Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DB
BuildaGate5library v5 - Reflected Cross-Site Scripting (XSS)
CVE-2023-36163webappsphp11 Jul 2023
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code
23RISK
open
Exploit-DB
Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
CVE-2022-21907CRITICALremotewindows07 Jul 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
Exploit-DB
Microsoft Outlook Microsoft 365 MSO (Version 2306 Build 16.0.16529.20100) 32-bit - Remote Code Execution
CVE-2023-33131HIGHremotemultiple07 Jul 2023
Microsoft Outlook Remote Code Execution Vulnerability
41RISK
open
Exploit-DB
Lost and Found Information System v1.0 - SQL Injection
CVE-2023-33592webappsphp06 Jul 2023
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RISK
open
Exploit-DB
Microsoft Edge 114.0.1823.67 (64-bit) - Information Disclosure
CVE-2023-33145MEDIUMlocalmultiple06 Jul 2023
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
33RISK
open
Exploit-DB
Sales of Cashier Goods v1.0 - Cross Site Scripting (XSS)
CVE-2023-36346webappsphp03 Jul 2023
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parame
38RISK
open
Exploit-DB
FuguHub 8.1 - Remote Code Execution
CVE-2023-24078HIGHwebappsmultiple03 Jul 2023
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RISK
open
Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)
CVE-2023-28285HIGHremotemultiple03 Jul 2023
Microsoft Office Remote Code Execution Vulnerability
41RISK
open
Exploit-DB
WP AutoComplete 1.0.4 - Unauthenticated SQLi
CVE-2022-4297CRITICALwebappsphp03 Jul 2023
WP AutoComplete Search <= 1.0.4 - Unauthenticated SQLi
48RISK
open
Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 32-bit - Remote Code Execution (RCE)
CVE-2023-33137HIGHremotemultiple03 Jul 2023
Microsoft Excel Remote Code Execution Vulnerability
41RISK
open
Exploit-DB
TP-Link TL-WR940N V4 - Buffer OverFlow
CVE-2023-36355doshardware03 Jul 2023
TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6Cfg
35RISK
open
Exploit-DB
POS Codekop v2.0 - Authenticated Remote Code Execution (RCE)
CVE-2023-36348webappsphp03 Jul 2023
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename p
23RISK
open
Exploit-DB
Windows 11 22h2 - Kernel Privilege Elevation
CVE-2023-28293HIGHlocalwindows26 Jun 2023
Windows Kernel Elevation of Privilege Vulnerability
41RISK
open
Exploit-DB
Microsoft SharePoint Enterprise Server 2016 - Spoofing
CVE-2023-28288HIGHwebappsmultiple26 Jun 2023
Microsoft SharePoint Server Spoofing Vulnerability
41RISK
open
Exploit-DB
PrestaShop Winbiz Payment module - Improper Limitation of a Pathname to a Restricted Directory
CVE-2023-30198HIGHwebappsphp26 Jun 2023
Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download
41RISK
open
Exploit-DB
Azure Apache Ambari 2302250400 - Spoofing
CVE-2023-23408MEDIUMremotemultiple26 Jun 2023
Azure Apache Ambari Spoofing Vulnerability
33RISK
open
Exploit-DB
NCH Express Invoice - Clear Text Password Storage and Account Takeover
CVE-2020-11560localwindows23 Jun 2023
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
23RISK
open
Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
CVE-2022-47075HIGHwebappsaspx22 Jun 2023
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the
68RISK
open
Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
CVE-2022-47076HIGHwebappsaspx22 Jun 2023
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via Display
41RISK
open
Exploit-DBVexDay Proof
Super Socializer 7.13.52 - Reflected XSS
CVE-2023-2779MEDIUMwebappsphp20 Jun 2023
Super Socializer < 7.13.52 - Reflected XSS
48RISK
open
Exploit-DB
WP Sticky Social 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)
CVE-2023-3320MEDIUMwebappsphp20 Jun 2023
The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,
33RISK
open
Exploit-DBVexDay Proof
SPIP v4.2.0 - Remote Code Execution (Unauthenticated)
CVE-2023-27372CRITICALwebappsphp20 Jun 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
Exploit-DB
Nokia ASIKA 7.13.52 - Hard-coded private key disclosure
CVE-2023-25187MEDIUMremotehardware20 Jun 2023
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures
33RISK
open
Exploit-DB
Symantec SiteMinder WebAgent v12.52 - Cross-site scripting (XSS)
CVE-2023-23956MEDIUMwebappshardware19 Jun 2023
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
33RISK
open
Exploit-DB
WordPress Theme Medic v1.0.0 - Weak Password Recovery Mechanism for Forgotten Password
CVE-2020-11027MEDIUMwebappsphp19 Jun 2023
Password reset links invalidation issue in WordPress
38RISK
open
Exploit-DBVexDay Proof
PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
CVE-2023-0297CRITICALwebappspython14 Jun 2023
Code Injection in pyload/pyload
85RISK
open
Exploit-DB
Teachers Record Management System 1.0 - File Upload Type Validation
CVE-2023-3187MEDIUMwebappsphp13 Jun 2023
PHPGurukul Teachers Record Management System Profile Picture changeimage.php unrestricted upload
33RISK
open
Exploit-DBVexDay Proof
Sales Tracker Management System v1.0 - Multiple Vulnerabilities
CVE-2023-3184LOWwebappsphp13 Jun 2023
SourceCodester Sales Tracker Management System cross site scripting
28RISK
open
Exploit-DB
WordPress Theme Workreap 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
CVE-2021-24499webappsphp09 Jun 2023
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISK
open
Exploit-DB
Tree Page View Plugin 1.6.7 - Cross Site Scripting (XSS)
CVE-2023-30868HIGHwebappsphp06 Jun 2023
WordPress CMS Tree Page View Plugin <= 1.6.7 is vulnerable to Cross Site Scripting (XSS)
56RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.