Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,325cataloged exploits
36,055CVEs with public exploitation
24,695lab-tested
78,295 exploits
VulnCheck XDB
initial-access
CVE-2021-3046107 May 2021
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISK
open
VulnCheck XDB
initial-access
CVE-2021-3046106 May 2021
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISK
open
Exploit-DB
b2evolution 7-2-2 - 'cf_name' SQL Injection
CVE-2021-28242webappsphp06 May 2021
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive dat
23RISK
open
GitHub PoC
cve-2019-8942, cve-2019-8943
CVE-2019-894205 May 2021
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISK
open
GitHub PoC20
CVE-2019-1388 Abuse UAC Windows Certificate Dialog
CVE-2019-1388HIGHunder attackransomware05 May 2021
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RISK
open
GitHub PoC
ajtech-hue/CVE-2021-3156-Mitigation-ShellScript-Build
CVE-2021-3156HIGHunder attack05 May 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2019-1388HIGHunder attackransomware05 May 2021
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RISK
open
GitHub PoC
exploit
CVE-2019-1863405 May 2021
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open
Metasploit600
Cisco HyperFlex HX Data Platform Command Execution
CVE-2021-1497CRITICALunder attack05 May 2021
Cisco HyperFlex HX Command Injection Vulnerabilities
100RISK
open
Metasploit600
Cisco HyperFlex HX Data Platform Command Execution
CVE-2021-1498CRITICALunder attack05 May 2021
Cisco HyperFlex HX Command Injection Vulnerabilities
100RISK
open
Metasploit600
Cisco HyperFlex HX Data Platform unauthenticated file upload to RCE (CVE-2021-1499)
CVE-2021-1499MEDIUM05 May 2021
Cisco HyperFlex HX Data Platform File Upload Vulnerability
50RISK
open
Metasploit600
Wordpress Plugin Backup Guard - Authenticated Remote Code Execution
CVE-2021-2415504 May 2021
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
60RISK
open
Metasploit400
Dell DBUtil_2_3.sys IOCTL memmove
CVE-2021-21551HIGHunder attack04 May 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-11581CRITICALunder attack04 May 2021
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISK
open
GitHub PoC6
Atlassian Jira unauthen template injection
CVE-2019-11581CRITICALunder attack04 May 2021
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISK
open
GitHub PoC1
事件: 微軟(Microsoft)上周公布了修補遭到駭客攻擊的 Exchange Server 漏洞,全球恐有數萬個組織受到影響。網域與被入侵的Exchange郵件伺服器有關,而這臺伺服器後來被駭客當作C&C中繼站使用,導致接下來發生加密攻擊事故。 嚴重性: 全球企業普遍使用微軟生態系執行日常業務,若遭受駭客攻擊,將造成用戶機敏資料外洩並導致極大損失。雖然微軟已推出更新補釘,但阿戴爾強調這尚未去除儲存在受害伺服器內的後門殼層(webshell),因此就算尚未受到攻擊的企業可以免於被駭風險,駭客仍有時間入侵已被駭的伺服器留下「定時炸彈」。 從2020年開始,美國便不斷指控中國入侵多家醫藥公司及學術單位,試圖竊取疫苗研發機密,這次事件很可能將使中美之間的關係進一步惡化。至於華為、TikTok等中國服務是否會受到這次駭客事件波及,則暫時還不明朗。 漏洞通報程序: 在2年前,曾經拿下資安圈漏洞奧斯卡獎Pwnie Awards「最佳伺服器漏洞獎」戴夫寇爾首席資安研究員Orange Tsai(蔡政達),漏洞通報記錄不勝枚舉,後來因為針對企業常用的SSL VPN進行漏洞研究與通報,更是在全球資安圈聲名大噪。 不過,在今年3月2日卻發生讓Orange Tsai錯愕不已的事情。那就是,他在今年一月跟微軟通報的2個Exchange漏洞,微軟原訂在3月9日對外釋出修補程式,卻突然提前一週,在3月2日便緊急釋出修補程式。原來是因為,在2月26日到2月28日,這個週五下班後到週末這段期間,全球各地發生許多利用微軟Exchange漏洞發動攻擊的資安事件。 攻擊本質: 有人在網路上大量掃描微軟於本月修補的CVE-2020-0688安全漏洞,該漏洞攸關Microsoft Exchange伺服器,呼籲Exchange用戶應儘速修補。 CVE-2020-0688漏洞肇因於Exchange伺服器在安裝時沒能妥善建立唯一金鑰,將允許具備該知識及信箱的授權用戶以系統權限傳遞任意物件,屬於遠端程式攻擊漏洞,該漏洞影響Microsoft Exchange Server 2010 SP3、Microsoft Exchange Server 2013、Microsoft Exchange Server 2016與Microsoft Exchange Server 2019,但只被微軟列為重要(Important)等級的風險。
CVE-2020-0688HIGHunder attackransomware03 May 2021
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
Exploit-DB
Piwigo 11.3.0 - 'language' SQL
CVE-2021-27973webappsphp03 May 2021
SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
28RISK
open
GitHub PoC
Docker-compose to set up a test environment for exploiting CVE-2015-8562
CVE-2015-856203 May 2021
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-28482HIGH03 May 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
63RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2015-856203 May 2021
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack02 May 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
local
CVE-2021-1732HIGHunder attackransomware02 May 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2018-17463HIGHunder attack02 May 2021
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RISK
open
GitHub PoC
DXY0411/CVE-2020-23342
CVE-2020-2334202 May 2021
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
28RISK
open
GitHub PoC
Abdennour-py/CVE-2021-3493
CVE-2021-3493HIGHunder attack02 May 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC1
Completed a working exploit for CVE-2018-17463 for fun.
CVE-2018-17463HIGHunder attack02 May 2021
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RISK
open
GitHub PoC
CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow
CVE-2009-018201 May 2021
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RISK
open
GitHub PoC
CVE-2003-0264 SLMail5.5_RemoteBufferOverflow
CVE-2003-026401 May 2021
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-6340HIGHunder attack01 May 2021
Drupal core - Highly critical - Remote Code Execution
100RISK
open
GitHub PoC2
Confluence unauthorize template injection
CVE-2019-3396CRITICALunder attackransomware01 May 2021
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
previouspage 689 / 2,610next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.