Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,324 exploits
GitHub PoC3
A repository hosting write ups for the 0 days CVE-2021-25679, CVE-2021-25680, and CVE-2021-25681
CVE-2021-2567903 Mar 2021
The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. T
23RISK
open
GitHub PoC
d3sh1n/cve-2021-21972
CVE-2021-21972CRITICALunder attackransomware03 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, City
CVE-2020-2527003 Mar 2021
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, o
23RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware03 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
Exploit-DBVexDay Proof
AnyDesk 5.5.2 - Remote Code Execution
CVE-2020-13160remotelinux03 Mar 2021
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execut
60RISK
open
GitHub PoC22
A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865
CVE-2021-26855CRITICALunder attackransomware03 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
Tiny Tiny RSS - Remote Code Execution
CVE-2020-25787webappsphp02 Mar 2021
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting
28RISK
open
Metasploit300
Microsoft Exchange ProxyLogon Collector
CVE-2021-26855CRITICALunder attackransomware02 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Metasploit300
Microsoft Exchange ProxyLogon Scanner
CVE-2021-26855CRITICALunder attackransomware02 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Metasploit600
Microsoft Exchange ProxyLogon RCE
CVE-2021-27065HIGHunder attackransomware02 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Metasploit600
Microsoft Exchange ProxyLogon RCE
CVE-2021-26855CRITICALunder attackransomware02 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Metasploit600
VMware View Planner Unauthenticated Log File Upload RCE
CVE-2021-2197802 Mar 2021
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input val
60RISK
open
Exploit-DBVexDay Proof
Zen Cart 1.5.7b - Remote Code Execution (Authenticated)
CVE-2021-3291webappsphp02 Mar 2021
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
28RISK
open
Metasploit600
Veritas Backup Exec Agent Remote Code Execution
CVE-2021-27878HIGHunder attackransomware01 Mar 2021
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc
91RISK
open
Metasploit600
Veritas Backup Exec Agent Remote Code Execution
CVE-2021-27877HIGHunder attackransomware01 Mar 2021
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authenticat
98RISK
open
Metasploit600
Veritas Backup Exec Agent Remote Code Execution
CVE-2021-27876HIGHunder attackransomware01 Mar 2021
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc
91RISK
open
Exploit-DB
VMware vCenter Server 7.0 - Unauthenticated File Upload
CVE-2021-21972CRITICALunder attackransomwarewebappsmultiple01 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC2
CVE-2020-12351
CVE-2020-1235101 Mar 2021
Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a
23RISK
open
GitHub PoC1
andyfeili/-CVE-2019-7214
CVE-2019-721401 Mar 2021
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RISK
open
GitHub PoC11
漏洞利用,Vmware vCenter 6.5-7.0 RCE(CVE-2021-21972),上传冰蝎3,getshell
CVE-2021-21972CRITICALunder attackransomware01 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC160
CVE 2021-21315 PoC
CVE-2021-21315HIGHunder attack01 Mar 2021
Command Injection Vulnerability
100RISK
open
Exploit-DBVexDay Proof
FortiLogger 4.4.2.2 - Unauthenticated Arbitrary File Upload (Metasploit)
CVE-2021-3378webappsmultiple01 Mar 2021
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-21315HIGHunder attack01 Mar 2021
Command Injection Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware01 Mar 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware01 Mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC1
Modified the test PoC from Secura, CVE-2020-1472, to change the machine password to null
CVE-2020-1472MEDIUMunder attackransomware01 Mar 2021
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware28 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-21972CRITICALunder attackransomware27 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware27 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware27 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
previouspage 704 / 2,611next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.