Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
78,958 exploits
Exploit-DB
Metasploit Framework 6.0.11 - msfvenom APK template command injection
CVE-2020-7384HIGHlocalmultiple28 Jan 2021
Client-Side Command Injection in Rapid7 Metasploit
68RISK
open
GitHub PoC3
CVE-2021-3156
CVE-2021-3156HIGHunder attack28 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Exploit-DB
CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
CVE-2020-25557webappsphp28 Jan 2021
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. A
23RISK
open
VulnCheck XDB
initial-access
CVE-2020-14756CRITICAL27 Jan 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versio
70RISK
open
GitHub PoC18
crisprss/Laravel_CVE-2021-3129_EXP
CVE-2021-3129CRITICALunder attackransomware27 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
CVE-2021-3156
CVE-2021-3156HIGHunder attack27 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC79
WebLogic T3/IIOP RCE ExternalizableHelper.class of coherence.jar
CVE-2020-14756CRITICAL27 Jan 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versio
70RISK
open
GitHub PoC
nexcess/sudo_cve-2021-3156
CVE-2021-3156HIGHunder attack27 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC112
CVE-2021-3156
CVE-2021-3156HIGHunder attack27 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC1
unauth401/CVE-2021-3156
CVE-2021-3156HIGHunder attack27 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC3
This simple bash script will patch the recently discovered sudo heap overflow vulnerability.
CVE-2021-3156HIGHunder attack27 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC69
Exploit for CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware27 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware27 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware27 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC35
mr-r3b00t/CVE-2021-3156
CVE-2021-3156HIGHunder attack26 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC2
CVE-2021-3441 CVE Check is a python script to search targets for indicators of compromise to CVE-2021-3441
CVE-2021-344126 Jan 2021
A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross
23RISK
open
Exploit-DB
Oracle WebLogic Server 12.2.1.0 - RCE (Unauthenticated)
CVE-2020-14882CRITICALunder attackwebappsjava26 Jan 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Metasploit600
Sudo Heap-Based Buffer Overflow
CVE-2021-3156HIGHunder attack26 Jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
Exploit-DB
Tenda AC5 AC1200 Wireless - 'WiFi Name & Password' Stored Cross Site Scripting
CVE-2021-3186webappshardware26 Jan 2021
A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_m
23RISK
open
GitHub PoC78
SecPros-Team/laravel-CVE-2021-3129-EXP
CVE-2021-3129CRITICALunder attackransomware25 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware25 Jan 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC5
用于对WebLogic(10.3.6.0.0 ;12.1.3.0.0 ;12.2.1.3.0; 12.2.1.4.0 ;14.1.1.0.0)进行验证及利用
CVE-2020-14883HIGHunder attack25 Jan 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
Quick and dirty bruteforcer for CVE-2018-7669 (Directory Traversal Vulnerability in Sitecore)
CVE-2018-766925 Jan 2021
An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application
28RISK
open
GitHub PoC6
SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.
CVE-2017-11882HIGHunder attackransomware25 Jan 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware25 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
Exploit-DBVexDay Proof
Klog Server 2.4.1 - Unauthenticated Command Injection (Metasploit)
CVE-2020-35729webappsphp25 Jan 2021
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALunder attack24 Jan 2021
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-17144HIGHunder attack24 Jan 2021
Microsoft Exchange Remote Code Execution Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2020-17144HIGHunder attack24 Jan 2021
Microsoft Exchange Remote Code Execution Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALunder attack24 Jan 2021
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
previouspage 728 / 2,632next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.