Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
13,727 exploits
GitHub PoC8
Poc for CVE-2023-22515
CVE-2023-22515CRITICALunder attackransomware10 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC2
Recreation of the SharePoint PoC for CVE-2023-29357 in C# from LuemmelSec
CVE-2023-29357CRITICALunder attackransomware10 Oct 2023
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC246
Basic vulnerability scanning to see if web servers may be vulnerable to CVE-2023-44487
CVE-2023-44487HIGHunder attack10 Oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
GitHub PoC153
CVE-2023-22515: Confluence Broken Access Control Exploit
CVE-2023-22515CRITICALunder attackransomware10 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC
An implementation of a proof-of-concept for CVE-2018-5767 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5767)
CVE-2018-576709 Oct 2023
An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code
35RISK
open
GitHub PoC164
LPE exploit for CVE-2023-36802
CVE-2023-36802HIGHunder attack09 Oct 2023
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC1
xiaoQ1z/CVE-2023-4911
CVE-2023-4911HIGHunder attack08 Oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
GitHub PoC
Trinadh465/platform_external_libvpx_v1.8.0_CVE-2023-5217
CVE-2023-5217HIGHunder attack06 Oct 2023
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remo
83RISK
open
GitHub PoC9
Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability
CVE-2021-44228CRITICALunder attackransomware06 Oct 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC16
A PoC to trigger CVE-2023-5217 from the Browser WebCodecs or MediaRecorder interface.
CVE-2023-5217HIGHunder attack06 Oct 2023
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remo
83RISK
open
GitHub PoC79
Scanner for CVE-2023-22515 - Broken Access Control Vulnerability in Atlassian Confluence
CVE-2023-22515CRITICALunder attackransomware06 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC3
CVE-2023-41892 - Craft CMS Remote Code Execution (RCE)
CVE-2023-41892CRITICAL06 Oct 2023
Craft CMS Remote Code Execution vulnerability
85RISK
open
GitHub PoC
Trinadh465/platform_external_libvpx_v1.4.0_CVE-2023-5217
CVE-2023-5217HIGHunder attack06 Oct 2023
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remo
83RISK
open
GitHub PoC
CVE-2021-3560 Bypass su - root
CVE-2021-3560HIGHunder attack06 Oct 2023
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC9
PoC of CVE-2023-42793
CVE-2023-42793CRITICALunder attackransomware05 Oct 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC
whoamins/CVE-2023-42793
CVE-2023-42793CRITICALunder attackransomware05 Oct 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC21
A tool for finding vulnerable libwebp(CVE-2023-4863)
CVE-2023-4863HIGHunder attack05 Oct 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
GitHub PoC167
CVE-2023-4911 proof of concept
CVE-2023-4911HIGHunder attack04 Oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
GitHub PoC392
PoC for CVE-2023-4911
CVE-2023-4911HIGHunder attack04 Oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
GitHub PoC15
https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
CVE-2023-4911HIGHunder attack04 Oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
GitHub PoC
Checker for CVE-2022-0441
CVE-2022-044103 Oct 2023
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RISK
open
GitHub PoC4
CVE-2023-36845 PoC script automates the PoC for CVE-2023-36845 targeting Juniper Networks Junos OS's J-Web component on EX and SRX Series devices. It exploits a PHP flaw, allowing remote modification of the PHPRC variable. Successful exploitation can lead to code injection and execution.
CVE-2023-36845CRITICALunder attack02 Oct 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
GitHub PoC1
Analysis of WS_FTP CVE
CVE-2023-40044CRITICALunder attackransomware02 Oct 2023
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
100RISK
open
GitHub PoC39
A tool that checks if a TorchServe instance is vulnerable to CVE-2023-43654
CVE-2023-43654CRITICAL02 Oct 2023
TorchServe Server-Side Request Forgery
75RISK
open
GitHub PoC1
simrotion13/CVE-2023-36845
CVE-2023-36845CRITICALunder attack01 Oct 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
GitHub PoC6
navreet1425/CVE-2021-34621
CVE-2021-34621CRITICAL30 Sep 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISK
open
GitHub PoC6
Find Electron Apps Vulnerable to CVE-2023-4863 / CVE-2023-5129
CVE-2023-4863HIGHunder attack30 Sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
GitHub PoC54
LuemmelSec/CVE-2023-29357
CVE-2023-29357CRITICALunder attackransomware30 Sep 2023
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC5
Scans an executable and determines if it was wrapped in an Electron version vulnerable to the Chromium vulnerability CVE-2023-4863/ CVE-2023-5129
CVE-2023-4863HIGHunder attack29 Sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
GitHub PoC
jytmX/CVE-2021-24499
CVE-2021-2449929 Sep 2023
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISK
open
previouspage 257 / 458next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.