Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
21,554 exploits
Referência
CVE-2023-27350
CVE-2023-27350CRITICALunder attackransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
Referência
CVE-2023-27350
CVE-2023-27350CRITICALunder attackransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
Referência
CVE-2023-27350
CVE-2023-27350CRITICALunder attackransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
Referência
CVE-2023-27350
CVE-2023-27350CRITICALunder attackransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
Referência
Froxlor 0.10.29.1 - SQL Injection (Authenticated)
CVE-2021-42325webappsphp
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
28RISK
open
Referência
CVE-2021-42362
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RISK
open
Referência
CVE-2021-42580
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/adm
23RISK
open
Referência
CVE-2021-42697
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, whic
35RISK
open
Referência
Ericsson Network Location MPS GMPC21 - Remote Code Execution (RCE) (Metasploit)
CVE-2021-43339webappsmultiple
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file
23RISK
open
Referência
CVE-2021-43481
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstag
23RISK
open
Referência
CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
Referência
CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
Referência
CVE-2016-10010
sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which
41RISK
open
Referência
CVE-2021-43857
Gerapy may contain remote code execution vulnerability
60RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 218 / 719next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.