Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
78,258 exploits
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware05 Jun 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-2291105 Jun 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
GitHub PoC1
Drupal 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
CVE-2018-7600CRITICALunder attackransomware05 Jun 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC181
mr-r3bot/Gitlab-CVE-2021-22205
CVE-2021-22205CRITICALunder attackransomware05 Jun 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC29
testanull/Project_CVE-2021-21985_PoC
CVE-2021-21985CRITICALunder attackransomware05 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
GitHub PoC71
This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists of embedded payload. The exploit was made public as CVE-2010-1240.
CVE-2010-124005 Jun 2021
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISK
open
GitHub PoC61
Pre-Auth Blind NoSQL Injection leading to Remote Code Execution in Rocket Chat 3.12.1
CVE-2021-2291105 Jun 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALunder attackransomware05 Jun 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21985CRITICALunder attackransomware04 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
Exploit-DB
Monstra CMS 3.0.4 - Remote Code Execution (Authenticated)
CVE-2018-6383webappsphp04 Jun 2021
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but
28RISK
open
GitHub PoC2
CVE-2021-21985 vmware 6.7-9.8 RCE
CVE-2021-21985CRITICALunder attackransomware04 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
Exploit-DB
FUDForum 3.1.0 - 'author' Reflected XSS
CVE-2021-27520webappsphp03 Jun 2021
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "
38RISK
open
Exploit-DB
CHIYU IoT Devices - Denial of Service (DoS)
CVE-2021-31642webappshardware03 Jun 2021
A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including B
35RISK
open
Exploit-DB
CHIYU IoT Devices - 'Telnet' Authentication Bypass
CVE-2021-31251remotehardware03 Jun 2021
An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Tec
35RISK
open
GitHub PoC115
cve-2021-21985 exploit
CVE-2021-21985CRITICALunder attackransomware03 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
Exploit-DB
Seo Panel 4.8.0 - 'from_time' Reflected XSS
CVE-2021-28420webappsphp03 Jun 2021
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and th
23RISK
open
VulnCheck XDB
initial-access
CVE-2020-2494903 Jun 2021
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr
50RISK
open
Metasploit600
Polkit D-Bus Authentication Bypass
CVE-2021-3560HIGHunder attack03 Jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC
PHPFusion 9.03.50 - Remote Code Execution
CVE-2020-2494903 Jun 2021
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr
50RISK
open
Exploit-DB
4Images 1.8 - 'redirect' Reflected XSS
CVE-2021-27308webappsphp03 Jun 2021
A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to in
23RISK
open
Exploit-DB
FUDForum 3.1.0 - 'srch' Reflected XSS
CVE-2021-27519webappsphp03 Jun 2021
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "
38RISK
open
VulnCheck XDB
initial-access
CVE-2021-21985CRITICALunder attackransomware03 Jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISK
open
VulnCheck XDB
local
CVE-2021-21551HIGHunder attack02 Jun 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISK
open
Exploit-DB
Products.PluggableAuthService 2.6.0 - Open Redirect
CVE-2021-21337MEDIUMwebappspython02 Jun 2021
URL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService
33RISK
open
VulnCheck XDB
initial-access
CVE-2020-7247CRITICALunder attack02 Jun 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
GitHub PoC9
bluefrostsecurity/CVE-2021-28476
CVE-2021-28476CRITICAL02 Jun 2021
Windows Hyper-V Remote Code Execution Vulnerability
60RISK
open
Exploit-DB
GetSimple CMS 3.3.4 - Information Disclosure
CVE-2014-8722webappsphp02 Jun 2021
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<user
28RISK
open
Exploit-DB
Apache Airflow 1.10.10 - 'Example Dag' Remote Code Execution
CVE-2020-13927CRITICALunder attackwebappsmultiple02 Jun 2021
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th
100RISK
open
Exploit-DB
Seo Panel 4.8.0 - 'search_name' Reflected XSS
CVE-2021-28417webappsphp02 Jun 2021
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and t
23RISK
open
Exploit-DB
Apache Airflow 1.10.10 - 'Example Dag' Remote Code Execution
CVE-2020-11978HIGHunder attackwebappsmultiple02 Jun 2021
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was disco
100RISK
open
previouspage 683 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.