Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
13,727 exploits
GitHub PoC8
Automatic Mass Tool for checking vulnerability in CVE-2022-4060 - WordPress Plugin : User Post Gallery <= 2.19 - Unauthenticated RCE
CVE-2022-4060CRITICAL15 Sep 2023
User Post Gallery <= 2.19 - Unauthenticated RCE
75RISK
open
GitHub PoC
Anthony1500/CVE-2022-40684
CVE-2022-40684CRITICALunder attackransomware14 Sep 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
GitHub PoC
CVE-2018-1000861 Exploit
CVE-2018-1000861CRITICALunder attack13 Sep 2023
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISK
open
GitHub PoC1
CVE-2023-43481
CVE-2023-43481CRITICAL13 Sep 2023
An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote att
48RISK
open
GitHub PoC9
CVE-2023-38831 WinRaR Exploit Generator
CVE-2023-38831HIGHunder attackransomware12 Sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC3
Proof of concept (PoC) exploit for WinRAR vulnerability (CVE-2023-38831) vulnerability
CVE-2023-38831HIGHunder attackransomware12 Sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC2
Automatic Mass Tool for checking vulnerability in CVE-2023-0159 - Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated LFI
CVE-2023-015911 Sep 2023
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RISK
open
GitHub PoC2
Automatic Mass Tool for checking vulnerability in CVE-2022-4063 - InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
CVE-2022-4063CRITICAL11 Sep 2023
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RISK
open
GitHub PoC
ช่องโหว่ CVE-2023-35674 *สถานะ: ยังไม่เสร็จ*
CVE-2023-35674HIGHunder attack11 Sep 2023
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the cod
71RISK
open
GitHub PoC
Development of an exploit for privilege escalation in Windows systems ( NT / 2k / XP / 2K3 / VISTA / 2k8 / 7 ) using the vulnerability CVE-2010-0232
CVE-2010-0232HIGHunder attack11 Sep 2023
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Se
91RISK
open
GitHub PoC1
Python3 exploit for Fuel CMS 1.4.1 Remote Code Execution (CVE-2018-16763) with Reverse Shell.
CVE-2018-1676311 Sep 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC
0xZon/CVE-2022-46169-Exploit
CVE-2022-46169CRITICALunder attack10 Sep 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
caopengyan/CVE-2023-2825
CVE-2023-2825CRITICAL10 Sep 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISK
open
GitHub PoC
davidholiday/CVE-2007-4559
CVE-2007-4559CRITICAL10 Sep 2023
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RISK
open
GitHub PoC
RCE PoC for Apache Commons Text vuln
CVE-2022-4288909 Sep 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
simulation experiment of Curveball (CVE-2020-0601) attacks under ECQV implicit certificates with Windows-like verifiers
CVE-2020-0601HIGHunder attack09 Sep 2023
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC28
jakabakos/CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE
CVE-2023-27524HIGHunder attack08 Sep 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
GitHub PoC9
A PoC exploit for CVE-2017-8225 - GoAhead System.ini Leak
CVE-2017-822508 Sep 2023
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
28RISK
open
GitHub PoC
Hikikan/CVE-2021-22205
CVE-2021-22205CRITICALunder attackransomware08 Sep 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC
Quick exploit builder for CVE-2023-38831, a vulnerability that affects WinRAR versions before 6.23.
CVE-2023-38831HIGHunder attackransomware07 Sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
This is a PoC for CVE-2023-27372 and spawns a fully interactive shell.
CVE-2023-27372CRITICAL07 Sep 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
GitHub PoC2
SUPRAAA-1337/CVE-2021-20021
CVE-2021-20021CRITICALunder attackransomware07 Sep 2023
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account
100RISK
open
GitHub PoC7
An exploit for OpenTSDB <= 2.4.1 cmd injection (CVE-2023-36812/CVE-2023-25826) written in Fortran
CVE-2023-36812CRITICAL07 Sep 2023
Remote Code Execution in OpenTSDB
68RISK
open
GitHub PoC
Text4Shell
CVE-2022-4288906 Sep 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
A bash script for easyly exploiting ImageMagick Arbitrary File Read Vulnerability CVE-2022-44268
CVE-2022-44268MEDIUM05 Sep 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
GitHub PoC
Ijinleife/CVE-2019-14287
CVE-2019-1428705 Sep 2023
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC47
CVE-2023-4634
CVE-2023-4634CRITICAL05 Sep 2023
Media Library Assistant <= 3.09 - Unauthenticated Local/Remote File Inclusion & Remote Code Execution
85RISK
open
GitHub PoC
asepsaepdin/CVE-2021-3156
CVE-2021-3156HIGHunder attack05 Sep 2023
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC11
Automated vulnerability scanner for CVE-2023-28432 in Minio deployments, revealing sensitive environment variables.
CVE-2023-28432HIGHunder attack05 Sep 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC
Generate Seralize Payload for CVE-2019-0604 for Sharepoint 2010 SP2 .net 3.5
CVE-2019-0604CRITICALunder attackransomware05 Sep 2023
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISK
open
previouspage 259 / 458next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.