Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,324 exploits
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware11 Mar 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
Exploit-DB
Microsoft Exchange 2019 - Server-Side Request Forgery (Proxylogon) (PoC)
CVE-2021-27065HIGHunder attackransomwarewebappswindows11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC60
PoC of proxylogon chain SSRF(CVE-2021-26855) to write file by testanull, censored by github
CVE-2021-26855CRITICALunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
Microsoft Exchange 2019 - Server-Side Request Forgery (Proxylogon) (PoC)
CVE-2021-26855CRITICALunder attackransomwarewebappswindows11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC111
proxylogon exploit - CVE-2021-26857
CVE-2021-26857HIGHunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
93RISK
open
GitHub PoC5
Apache ActiveMQ Remote Code Execution Exploit
CVE-2016-3088CRITICALunder attack11 Mar 2021
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC5
CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065
CVE-2021-26855CRITICALunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1,077
Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-UltraVires/Redis-Unauthorized-RCE/TDOA-V11.7-GetOnlineCookie/VMware-vCenter-GetAnyFile/yongyou-GRP-U8-XXE/Oracle-WebLogic-CVE-2020-14883/Oracle-WebLogic-CVE-2020-14882/Apache-Solr-GetAnyFile/F5-BIG-IP-CVE-2021-22986/Sonicwall-SSL-VPN-RCE/GitLab-Graphql-CNVD-2021-14193/D-Link-DCS-CVE-2020-25078/WLAN-AP-WEA453e-RCE/360TianQing-Unauthorized/360TianQing-SQLinjection/FanWeiOA-V8-SQLinjection/QiZhiBaoLeiJi-AnyUserLogin/QiAnXin-WangKangFirewall-RCE/金山-V8-终端安全系统/NCCloud-SQLinjection/ShowDoc-RCE
CVE-2020-14883HIGHunder attack11 Mar 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC12
CVE-2021-26855, also known as Proxylogon, is a server-side request forgery (SSRF) vulnerability in Exchange that allows an attacker to send arbitrary HTTP requests and authenticate as the Exchange server.
CVE-2021-26855CRITICALunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26857HIGHunder attackransomware11 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2016-3088CRITICALunder attack11 Mar 2021
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC53
alt3kx/CVE-2021-26855_PoC
CVE-2021-26855CRITICALunder attackransomware10 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALunder attackransomware10 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Metasploit600
F5 iControl REST Unauthenticated SSRF Token Generation RCE
CVE-2021-22986CRITICALunder attackransomware10 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
Exploit-DB
Atlassian JIRA 8.11.1 - User Enumeration
CVE-2020-14181webappsmultiple10 Mar 2021
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
60RISK
open
GitHub PoC1
oneoy/CVE-2021-1732-Exploit
CVE-2021-1732HIGHunder attackransomware09 Mar 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC98
h4x0r-dz/CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware09 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC17
PoC exploit code for CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware09 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALunder attackransomware09 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Exploit-DBVexDay Proof
Golden FTP Server 4.70 - 'PASS' Buffer Overflow (2)
CVE-2006-6576remotewindows09 Mar 2021
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (
50RISK
open
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALunder attackransomware09 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALunder attackransomware09 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
This script test the CVE-2021-26855 vulnerability on Exchange Server.
CVE-2021-26855CRITICALunder attackransomware09 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065
CVE-2021-26855CRITICALunder attackransomware09 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
Joomla JCK Editor 6.4.4 - 'parent' SQL Injection (2)
CVE-2018-17254webappsphp08 Mar 2021
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
60RISK
open
GitHub PoC164
A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin (CVE-2021-26855).
CVE-2021-26855CRITICALunder attackransomware08 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALunder attackransomware08 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
previouspage 702 / 2,611next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.