
CVE-2021-35956webappshardware02 Jul 2021
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote aut
23RISK
open
Exploit-DB
Wordpress Plugin Modern Events Calendar 5.16.2 - Remote Code Execution (Authenticated)
CVE-2021-24145webappsphp02 Jul 2021
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISK
open
GitHub PoC
A small powershell script to disable print spooler service using desired state configuration
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC9
corelight/CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
CVE-2021-1675: ZERO-DAY VULNERABILITY IN WINDOWS PRINTER SERVICE WITH AN EXPLOIT AVAILABLE IN ALL OPERATING SYSTEM VERSIONS
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
thomasgeens/CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
mrezqi/CVE-2021-1675_CarbonBlack_HuntingQuery
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
killtr0/CVE-2021-1675-PrintNightmare
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC9
Vulnerability Scanner for CVE-2021-1675/PrintNightmare
CVE-2021-1675HIGHunder attackransomware02 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
CVE-2019-15107 Webmin Exploit in C
CVE-2019-15107CRITICALunder attackransomware02 Jul 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
Exploit-DB
Scratch Desktop 3.17 - Remote Code Execution
CVE-2020-7750CRITICALwebappsmultiple02 Jul 2021
Cross-site Scripting (XSS)
48RISK
open
GitHub PoC1
puckiestyle/CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC56
PrintNightmare , Local Privilege Escalation of CVE-2021-1675 or CVE-2021-34527
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC325
Local Privilege Escalation Edition for CVE-2021-1675/CVE-2021-34527
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC23
cybersecurityworks553/CVE-2021-1675_PrintNightMare
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Fix without disabling Print Spooler
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1,100
Pure PowerShell implementation of CVE-2021-1675 Print Spooler Local Privilege Escalation (PrintNightmare)
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
Wordpress Plugin XCloner 4.2.12 - Remote Code Execution (Authenticated)
CVE-2020-35948CRITICALwebappsphp01 Jul 2021
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated atta
53RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Small Powershell Script to detect Running Printer Spoolers on Domain Controller
CVE-2021-34527HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-1675HIGHunder attackransomware01 Jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-35464CRITICALunder attackransomware01 Jul 2021
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RISK
open
GitHub PoC2
h3x0v3rl0rd/distccd_rce_CVE-2004-2687
CVE-2004-268701 Jul 2021
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISK
open
GitHub PoC1
Proof of Concept Exploit for CVE-2021-35956, AKCP sensorProbe - 'Multiple' Cross Site Scripting (XSS)
CVE-2021-3595601 Jul 2021
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote aut
23RISK
open
GitHub PoC88
openam-CVE-2021-35464 tomcat 执行命令回显
CVE-2021-35464CRITICALunder attackransomware01 Jul 2021
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RISK
open
previouspage 678 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.