Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,324 exploits
Exploit-DB
Tileserver-gl 3.0.0 - 'key' Reflected Cross-Site Scripting (XSS)
CVE-2020-15500webappsmultiple15 Apr 2021
An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected u
43RISK
open
Exploit-DB
CITSmart ITSM 9.1.2.22 - LDAP Injection
CVE-2020-35775webappsjava14 Apr 2021
CITSmart before 9.1.2.23 allows LDAP Injection.
28RISK
open
Exploit-DB
CITSmart ITSM 9.1.2.27 - 'query' Time-based Blind SQL Injection (Authenticated)
CVE-2021-28142webappsjava14 Apr 2021
CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."
23RISK
open
Exploit-DB
jQuery 1.0.3 - Cross-Site Scripting (XSS)
CVE-2020-11023MEDIUMunder attackwebappsmultiple14 Apr 2021
Potential XSS vulnerability in jQuery
85RISK
open
GitHub PoC176
[ProxyLogon] CVE-2021-26855 & CVE-2021-27065 Fixed RawIdentity Bug Exploit. [ProxyOracle] CVE-2021-31195 & CVE-2021-31196 Exploit Chains. [ProxyShell] CVE-2021-34473 & CVE-2021-34523 & CVE-2021-31207 Exploit Chains.
CVE-2021-26855CRITICALunder attackransomware14 Apr 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 - RCE
CVE-2021-29003webappshardware14 Apr 2021
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacter
35RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware14 Apr 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
haotiku/CVE-2021-26855-exploit-Exchange
CVE-2021-26855CRITICALunder attackransomware14 Apr 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack14 Apr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Exploit-DB
MariaDB 10.2 - 'wsrep_provider' OS Command Execution
CVE-2021-27928locallinux14 Apr 2021
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RISK
open
Exploit-DB
jQuery 1.2 - Cross-Site Scripting (XSS)
CVE-2020-11022MEDIUMwebappsmultiple14 Apr 2021
jQuery has a potential XSS vulnerability
55RISK
open
GitHub PoC
Malicious Payloads that abuses Win32k Elevation of Privilege Vulnerability (CVE-2021-28310)
CVE-2021-28310HIGHunder attack14 Apr 2021
Win32k Elevation of Privilege Vulnerability
71RISK
open
Metasploit600
GitLab Unauthenticated Remote ExifTool Command Injection
CVE-2021-22204MEDIUMunder attack14 Apr 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
Metasploit600
GitLab Unauthenticated Remote ExifTool Command Injection
CVE-2021-22205CRITICALunder attackransomware14 Apr 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
Metasploit300
Cockpit CMS NoSQLi to RCE
CVE-2020-3584613 Apr 2021
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
40RISK
open
Exploit-DB
ExpressVPN VPN Router 1.0 - Router Login Panel's Integer Overflow
CVE-2020-29238webappsmultiple13 Apr 2021
An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensi
28RISK
open
Metasploit0
Google Chrome versions before 89.0.4389.128 V8 XOR Typer Out-Of-Bounds Access RCE
CVE-2021-21220HIGHunder attack13 Apr 2021
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
100RISK
open
Metasploit300
Cockpit CMS NoSQLi to RCE
CVE-2020-3584713 Apr 2021
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
60RISK
open
GitHub PoC1
Auto exploit RCE CVE-2020-5902
CVE-2020-5902CRITICALunder attackransomware13 Apr 2021
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
GitHub PoC1
CVE-2020-17519 Cheetah
CVE-2020-17519CRITICALunder attack13 Apr 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack13 Apr 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-5902CRITICALunder attackransomware13 Apr 2021
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
Exploit-DBVexDay Proof
vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-2523remoteunix12 Apr 2021
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
VulnCheck XDB
initial-access
CVE-2003-020112 Apr 2021
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open
Metasploit500
2021 Ubuntu Overlayfs LPE
CVE-2021-3493HIGHunder attack12 Apr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC2
Samba exploit CVE2003-0201
CVE-2003-020112 Apr 2021
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open
GitHub PoC3
GitLab 11.4.7 RCE exploit with different reverse shells. CVE-2018-19571 + CVE-2018-19585
CVE-2018-1957111 Apr 2021
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RISK
open
GitHub PoC
CVE-2021-3129-Laravel Debug mode 远程代码执行漏洞
CVE-2021-3129CRITICALunder attackransomware11 Apr 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC3
VMWare-CVE-2021-21975 SSRF vulnerability
CVE-2021-21975HIGHunder attackransomware10 Apr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-21975HIGHunder attackransomware10 Apr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
previouspage 694 / 2,611next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.