Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
8,213 exploits
VulnCheck XDB
initial-access
CVE-2023-34362CRITICALunder attackransomware09 Jul 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open
VulnCheck XDB
client-side
CVE-2023-346009 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-32315HIGHunder attack07 Jul 2023
Openfire administration console authentication bypass
100RISK
open
VulnCheck XDB
client-side
CVE-2023-346007 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
VulnCheck XDB
client-side
CVE-2023-2982CRITICAL07 Jul 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack06 Jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM06 Jul 2023
Cross site scripting
70RISK
open
VulnCheck XDB
initial-access
CVE-2023-346005 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack05 Jul 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL05 Jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM04 Jul 2023
Cross site scripting
70RISK
open
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALunder attack04 Jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-3710CRITICAL03 Jul 2023
Printer web page invalid command execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2023-2834303 Jul 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL03 Jul 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-3496003 Jul 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware03 Jul 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-32315HIGHunder attack02 Jul 2023
Openfire administration console authentication bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack01 Jul 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM01 Jul 2023
Cross site scripting
70RISK
open
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM01 Jul 2023
Cross site scripting
70RISK
open
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL01 Jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-2982CRITICAL30 Jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISK
open
VulnCheck XDB
local
CVE-2020-104830 Jun 2023
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writin
43RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware29 Jun 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-2982CRITICAL29 Jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISK
open
VulnCheck XDB
infoleak
CVE-2021-42013CRITICALunder attackransomware29 Jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
local
CVE-2023-0386HIGHunder attack28 Jun 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
VulnCheck XDB
initial-access
CVE-2023-2625828 Jun 2023
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashSe
50RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-287728 Jun 2023
Formidable Forms < 6.3.1 - Subscriber+ Remote Code Execution
28RISK
open
previouspage 159 / 274next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.