Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,324 exploits
VulnCheck XDB
infoleak
CVE-2017-100017019 Mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RISK
open
GitHub PoC3
Zoho ManageEngine ServiceDesk Plus MSP - Active Directory User Enumeration (CVE-2021-31159) - https://ricardojoserf.github.io/CVE-2021-31159/
CVE-2021-3115919 Mar 2021
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-messag
28RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack19 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack19 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC4
Exploit generator for sudo CVE-2021-3156
CVE-2021-3156HIGHunder attack19 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALunder attackransomware19 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC27
Whatsapp remote code execution CVE-2019-11932 https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/
CVE-2019-1193219 Mar 2021
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware19 Mar 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC1
PoC Python script as an exercice from tryhackme.
CVE-2012-298218 Mar 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
VulnCheck XDB
initial-access
CVE-2019-1144718 Mar 2021
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
GitHub PoC
antichown/Scan-Vuln-CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware18 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack18 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALunder attackransomware18 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC9
CutePHP Cute News 2.1.2 RCE PoC
CVE-2019-1144718 Mar 2021
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack18 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
CVE-2019-20361HIGH18 Mar 2021
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b
78RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware17 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware17 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
VestaCP 0.9.8 - File Upload CSRF
CVE-2021-28379webappsmultiple17 Mar 2021
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allow
23RISK
open
GitHub PoC
Exploit Code for CVE-2019-11447 aka CuteNews 2.1.2 Avatar upload RCE (Authenticated)
CVE-2019-1144717 Mar 2021
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
GitHub PoC4
CVE-2021-26855 proxyLogon metasploit exploit script
CVE-2021-26855CRITICALunder attackransomware17 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC124
ProxyLogon(CVE-2021-26855+CVE-2021-27065) Exchange Server RCE(SSRF->GetWebShell)
CVE-2021-26855CRITICALunder attackransomware17 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-1144717 Mar 2021
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALunder attackransomware17 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-27065HIGHunder attackransomware17 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC51
This is a Poc for BIGIP iControl unauth RCE
CVE-2021-22986CRITICALunder attackransomware17 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
Metasploit600
rConfig Vendors Auth File Upload RCE
CVE-2022-44384HIGH17 Mar 2021
An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP fi
36RISK
open
GitHub PoC1
automate me!
CVE-2021-21973MEDIUMunder attack16 Mar 2021
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of UR
100RISK
open
GitHub PoC33
ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin. We have also chained this bug with another post-auth arbitrary-file-write vulnerability, CVE-2021-27065, to get code execution.
CVE-2021-26855CRITICALunder attackransomware16 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack16 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
previouspage 700 / 2,611next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.