Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,324 exploits
VulnCheck XDB
infoleak
CVE-2021-21972CRITICALunder attackransomware27 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC
JMousqueton/Detect-CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware27 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC1
VMware vCenter CVE-2021-21972 Tools
CVE-2021-21972CRITICALunder attackransomware27 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC
CVE-2015-3224
CVE-2015-322427 Feb 2021
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RISK
open
GitHub PoC29
Nmap script to check vulnerability CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware26 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC44
ZeusBox/CVE-2021-21017
CVE-2021-21017HIGHunder attack26 Feb 2021
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
93RISK
open
VulnCheck XDB
infoleak
CVE-2021-21972CRITICALunder attackransomware26 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
Metasploit300
FortiLogger Arbitrary File Upload Exploit
CVE-2021-337826 Feb 2021
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RISK
open
Metasploit300
Wifi Mouse RCE
CVE-2022-321825 Feb 2021
Necta WiFi Mouse (Mouse Server) client-side authentication bypass
40RISK
open
Metasploit600
IGEL OS Secure VNC/Terminal Command Injection RCE
CVE-2025-34082CRITICAL25 Feb 2021
IGEL OS Secure Terminal and Secure Shadow Remote Code Execution
63RISK
open
Metasploit300
Unified Remote Auth Bypass to RCE
CVE-2022-3229CRITICAL25 Feb 2021
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication
55RISK
open
Metasploit600
SaltStack Salt API Unauthenticated RCE through wheel_async client
CVE-2021-2528225 Feb 2021
An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable
40RISK
open
Metasploit600
SaltStack Salt API Unauthenticated RCE through wheel_async client
CVE-2021-2528125 Feb 2021
An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel
40RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack25 Feb 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
A vulnerability scanner that detects CVE-2020-14883 vulnerabilities.
CVE-2020-14883HIGHunder attack25 Feb 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC2
CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC15
Nibbleblog 4.0.3 - Arbitrary File Upload (CVE-2015-6967)
CVE-2015-696725 Feb 2021
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RISK
open
GitHub PoC11
VMware vCenter Server远程代码执行漏洞 (CVE-2021-21972)批量检测脚本
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC1
A vulnerability scanner that detects CVE-2021-21972 vulnerabilities.
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC54
alt3kx/CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC33
CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC27
VMware vCenter 未授权RCE(CVE-2021-21972)
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC1
L-pin/CVE-2021-21972
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC8
CVE-2020-14882
CVE-2020-14882CRITICALunder attack25 Feb 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
A vulnerability scanner that detects CVE-2020-17519 vulnerabilities.
CVE-2020-17519CRITICALunder attack25 Feb 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-21972CRITICALunder attackransomware25 Feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
previouspage 705 / 2,611next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.