Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,324 exploits
VulnCheck XDB
initial-access
CVE-2021-27065HIGHunder attackransomware24 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC52
Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.
CVE-2021-26855CRITICALunder attackransomware24 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC10
CVE-2017-0100、MS17-012、Eop
CVE-2017-010024 Mar 2021
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware24 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
CVE-2021-22986 Checker Script in Python3
CVE-2021-22986CRITICALunder attackransomware23 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALunder attackransomware23 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC
analytics ProxyLogo Mail exchange RCE
CVE-2021-26855CRITICALunder attackransomware23 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
MyBB 1.8.25 - Poll Vote Count SQL Injection
CVE-2021-27946webappsphp23 Mar 2021
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
23RISK
open
VulnCheck XDB
initial-access
CVE-2021-27065HIGHunder attackransomware23 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-2629523 Mar 2021
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
60RISK
open
Exploit-DBVexDay Proof
Codiad 2.8.4 - Remote Code Execution (Authenticated)
CVE-2018-14009webappsmultiple23 Mar 2021
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
35RISK
open
Exploit-DB
MyBB 1.8.25 - Chained Remote Command Execution
CVE-2021-27890webappsphp22 Mar 2021
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
28RISK
open
GitHub PoC
Bypass bludit mitigation login form and upload malicious to call a rev shell
CVE-2019-17240LOW22 Mar 2021
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
Exploit-DB
MyBB 1.8.25 - Chained Remote Command Execution
CVE-2021-27889webappsphp22 Mar 2021
Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.
23RISK
open
Exploit-DB
WordPress Plugin Delightful Downloads Jquery File Tree 1.6.6 - Path Traversal
CVE-2017-1000170webappsphp22 Mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RISK
open
GitHub PoC
F5 BIG-IP/BIG-IQ iControl Rest API SSRF to RCE
CVE-2021-22986CRITICALunder attackransomware22 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC
kiri-48/CVE-2021-22986
CVE-2021-22986CRITICALunder attackransomware22 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC91
CVE-2021-22986 & F5 BIG-IP RCE
CVE-2021-22986CRITICALunder attackransomware22 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALunder attackransomware22 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC18
EEsshq/CVE-2017-0144---EtneralBlue-MS17-010-Remote-Code-Execution
CVE-2017-0144HIGHunder attackransomware22 Mar 2021
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Metasploit600
Apache OFBiz SOAP Java Deserialization
CVE-2021-2629522 Mar 2021
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
60RISK
open
GitHub PoC
Microsoft Exchange Proxylogon Exploit Chain EXP分析
CVE-2021-26855CRITICALunder attackransomware21 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-26855CRITICALunder attackransomware21 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC4
CVE-2021-22986 F5 BIG-IP iControl 命令执行漏洞
CVE-2021-22986CRITICALunder attackransomware21 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALunder attackransomware21 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC
A vulnerability scanner that detects CVE-2021-22986 vulnerabilities.
CVE-2021-22986CRITICALunder attackransomware20 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC1
Exploiting CVE-2016-2555 enumerating and dumping the underlying Database.
CVE-2016-255520 Mar 2021
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISK
open
GitHub PoC4
Jquery File Tree 1.6.6 Path Traversal exploit (CVE-2017-1000170)
CVE-2017-100017019 Mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RISK
open
Exploit-DB
LiveZilla Server 8.0.1.0 - 'Accept-Language' Reflected XSS
CVE-2019-12962webappsphp19 Mar 2021
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
38RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack19 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
previouspage 699 / 2,611next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.