Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Intern Record System v1.0 - SQL Injection (Unauthenticated)
CVE-2022-40347CRITICALwebappsphp06 Apr 2023
SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType
48RISK
open
Exploit-DBVexDay Proof
Best pos Management System v1.0 - Remote Code Execution (RCE) on File Upload
CVE-2023-0943MEDIUMwebappsphp06 Apr 2023
SourceCodester Best POS Management System Image save_settings unrestricted upload
33RISK
open
Exploit-DBVexDay Proof
Employee Task Management System v1.0 - SQL Injection on (task-details.php?task_id=?)
CVE-2023-0904MEDIUMwebappsphp06 Apr 2023
SourceCodester Employee Task Management System task-details.php sql injection
33RISK
open
Exploit-DBVexDay Proof
Art Gallery Management System Project in PHP v 1.0 - SQL injection
CVE-2023-23156webappsphp06 Apr 2023
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid par
23RISK
open
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - SQL Injection on page Master.php
CVE-2023-0962MEDIUMwebappsphp06 Apr 2023
SourceCodester Music Gallery Site GET Request Master.php sql injection
33RISK
open
Exploit-DBVexDay Proof
Auto Dealer Management System v1.0 - SQL Injection in sell_vehicle.php
CVE-2023-0913MEDIUMwebappsphp06 Apr 2023
SourceCodester Auto Dealer Management System sql injection
33RISK
open
Exploit-DBVexDay Proof
Employee Task Management System v1.0 - SQL Injection on edit-task.php
CVE-2023-0902LOWwebappsphp06 Apr 2023
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISK
open
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - SQL Injection on music_list.php
CVE-2023-0938MEDIUMwebappsphp06 Apr 2023
SourceCodester Music Gallery Site GET Request music_list.php sql injection
33RISK
open
Exploit-DBVexDay Proof
Answerdev 1.0.3 - Account Takeover
CVE-2023-0744CRITICALwebappsgo05 Apr 2023
Improper Access Control in answerdev/answer
48RISK
open
Exploit-DBVexDay Proof
Responsive FileManager 9.9.5 - Remote Code Execution (RCE)
CVE-2022-46604HIGHwebappsphp05 Apr 2023
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RISK
open
Exploit-DBVexDay Proof
BTCPay Server v1.7.4 - HTML Injection
CVE-2023-0493MEDIUMwebappsmultiple05 Apr 2023
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
33RISK
open
Exploit-DBVexDay Proof
WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE
CVE-2020-25213CRITICALunder attackwebappsphp03 Apr 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
Exploit-DBVexDay Proof
Roxy WI v6.1.0.0 - Improper Authentication Control
CVE-2022-31125CRITICALwebappspython03 Apr 2023
Authentication Bypass in Roxy-wi
53RISK
open
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS)
CVE-2023-23161webappsphp03 Apr 2023
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to e
38RISK
open
Exploit-DBVexDay Proof
Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE)
CVE-2022-31126CRITICALwebappspython03 Apr 2023
Unauthenticated Remote Code Execution in Roxy-wi
75RISK
open
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - SQL Injection (cid) Unauthenticated
CVE-2023-23162webappsphp03 Apr 2023
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter
23RISK
open
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - SQL Injection (editid) authenticated
CVE-2023-23163webappsphp03 Apr 2023
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parame
23RISK
open
Exploit-DBVexDay Proof
Paid Memberships Pro v2.9.8 (WordPress Plugin) - Unauthenticated SQL Injection
CVE-2023-23488CRITICALwebappsphp03 Apr 2023
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RISK
open
Exploit-DBVexDay Proof
Apache 2.4.x - Buffer Overflow
CVE-2021-44790webappsmultiple01 Apr 2023
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
45RISK
open
Exploit-DBVexDay Proof
Yahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)
CVE-2022-48197webappsphp01 Apr 2023
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, Tree
38RISK
open
Exploit-DBVexDay Proof
GitLab v15.3 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-2884CRITICALwebappsruby01 Apr 2023
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3
70RISK
open
Exploit-DBVexDay Proof
WP All Import v3.6.7 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-1565HIGHwebappsphp29 Mar 2023
Import any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload
46RISK
open
Exploit-DBVexDay Proof
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
CVE-2022-3552HIGHwebappsphp28 Mar 2023
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISK
open
Exploit-DBVexDay Proof
Grafana <=6.2.4 - HTML Injection
CVE-2019-13068webappstypescript27 Mar 2023
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the
35RISK
open
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39291MEDIUMwebappsphp27 Mar 2023
Denial of service through logs in zoneminder
33RISK
open
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39290HIGHwebappsphp27 Mar 2023
CSRF key bypass using HTTP methods in zoneminder
41RISK
open
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39285HIGHwebappsphp27 Mar 2023
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
41RISK
open
Exploit-DBVexDay Proof
MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
CVE-2022-26149webappsphp25 Mar 2023
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex
23RISK
open
Exploit-DBVexDay Proof
Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
CVE-2022-35155MEDIUMwebappsphp25 Mar 2023
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the s
33RISK
open
Exploit-DBVexDay Proof
Abantecart v1.3.2 - Authenticated Remote Code Execution
CVE-2022-26521webappsphp25 Mar 2023
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.