Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,324 exploits
GitHub PoC2
FunPhishing/Laravel-8.4.2-rce-CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware14 Feb 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC3
OpenSSL Heartbleed Bug CVE-2014-0160 Toolkit. Built with ❤ by Christopher Ngo.
CVE-2014-0160HIGHunder attack14 Feb 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware14 Feb 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-7247CRITICALunder attack13 Feb 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
GitHub PoC4
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker.
CVE-2021-21014CRITICAL13 Feb 2021
Magento Commerce Arbitrary Folder Empty Could Lead To Arbitrary Code Execution
48RISK
open
VulnCheck XDB
initial-access
CVE-2021-2564613 Feb 2021
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RISK
open
GitHub PoC11
OpenSMTPD 6.4.0 - 6.6.1 Remote Code Execution PoC exploit
CVE-2020-7247CRITICALunder attack13 Feb 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
Metasploit600
Nagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code Exection
CVE-2021-25298HIGHunder attack13 Feb 2021
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RISK
open
Metasploit600
Nagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code Exection
CVE-2021-25297HIGHunder attack13 Feb 2021
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
98RISK
open
Metasploit600
Nagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code Exection
CVE-2021-25296HIGHunder attack13 Feb 2021
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RISK
open
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM12 Feb 2021
Cross site scripting
70RISK
open
GitHub PoC8
Test for CVE-2000-0649, and return an IP address if vulnerable
CVE-2000-064911 Feb 2021
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RISK
open
Exploit-DB
Node.JS - 'node-serialize' Remote Code Execution (2)
CVE-2017-5941webappsnodejs10 Feb 2021
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISK
open
GitHub PoC40
synacktiv/CVE-2021-1782
CVE-2021-1782HIGHunder attack10 Feb 2021
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-00
71RISK
open
VulnCheck XDB
local
CVE-2021-1782HIGHunder attack10 Feb 2021
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-00
71RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack10 Feb 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack09 Feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Metasploit600
Micro Focus Operations Bridge Reporter Unauthenticated Command Injection
CVE-2021-22502CRITICALunder attack09 Feb 2021
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The
100RISK
open
Metasploit600
Advantech iView Unauthenticated Remote Code Execution
CVE-2021-2265209 Feb 2021
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow a
30RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack09 Feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Metasploit200
Win32k ConsoleControl Offset Confusion
CVE-2021-1732HIGHunder attackransomware09 Feb 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC16
sudo heap overflow to LPE, in Go
CVE-2021-3156HIGHunder attack09 Feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
보안취약점 확인
CVE-2021-3156HIGHunder attack09 Feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC205
CVE-2021-3156非交互式执行命令
CVE-2021-3156HIGHunder attack09 Feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Exploit-DB
Adobe Connect 10 - Username Disclosure
CVE-2023-22232MEDIUMwebappsmultiple09 Feb 2021
Adobe Connect Improper Access Control Security feature bypass
70RISK
open
Metasploit200
Win32k ConsoleControl Offset Confusion
CVE-2022-21882HIGHunder attackransomware09 Feb 2021
Win32k Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC51
CVE-2021-3156: Sudo heap overflow exploit for Debian 10
CVE-2021-3156HIGHunder attack08 Feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Exploit-DB
Alt-N MDaemon webmail 20.0.0 - 'Contact name' Stored Cross Site Scripting (XSS)
CVE-2020-18724webappswindows08 Feb 2021
Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19
23RISK
open
Exploit-DB
Alt-N MDaemon webmail 20.0.0 - 'file name' Stored Cross Site Scripting (XSS)
CVE-2020-18723webappswindows08 Feb 2021
Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code
23RISK
open
Metasploit600
NetMotion Mobility Server MvcUtil Java Deserialization
CVE-2021-2691408 Feb 2021
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code
40RISK
open
previouspage 707 / 2,611next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.