Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
78,329 exploits
GitHub PoC5
cve-2021-3156;sudo堆溢出漏洞;漏洞检测
CVE-2021-3156HIGHunder attack28 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC18
1day research effort
CVE-2021-3156HIGHunder attack28 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC2
👻CVE-2017-16995
CVE-2017-1699528 Jan 2021
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
GitHub PoC18
crisprss/Laravel_CVE-2021-3129_EXP
CVE-2021-3129CRITICALunder attackransomware27 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC112
CVE-2021-3156
CVE-2021-3156HIGHunder attack27 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC3
This simple bash script will patch the recently discovered sudo heap overflow vulnerability.
CVE-2021-3156HIGHunder attack27 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
CVE-2021-3156
CVE-2021-3156HIGHunder attack27 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC1
unauth401/CVE-2021-3156
CVE-2021-3156HIGHunder attack27 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
nexcess/sudo_cve-2021-3156
CVE-2021-3156HIGHunder attack27 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC69
Exploit for CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware27 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC79
WebLogic T3/IIOP RCE ExternalizableHelper.class of coherence.jar
CVE-2020-14756CRITICAL27 Jan 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versio
70RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware27 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14756CRITICAL27 Jan 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versio
70RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware27 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
Exploit-DB
Oracle WebLogic Server 12.2.1.0 - RCE (Unauthenticated)
CVE-2020-14882CRITICALunder attackwebappsjava26 Jan 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC35
mr-r3b00t/CVE-2021-3156
CVE-2021-3156HIGHunder attack26 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC2
CVE-2021-3441 CVE Check is a python script to search targets for indicators of compromise to CVE-2021-3441
CVE-2021-344126 Jan 2021
A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross
23RISK
open
Metasploit600
Sudo Heap-Based Buffer Overflow
CVE-2021-3156HIGHunder attack26 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Exploit-DB
Tenda AC5 AC1200 Wireless - 'WiFi Name & Password' Stored Cross Site Scripting
CVE-2021-3186webappshardware26 Jan 2021
A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_m
23RISK
open
GitHub PoC
Quick and dirty bruteforcer for CVE-2018-7669 (Directory Traversal Vulnerability in Sitecore)
CVE-2018-766925 Jan 2021
An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application
28RISK
open
GitHub PoC6
SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.
CVE-2017-11882HIGHunder attackransomware25 Jan 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC78
SecPros-Team/laravel-CVE-2021-3129-EXP
CVE-2021-3129CRITICALunder attackransomware25 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware25 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware25 Jan 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
Exploit-DBVexDay Proof
Klog Server 2.4.1 - Unauthenticated Command Injection (Metasploit)
CVE-2020-35729webappsphp25 Jan 2021
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RISK
open
GitHub PoC5
用于对WebLogic(10.3.6.0.0 ;12.1.3.0.0 ;12.2.1.3.0; 12.2.1.4.0 ;14.1.1.0.0)进行验证及利用
CVE-2020-14883HIGHunder attack25 Jan 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
killmonday/CVE-2020-17530-s2-061
CVE-2020-17530CRITICALunder attack24 Jan 2021
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack24 Jan 2021
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
client-side
CVE-2020-820924 Jan 2021
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix Xe
50RISK
open
GitHub PoC6
CVE-2020-8597 in RM2100
CVE-2020-8597CRITICAL24 Jan 2021
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RISK
open
previouspage 711 / 2,611next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.