Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
78,324 exploits
GitHub PoC★ 3
A repository hosting write ups for the 0 days CVE-2021-25679, CVE-2021-25680, and CVE-2021-25681
The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. T
23RISK
open ↗GitHub PoC
d3sh1n/cve-2021-21972
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open ↗GitHub PoC
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, City
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, o
23RISK
open ↗VulnCheck XDB
initial-access
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open ↗Exploit-DB✓ VexDay Proof
AnyDesk 5.5.2 - Remote Code Execution
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execut
60RISK
open ↗GitHub PoC★ 22
A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗Exploit-DB
Tiny Tiny RSS - Remote Code Execution
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting
28RISK
open ↗Metasploit300
Microsoft Exchange ProxyLogon Collector
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗Metasploit300
Microsoft Exchange ProxyLogon Scanner
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗Metasploit600
Microsoft Exchange ProxyLogon RCE
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗Metasploit600
Microsoft Exchange ProxyLogon RCE
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗Metasploit600
VMware View Planner Unauthenticated Log File Upload RCE
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input val
60RISK
open ↗Exploit-DB✓ VexDay Proof
Zen Cart 1.5.7b - Remote Code Execution (Authenticated)
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
28RISK
open ↗Metasploit600
Veritas Backup Exec Agent Remote Code Execution
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc
91RISK
open ↗Metasploit600
Veritas Backup Exec Agent Remote Code Execution
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authenticat
98RISK
open ↗Metasploit600
Veritas Backup Exec Agent Remote Code Execution
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc
91RISK
open ↗Exploit-DB
VMware vCenter Server 7.0 - Unauthenticated File Upload
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open ↗GitHub PoC★ 2
CVE-2020-12351
Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a
23RISK
open ↗GitHub PoC★ 1
andyfeili/-CVE-2019-7214
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RISK
open ↗GitHub PoC★ 11
漏洞利用,Vmware vCenter 6.5-7.0 RCE(CVE-2021-21972),上传冰蝎3,getshell
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open ↗Exploit-DB✓ VexDay Proof
FortiLogger 4.4.2.2 - Unauthenticated Arbitrary File Upload (Metasploit)
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RISK
open ↗VulnCheck XDB
initial-access
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open ↗GitHub PoC★ 1
Modified the test PoC from Secura, CVE-2020-1472, to change the machine password to null
Netlogon Elevation of Privilege Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open ↗VulnCheck XDB
infoleak
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open ↗VulnCheck XDB
initial-access
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open ↗VulnCheck XDB
initial-access
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.