Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
78,258 exploits
GitHub PoC5
Automatic Explotation PoC for Polkit CVE-2021-3560
CVE-2021-3560HIGHunder attack11 Jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC82
CVE-2021-3560 Local PrivEsc Exploit
CVE-2021-3560HIGHunder attack11 Jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
Metasploit300
Wordpress Popular Posts Authenticated RCE
CVE-2021-42362HIGH11 Jun 2021
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RISK
open
Exploit-DB
WordPress Plugin Database Backups 1.2.2.6 - 'Database Backup Download' CSRF
CVE-2021-24174webappsphp11 Jun 2021
Database Backups <= 1.2.2.6 - CSRF to Backup Download
23RISK
open
GitHub PoC8
Python3 POC for CVE 2020-11060
CVE-2020-11060HIGH11 Jun 2021
Remote Code Execution in GLPI
46RISK
open
Exploit-DB
Microsoft SharePoint Server 16.0.10372.20060 - 'GetXmlDataFromDataSource' Server-Side Request Forgery (SSRF)
CVE-2021-31950HIGHwebappswindows11 Jun 2021
Microsoft SharePoint Server Spoofing Vulnerability
41RISK
open
GitHub PoC
sujaygr8/CVE-2020-3452
CVE-2020-3452HIGHunder attack10 Jun 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-3452HIGHunder attack10 Jun 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2020-1020HIGHunder attack10 Jun 2021
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RISK
open
GitHub PoC2
CrackerCat/CVE-2020-1020-Exploit
CVE-2020-1020HIGHunder attack10 Jun 2021
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RISK
open
Exploit-DB
Intelbras Router RF 301K - 'DNS Hijacking' Cross-Site Request Forgery (CSRF)
CVE-2021-32403webappshardware09 Jun 2021
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mecha
23RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack09 Jun 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2021-33739HIGHunder attack09 Jun 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC10
freeide2017/CVE-2021-33739-POC
CVE-2021-33739HIGHunder attack09 Jun 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RISK
open
Metasploit300
Print Spooler Remote DLL Injection
CVE-2021-1675HIGHunder attackransomware08 Jun 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
Metasploit300
Print Spooler Remote DLL Injection
CVE-2021-34527HIGHunder attackransomware08 Jun 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
info-leak
CVE-2017-955408 Jun 2021
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RISK
open
Exploit-DB
WordPress Plugin wpDiscuz 7.0.4 - Remote Code Execution (Unauthenticated)
CVE-2020-24186CRITICALwebappsphp08 Jun 2021
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISK
open
GitHub PoC
CVE-2017-9554 Exploit Tool
CVE-2017-955408 Jun 2021
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RISK
open
GitHub PoC
Bludit 3.9.2 - Auth Brute Force Mitigation Bypass. CVE-2019-17240
CVE-2019-17240LOW07 Jun 2021
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
Exploit-DBVexDay Proof
Rocket.Chat 3.12.1 - NoSQL Injection (Unauthenticated)
CVE-2021-22911webappslinux07 Jun 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
GitHub PoC7
suprise4u/CVE-2019-1388
CVE-2019-1388HIGHunder attackransomware07 Jun 2021
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RISK
open
Exploit-DB
IcoFX 2.6 - '.ico' Buffer Overflow SEH + DEP Bypass using JOP
CVE-2013-4988localwindows07 Jun 2021
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun
50RISK
open
Exploit-DB
Grav CMS 1.7.10 - Server-Side Template Injection (SSTI) (Authenticated)
CVE-2021-29440HIGHwebappsphp07 Jun 2021
Twig allowing dangerous PHP functions by default
53RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-999507 Jun 2021
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC4
kienquoc102/CVE-2018-9995-2
CVE-2018-999507 Jun 2021
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
Exploit-DB
Wordpress Plugin wpDiscuz 7.0.4 - Arbitrary File Upload (Unauthenticated)
CVE-2020-24186CRITICALwebappsphp07 Jun 2021
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISK
open
GitHub PoC
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
CVE-2020-949606 Jun 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-949606 Jun 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
GitHub PoC4
Unsafe Twig processing of static pages leading to RCE in Grav CMS 1.7.10
CVE-2021-29440HIGH06 Jun 2021
Twig allowing dangerous PHP functions by default
53RISK
open
previouspage 682 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.