Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
78,324 exploits
VulnCheck XDB
denial-of-service
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open ↗Exploit-DB
Microsoft Exchange 2019 - Server-Side Request Forgery (Proxylogon) (PoC)
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 60
PoC of proxylogon chain SSRF(CVE-2021-26855) to write file by testanull, censored by github
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗Exploit-DB
Microsoft Exchange 2019 - Server-Side Request Forgery (Proxylogon) (PoC)
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 111
proxylogon exploit - CVE-2021-26857
Microsoft Exchange Server Remote Code Execution Vulnerability
93RISK
open ↗GitHub PoC★ 5
Apache ActiveMQ Remote Code Execution Exploit
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open ↗GitHub PoC★ 5
CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1,077
Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-UltraVires/Redis-Unauthorized-RCE/TDOA-V11.7-GetOnlineCookie/VMware-vCenter-GetAnyFile/yongyou-GRP-U8-XXE/Oracle-WebLogic-CVE-2020-14883/Oracle-WebLogic-CVE-2020-14882/Apache-Solr-GetAnyFile/F5-BIG-IP-CVE-2021-22986/Sonicwall-SSL-VPN-RCE/GitLab-Graphql-CNVD-2021-14193/D-Link-DCS-CVE-2020-25078/WLAN-AP-WEA453e-RCE/360TianQing-Unauthorized/360TianQing-SQLinjection/FanWeiOA-V8-SQLinjection/QiZhiBaoLeiJi-AnyUserLogin/QiAnXin-WangKangFirewall-RCE/金山-V8-终端安全系统/NCCloud-SQLinjection/ShowDoc-RCE
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open ↗GitHub PoC★ 12
CVE-2021-26855, also known as Proxylogon, is a server-side request forgery (SSRF) vulnerability in Exchange that allows an attacker to send arbitrary HTTP requests and authenticate as the Exchange server.
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
93RISK
open ↗VulnCheck XDB
remote-with-credentials
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open ↗GitHub PoC★ 53
alt3kx/CVE-2021-26855_PoC
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗Metasploit600
F5 iControl REST Unauthenticated SSRF Token Generation RCE
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open ↗Exploit-DB
Atlassian JIRA 8.11.1 - User Enumeration
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
60RISK
open ↗GitHub PoC★ 1
oneoy/CVE-2021-1732-Exploit
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC★ 98
h4x0r-dz/CVE-2021-26855
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 17
PoC exploit code for CVE-2021-26855
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗Exploit-DB✓ VexDay Proof
Golden FTP Server 4.70 - 'PASS' Buffer Overflow (2)
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (
50RISK
open ↗GitHub PoC
This script test the CVE-2021-26855 vulnerability on Exchange Server.
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗Exploit-DB
Joomla JCK Editor 6.4.4 - 'parent' SQL Injection (2)
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
60RISK
open ↗GitHub PoC★ 164
A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin (CVE-2021-26855).
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.