Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,324 exploits
GitHub PoC2
CVE-2021-3317
CVE-2021-331709 Apr 2021
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of
35RISK
open
VulnCheck XDB
initial-access
CVE-2021-21402HIGH09 Apr 2021
Unauthenticated Arbitrary File Access in Jellyfin
78RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack09 Apr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Exploit-DB
PrestaShop 1.7.6.7 - 'location' Blind Sql Injection
CVE-2020-15160webappsphp09 Apr 2021
Blind SQL Injection in PrestaShop
28RISK
open
GitHub PoC
An exploit to get root in vsftpd 2.3.4 (CVE-2011-2523) written in python
CVE-2011-252309 Apr 2021
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALunder attack09 Apr 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
GitHub PoC5
CVE-2020-35729
CVE-2020-3572909 Apr 2021
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RISK
open
GitHub PoC1
CVE-2020–7961 Mass exploit for Script Kiddies
CVE-2020-7961CRITICALunder attack09 Apr 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
GitHub PoC
Buffer Overflow in Seattle Lab Mail (SLmail) 5.5 - POP3
CVE-2003-026408 Apr 2021
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISK
open
Exploit-DB
Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution
CVE-2020-12351remotelinux08 Apr 2021
Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a
23RISK
open
VulnCheck XDB
client-side
CVE-2020-1938CRITICALunder attack08 Apr 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
Exploit-DB
Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution
CVE-2020-12352remotelinux08 Apr 2021
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adja
23RISK
open
Exploit-DB
DMA Radius Manager 4.4.0 - Cross-Site Request Forgery (CSRF)
CVE-2021-30147webappsmultiple08 Apr 2021
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
23RISK
open
Exploit-DB
Composr 10.0.36 - Remote Code Execution
CVE-2021-30149webappsphp08 Apr 2021
Composr 10.0.36 allows upload and execution of PHP files.
28RISK
open
Exploit-DB
Composr CMS 10.0.36 - Cross Site Scripting
CVE-2021-30150webappsphp07 Apr 2021
Composr 10.0.36 allows XSS in an XML script.
23RISK
open
Metasploit600
Cisco Small Business RV Series Authentication Bypass and Command Injection
CVE-2021-1472MEDIUM07 Apr 2021
Cisco Small Business RV Series Routers Vulnerabilities
50RISK
open
Metasploit600
Cisco Small Business RV Series Authentication Bypass and Command Injection
CVE-2021-1473MEDIUM07 Apr 2021
Cisco Small Business RV Series Routers Vulnerabilities
40RISK
open
Exploit-DB
Dell OpenManage Server Administrator 9.4.0.0 - Arbitrary File Read
CVE-2020-5377CRITICALwebappswindows07 Apr 2021
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RISK
open
Exploit-DB
Atlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSS
CVE-2020-14166webappsmultiple07 Apr 2021
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remo
23RISK
open
GitHub PoC
CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
CVE-2016-209807 Apr 2021
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISK
open
GitHub PoC1
Exploit Code for CVE-2020-1472 aka Zerologon
CVE-2020-1472MEDIUMunder attackransomware06 Apr 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware06 Apr 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALunder attackransomware06 Apr 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21975HIGHunder attackransomware06 Apr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware06 Apr 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
Exploit-DB
Google Chrome 86.0.4240 V8 - Remote Code Execution
CVE-2020-16040remotemultiple06 Apr 2021
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RISK
open
GitHub PoC6
[CVE-2021-21972] VMware vSphere Client Unauthorized File Upload to Remote Code Execution (RCE)
CVE-2021-21972CRITICALunder attackransomware06 Apr 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC
Exploit for CVE-2012-2982
CVE-2012-298206 Apr 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
Exploit-DB
Google Chrome 81.0.4044 V8 - Remote Code Execution
CVE-2020-6507remotemultiple06 Apr 2021
Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap
28RISK
open
GitHub PoC37
vRealize RCE + Privesc (CVE-2021-21975, CVE-2021-21983, CVE-0DAY-?????)
CVE-2021-21975HIGHunder attackransomware06 Apr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
previouspage 695 / 2,611next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.