Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,331cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
78,295 exploits
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack25 Apr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC
edsonjt81/CVE-2019-14287-
CVE-2019-1428725 Apr 2021
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
VulnCheck XDB
local
CVE-2021-1732HIGHunder attackransomware25 Apr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
edsonjt81/sudo-cve-2019-18634
CVE-2019-1863425 Apr 2021
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open
GitHub PoC1
rebuild cve
CVE-2021-329125 Apr 2021
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
28RISK
open
GitHub PoC31
Read my blog for more info -
CVE-2021-1732HIGHunder attackransomware25 Apr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC2
b1tg/CVE-2018-6065-exploit
CVE-2018-6065HIGHunder attack24 Apr 2021
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISK
open
VulnCheck XDB
client-side
CVE-2018-6065HIGHunder attack24 Apr 2021
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISK
open
VulnCheck XDB
local
CVE-2021-1732HIGHunder attackransomware23 Apr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC66
CVE-2021-1732 poc & exp; tested on 20H2
CVE-2021-1732HIGHunder attackransomware23 Apr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
Exploit-DB
DzzOffice 2.02.1 - 'Multiple' Cross-Site Scripting (XSS)
CVE-2021-3318webappsmultiple23 Apr 2021
attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.
23RISK
open
GitHub PoC3
POC exploit for CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware22 Apr 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC13
CVE-2021-22192
CVE-2021-22192CRITICAL22 Apr 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticat
53RISK
open
GitHub PoC3
oneoy/CVE-2021-3493
CVE-2021-3493HIGHunder attack22 Apr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-31327webappsphp22 Apr 2021
Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field.
23RISK
open
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-31329webappsphp22 Apr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php
23RISK
open
GitHub PoC
itssmikefm/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware22 Apr 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-30042webappsphp22 Apr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Cont
23RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware22 Apr 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC8
Automated tool to exploit sharepoint CVE-2019-0604
CVE-2019-0604CRITICALunder attackransomware22 Apr 2021
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack22 Apr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
initial-access
CVE-2019-0604CRITICALunder attackransomware22 Apr 2021
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISK
open
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-30034webappsphp22 Apr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php.
23RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack22 Apr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-30039webappsphp22 Apr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-repo
23RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware22 Apr 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
Exploit-DB
CMS Made Simple 2.2.15 - 'title' Cross-Site Scripting (XSS)
CVE-2021-28935webappsphp22 Apr 2021
CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > M
23RISK
open
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-30030webappsphp22 Apr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php.
23RISK
open
Metasploit300
Netgear R7000 backup.cgi Heap Overflow RCE
CVE-2021-3180221 Apr 2021
NETGEAR R7000 1.0.11.116 devices have a heap-based Buffer Overflow that is exploitable from the local network without au
23RISK
open
Exploit-DB
RemoteClinic 2 - 'Multiple' Cross-Site Scripting (XSS)
CVE-2021-30044webappsphp21 Apr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php.
23RISK
open
previouspage 691 / 2,610next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.