Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
78,958 exploits
GitHub PoC
A vulnerability scanner that detects CVE-2021-22986 vulnerabilities.
CVE-2021-22986CRITICALunder attackransomware20 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC1
Exploiting CVE-2016-2555 enumerating and dumping the underlying Database.
CVE-2016-255520 Mar 2021
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware19 Mar 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC26
cve-2021-22986 f5 rce 漏洞批量检测 poc
CVE-2021-22986CRITICALunder attackransomware19 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC3
Zoho ManageEngine ServiceDesk Plus MSP - Active Directory User Enumeration (CVE-2021-31159) - https://ricardojoserf.github.io/CVE-2021-31159/
CVE-2021-3115919 Mar 2021
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-messag
28RISK
open
VulnCheck XDB
infoleak
CVE-2017-100017019 Mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RISK
open
GitHub PoC4
Exploit generator for sudo CVE-2021-3156
CVE-2021-3156HIGHunder attack19 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC4
Jquery File Tree 1.6.6 Path Traversal exploit (CVE-2017-1000170)
CVE-2017-100017019 Mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack19 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack19 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Exploit-DB
LiveZilla Server 8.0.1.0 - 'Accept-Language' Reflected XSS
CVE-2019-12962webappsphp19 Mar 2021
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
38RISK
open
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALunder attackransomware19 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
GitHub PoC28
Whatsapp remote code execution CVE-2019-11932 https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/
CVE-2019-1193219 Mar 2021
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack18 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack18 Mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALunder attackransomware18 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
PoC Python script as an exercice from tryhackme.
CVE-2012-298218 Mar 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
VulnCheck XDB
initial-access
CVE-2019-1144718 Mar 2021
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
GitHub PoC
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
CVE-2019-20361HIGH18 Mar 2021
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b
78RISK
open
GitHub PoC
antichown/Scan-Vuln-CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware18 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC9
CutePHP Cute News 2.1.2 RCE PoC
CVE-2019-1144718 Mar 2021
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
Exploit-DB
VestaCP 0.9.8 - File Upload CSRF
CVE-2021-28379webappsmultiple17 Mar 2021
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allow
23RISK
open
GitHub PoC4
CVE-2021-26855 proxyLogon metasploit exploit script
CVE-2021-26855CRITICALunder attackransomware17 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Exploit Code for CVE-2019-11447 aka CuteNews 2.1.2 Avatar upload RCE (Authenticated)
CVE-2019-1144717 Mar 2021
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
GitHub PoC124
ProxyLogon(CVE-2021-26855+CVE-2021-27065) Exchange Server RCE(SSRF->GetWebShell)
CVE-2021-26855CRITICALunder attackransomware17 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-27065HIGHunder attackransomware17 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALunder attackransomware17 Mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
Metasploit600
rConfig Vendors Auth File Upload RCE
CVE-2022-44384HIGH17 Mar 2021
An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP fi
36RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware17 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware17 Mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
previouspage 717 / 2,632next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.