Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
78,324 exploits
GitHub PoC★ 33
ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin. We have also chained this bug with another post-auth arbitrary-file-write vulnerability, CVE-2021-27065, to get code execution.
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
automate me!
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of UR
100RISK
open ↗VulnCheck XDB
initial-access
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open ↗VulnCheck XDB
local
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open ↗VulnCheck XDB
local
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
remote-with-credentials
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗Exploit-DB✓ VexDay Proof
SonLogger 4.2.3.3 - Unauthenticated Arbitrary File Upload (Metasploit)
SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Con
50RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 6
Mr-xn/CVE-2021-26855-d
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 806
Sudo Baron Samedit Exploit
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open ↗GitHub PoC★ 4
patched to work
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗Exploit-DB
Zenario CMS 8.8.53370 - 'id' Blind SQL Injection
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin
23RISK
open ↗GitHub PoC★ 28
CVE-2021-26855 & CVE-2021-27065
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 9
RCE exploit for ProxyLogon vulnerability in Microsoft Exchange
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 30
CVE-2021-26855: PoC (Not a HoneyPoC for once!)
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 22
RCE exploit for Microsoft Exchange Server (CVE-2021-26855).
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
Exploit Samba
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗Exploit-DB
Microsoft Exchange 2019 - Server-Side Request Forgery
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
vonderchild/CVE-2016-3088
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open ↗GitHub PoC
Will write a python script for exploiting this vulnerability
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open ↗VulnCheck XDB
initial-access
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open ↗GitHub PoC★ 3
Scanner and PoC for CVE-2021-26855
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
remote-with-credentials
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.