Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
78,291 exploits
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMunder attack12 May 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
GitHub PoC12
exiftool arbitrary code execution vulnerability
CVE-2021-22204MEDIUMunder attack12 May 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
GitHub PoC1
0xm4ud/Cacti-CVE-2020-8813
CVE-2020-881311 May 2021
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISK
open
GitHub PoC96
Python exploit for the CVE-2021-22204 vulnerability in Exiftool
CVE-2021-22204MEDIUMunder attack11 May 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
Metasploit300
Windows IIS HTTP Protocol Stack DOS
CVE-2021-31166CRITICALunder attack11 May 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
Metasploit600
Microsoft SharePoint Unsafe Control and ViewState RCE
CVE-2021-31181HIGH11 May 2021
Microsoft SharePoint Remote Code Execution Vulnerability
48RISK
open
Metasploit500
Linux eBPF ALU32 32-bit Invalid Bounds Tracking LPE
CVE-2021-3490HIGH11 May 2021
Linux kernel eBPF bitwise ops ALU32 bounds tracking
41RISK
open
VulnCheck XDB
initial-access
CVE-2021-3046111 May 2021
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISK
open
GitHub PoC3
Exploit for Node-jose < 0.11.0 written in Ruby
CVE-2018-011411 May 2021
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMunder attack11 May 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
GitHub PoC3
POC Exploit written in Ruby
CVE-2019-542011 May 2021
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
GitHub PoC
fu2x2000/CVE-2017-17058-woo_exploit
CVE-2017-17058HIGH11 May 2021
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco
46RISK
open
VulnCheck XDB
initial-access
CVE-2020-881311 May 2021
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack10 May 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Exploit-DB
Microweber CMS 1.1.20 - Remote Code Execution (Authenticated)
CVE-2020-28337webappsphp10 May 2021
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to g
28RISK
open
GitHub PoC3
Check YouTube - https://youtu.be/O0ZnLXRY5Wo
CVE-2020-14882CRITICALunder attack10 May 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Metasploit300
Apache 2.4.49/2.4.50 Traversal RCE scanner
CVE-2021-42013CRITICALunder attackransomware10 May 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
Metasploit600
Apache 2.4.49/2.4.50 Traversal RCE
CVE-2021-42013CRITICALunder attackransomware10 May 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
Metasploit600
Apache 2.4.49/2.4.50 Traversal RCE
CVE-2021-41773HIGHunder attackransomware10 May 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Metasploit300
Apache 2.4.49/2.4.50 Traversal RCE scanner
CVE-2021-41773HIGHunder attackransomware10 May 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC6
CVE-2017-7494 python exploit
CVE-2017-7494CRITICALunder attackransomware09 May 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack09 May 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALunder attackransomware09 May 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3046107 May 2021
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack07 May 2021
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-949607 May 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
GitHub PoC3
CVE-2019-2215
CVE-2019-2215HIGHunder attack07 May 2021
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3046106 May 2021
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISK
open
Exploit-DB
b2evolution 7-2-2 - 'cf_name' SQL Injection
CVE-2021-28242webappsphp06 May 2021
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive dat
23RISK
open
Metasploit600
Cisco HyperFlex HX Data Platform unauthenticated file upload to RCE (CVE-2021-1499)
CVE-2021-1499MEDIUM05 May 2021
Cisco HyperFlex HX Data Platform File Upload Vulnerability
50RISK
open
previouspage 688 / 2,610next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.