Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,324 exploits
GitHub PoC33
ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin. We have also chained this bug with another post-auth arbitrary-file-write vulnerability, CVE-2021-27065, to get code execution.
CVE-2021-26855CRITICALunder attackransomware16 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
automate me!
CVE-2021-21973MEDIUMunder attack16 Mar 2021
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of UR
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware16 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack16 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack15 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware15 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-26855CRITICALunder attackransomware15 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALunder attackransomware15 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Exploit-DBVexDay Proof
SonLogger 4.2.3.3 - Unauthenticated Arbitrary File Upload (Metasploit)
CVE-2021-27964webappsmultiple15 Mar 2021
SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Con
50RISK
open
VulnCheck XDB
initial-access
CVE-2021-27065HIGHunder attackransomware15 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC6
Mr-xn/CVE-2021-26855-d
CVE-2021-26855CRITICALunder attackransomware15 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC806
Sudo Baron Samedit Exploit
CVE-2021-3156HIGHunder attack15 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC4
patched to work
CVE-2021-26855CRITICALunder attackransomware15 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
Zenario CMS 8.8.53370 - 'id' Blind SQL Injection
CVE-2021-26830webappsphp15 Mar 2021
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin
23RISK
open
GitHub PoC28
CVE-2021-26855 & CVE-2021-27065
CVE-2021-26855CRITICALunder attackransomware15 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC9
RCE exploit for ProxyLogon vulnerability in Microsoft Exchange
CVE-2021-26855CRITICALunder attackransomware14 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC30
CVE-2021-26855: PoC (Not a HoneyPoC for once!)
CVE-2021-26855CRITICALunder attackransomware14 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC22
RCE exploit for Microsoft Exchange Server (CVE-2021-26855).
CVE-2021-26855CRITICALunder attackransomware14 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Exploit Samba
CVE-2007-244714 Mar 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware14 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware14 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware14 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
Microsoft Exchange 2019 - Server-Side Request Forgery
CVE-2021-26855CRITICALunder attackransomwareremotewindows14 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
vonderchild/CVE-2016-3088
CVE-2016-3088CRITICALunder attack12 Mar 2021
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC
Will write a python script for exploiting this vulnerability
CVE-2020-25213CRITICALunder attack12 Mar 2021
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-25213CRITICALunder attack12 Mar 2021
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
GitHub PoC3
Scanner and PoC for CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware12 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2016-3088CRITICALunder attack12 Mar 2021
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALunder attackransomware12 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALunder attackransomware12 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
previouspage 701 / 2,611next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.