Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,801cataloged exploits
36,063CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DB
Symantec Messaging Gateway 10.7.4 - Stored Cross-Site Scripting (XSS)
CVE-2022-25630MEDIUMwebappsmultiple08 Apr 2023
An authenticated user can embed malicious content with XSS into the admin group policy page.
33RISK
open
Exploit-DB
Adobe Connect 11.4.5 - Local File Disclosure
CVE-2023-22232MEDIUMwebappsmultiple08 Apr 2023
Adobe Connect Improper Access Control Security feature bypass
70RISK
open
Exploit-DB
RSA NetWitness Platform 12.2 - Incorrect Access Control / Code Execution
CVE-2022-47529localwindows08 Apr 2023
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Wi
23RISK
open
Exploit-DB
Altenergy Power Control Software C1.2.5 - OS command injection
CVE-2023-28343webappshardware08 Apr 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open
Exploit-DB
Microsoft Excel 365 MSO (Version 2302 Build 16.0.16130.20186) 64-bit - Remote Code Execution (RCE)
CVE-2023-23399HIGHremotemultiple08 Apr 2023
Microsoft Excel Remote Code Execution Vulnerability
41RISK
open
Exploit-DBVexDay Proof
Joomla! v4.2.8 - Unauthenticated information disclosure
CVE-2023-23752MEDIUMunder attackwebappsphp08 Apr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
Exploit-DB
ZCBS/ZBBS/ZPBS v4.14k - Reflected Cross-Site Scripting (XSS)
CVE-2023-26692MEDIUMwebappscgi08 Apr 2023
ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Manageme
33RISK
open
Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2022-43769HIGHunder attackwebappsjsp08 Apr 2023
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RISK
open
Exploit-DB
X2CRM v6.6/6.9 - Reflected Cross-Site Scripting (XSS) (Authenticated)
CVE-2022-48177MEDIUMwebappsphp08 Apr 2023
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability v
33RISK
open
Exploit-DB
Docker based datastores for IBM Instana 241-2 243-0 - No Authentication
CVE-2023-27290CRITICALremotemultiple07 Apr 2023
IBM Observability with Instana missing authentication
48RISK
open
Exploit-DB
Tenda N300 F3 12.01.01.48 - Malformed HTTP Request Header Processing
CVE-2020-35391CRITICALremotehardware07 Apr 2023
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISK
open
Exploit-DB
ChurchCRM 4.5.1 - Authenticated SQL Injection
CVE-2023-24787webappsphp07 Apr 2023
20RISK
open
Exploit-DB
IBM Aspera Faspex 4.4.1 - YAML deserialization (RCE)
CVE-2022-47986CRITICALunder attackransomwareremotemultiple07 Apr 2023
IBM Aspera Faspex code execution
100RISK
open
Exploit-DB
NotrinosERP 0.7 - Authenticated Blind SQL Injection
CVE-2023-24788webappsphp07 Apr 2023
NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/s
23RISK
open
Exploit-DB
Wondershare Dr Fone 12.9.6 - Privilege Escalation
CVE-2023-27010HIGHlocalwindows07 Apr 2023
Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability all
41RISK
open
Exploit-DB
MAC 1200R - Directory Traversal
CVE-2021-27825HIGHwebappshardware07 Apr 2023
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-stati
41RISK
open
Exploit-DBVexDay Proof
Employee Task Management System v1.0 - Broken Authentication
CVE-2023-0905HIGHwebappsphp06 Apr 2023
SourceCodester Employee Task Management System changePasswordForEmployee.php improper authentication
41RISK
open
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - Broken Access Control
CVE-2023-0963HIGHwebappsphp06 Apr 2023
SourceCodester Music Gallery Site POST Request Users.php access control
41RISK
open
Exploit-DBVexDay Proof
Employee Task Management System v1.0 - SQL Injection on edit-task.php
CVE-2023-0902LOWwebappsphp06 Apr 2023
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISK
open
Exploit-DBVexDay Proof
Employee Task Management System v1.0 - SQL Injection on (task-details.php?task_id=?)
CVE-2023-0904MEDIUMwebappsphp06 Apr 2023
SourceCodester Employee Task Management System task-details.php sql injection
33RISK
open
Exploit-DB
modoboa 2.0.4 - Admin TakeOver
CVE-2023-0777HIGHwebappspython06 Apr 2023
Authentication Bypass by Primary Weakness in modoboa/modoboa
61RISK
open
Exploit-DBVexDay Proof
Auto Dealer Management System v1.0 - SQL Injection on manage_user.php
CVE-2023-0915MEDIUMwebappsphp06 Apr 2023
SourceCodester Auto Dealer Management System sql injection
33RISK
open
Exploit-DBVexDay Proof
Auto Dealer Management System v1.0 - SQL Injection in sell_vehicle.php
CVE-2023-0913MEDIUMwebappsphp06 Apr 2023
SourceCodester Auto Dealer Management System sql injection
33RISK
open
Exploit-DBVexDay Proof
Auto Dealer Management System 1.0 - Broken Access Control Exploit
CVE-2023-0916MEDIUMwebappsphp06 Apr 2023
SourceCodester Auto Dealer Management System Users.php access control
33RISK
open
Exploit-DB
Dompdf 1.2.1 - Remote Code Execution (RCE)
CVE-2022-28368webappsphp06 Apr 2023
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RISK
open
Exploit-DBVexDay Proof
Simple Task Managing System v1.0 - SQL Injection (Unauthenticated)
CVE-2022-40032CRITICALwebappsphp06 Apr 2023
SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' paramet
68RISK
open
Exploit-DBVexDay Proof
Art Gallery Management System Project in PHP v 1.0 - SQL injection
CVE-2023-23156webappsphp06 Apr 2023
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid par
23RISK
open
Exploit-DB
POLR URL 2.3.0 - Shortener Admin Takeover
CVE-2021-21276CRITICALwebappsphp06 Apr 2023
Privilege escalation in Polr
48RISK
open
Exploit-DB
Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-45701HIGHremotehardware06 Apr 2023
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
53RISK
open
Exploit-DBVexDay Proof
Simple Food Ordering System v1.0 - Cross-Site Scripting (XSS)
CVE-2023-0902LOWwebappsphp06 Apr 2023
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.