Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
13,727 exploits
GitHub PoC3
CVE-2023-36845 - Juniper Firewall Remote code execution (RCE)
CVE-2023-36845CRITICALunder attack29 Sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
GitHub PoC
go CVE-2023-24538 patch issue resolver - Dunfell
CVE-2023-24538CRITICAL29 Sep 2023
Backticks not treated as string delimiters in html/template
48RISK
open
GitHub PoC46
JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit
CVE-2023-42793CRITICALunder attackransomware29 Sep 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC5
Scans an executable and determines if it was wrapped in an Electron version vulnerable to the Chromium vulnerability CVE-2023-4863/ CVE-2023-5129
CVE-2023-4863HIGHunder attack29 Sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
GitHub PoC41
MS Office and Windows HTML RCE (CVE-2023-36884) - PoC and exploit
CVE-2023-36884HIGHunder attackransomware28 Sep 2023
Windows Search Remote Code Execution Vulnerability
93RISK
open
GitHub PoC3
PoC for Stored XSS (CVE-2023-43770) Vulnerability
CVE-2023-43770MEDIUMunder attack28 Sep 2023
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft
75RISK
open
GitHub PoC34
A Proof-Of-Concept for the CVE-2023-43770 vulnerability.
CVE-2023-43770MEDIUMunder attack27 Sep 2023
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft
75RISK
open
GitHub PoC9
CVE-2023-34152
CVE-2023-34152CRITICAL27 Sep 2023
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob wit
48RISK
open
GitHub PoC
sherlocksecurity/CVE-2023-4762-Code-Review
CVE-2023-4762HIGHunder attack27 Sep 2023
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a
83RISK
open
GitHub PoC24
buptsb/CVE-2023-4762
CVE-2023-4762HIGHunder attack27 Sep 2023
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a
83RISK
open
GitHub PoC1
halencarjunior/CVE-2023-36845
CVE-2023-36845CRITICALunder attack27 Sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
GitHub PoC1
New exploitation of 2020 Sophos vuln
CVE-2022-1040CRITICALunder attack26 Sep 2023
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
GitHub PoC55
Juniper Firewalls CVE-2023-36845 - RCE
CVE-2023-36845CRITICALunder attack26 Sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
GitHub PoC1
Automatic Mass Tool for check and exploiting vulnerability in CVE-2022-4047 - Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
CVE-2022-4047CRITICAL26 Sep 2023
Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
48RISK
open
GitHub PoC239
Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2023-29357CRITICALunder attackransomware26 Sep 2023
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC8
VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
CVE-2023-20887CRITICALunder attack25 Sep 2023
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RISK
open
GitHub PoC3
BAD-WEBP-CVE-2023-4863
CVE-2023-4863HIGHunder attack25 Sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
GitHub PoC6
bbaranoff/CVE-2023-4863
CVE-2023-4863HIGHunder attack25 Sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
GitHub PoC151
Exploit for CVE-2023-29360 targeting MSKSSRV.SYS driver
CVE-2023-29360HIGHunder attack24 Sep 2023
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC5
A Proof of Concept for chaining the CVEs [CVE-2023-36844, CVE-2023-36845, CVE-2023-36846, CVE-2023-36847] to achieve Remote Code Execution (phpinfo) in Juniper JunOS within SRX and EX Series products.Modified from original exploit developed by @watchTowr .
CVE-2023-36844MEDIUMunder attack24 Sep 2023
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
100RISK
open
GitHub PoC
DimaMend/cve-2022-42889-text4shell
CVE-2022-4288922 Sep 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC3
Proof-of-Concept (POC) of CVE-2023-38831 Zero-Day vulnerability in WinRAR
CVE-2023-38831HIGHunder attackransomware21 Sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC316
mistymntncop/CVE-2023-4863
CVE-2023-4863HIGHunder attack21 Sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
GitHub PoC1
A PoC for CVE-2022-26134 for Educational Purposes and Security Research
CVE-2022-26134CRITICALunder attackransomware20 Sep 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
Perform With Massive Juniper Remote Code Execution
CVE-2023-36844MEDIUMunder attack20 Sep 2023
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
100RISK
open
GitHub PoC
ngothienan/CVE-2023-38831
CVE-2023-38831HIGHunder attackransomware17 Sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC1
CVE: CVE-2022-0847
CVE-2022-0847HIGHunder attack17 Sep 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
futurezayka/CVE-2011-3192
CVE-2011-319216 Sep 2023
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISK
open
GitHub PoC62
A go-exploit to scan for Juniper firewalls vulnerable to CVE-2023-36845
CVE-2023-36845CRITICALunder attack16 Sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
GitHub PoC8
Automatic Mass Tool for checking vulnerability in CVE-2022-4060 - WordPress Plugin : User Post Gallery <= 2.19 - Unauthenticated RCE
CVE-2022-4060CRITICAL15 Sep 2023
User Post Gallery <= 2.19 - Unauthenticated RCE
75RISK
open
previouspage 258 / 458next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.