Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DB
Cacti v1.2.22 - Remote Command Execution (RCE)
CVE-2022-46169CRITICALunder attackwebappsphp31 Mar 2023
Unauthenticated Command Injection
100RISK
open
Exploit-DB
rconfig 3.9.7 - Sql Injection (Authenticated)
CVE-2022-45030HIGHwebappsphp31 Mar 2023
A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may
41RISK
open
Exploit-DB
Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
CVE-2022-24627CRITICALwebappsphp30 Mar 2023
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injec
68RISK
open
Exploit-DB
Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
CVE-2022-24629CRITICALwebappsphp30 Mar 2023
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achie
60RISK
open
Exploit-DB
Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
CVE-2022-24632webappsphp30 Mar 2023
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during f
28RISK
open
Exploit-DB
Dreamer CMS v4.0.0 - SQL Injection
CVE-2022-43128webappsmultiple30 Mar 2023
20RISK
open
Exploit-DB
CrowdStrike Falcon AGENT 6.44.15806 - Uninstall without Installation Token
CVE-2022-2841LOWlocalwindows30 Mar 2023
CrowdStrike Falcon Uninstallation authorization
28RISK
open
Exploit-DB
Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
CVE-2022-24630webappsphp30 Mar 2023
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh
28RISK
open
Exploit-DB
LISTSERV 17 - Insecure Direct Object Reference (IDOR)
CVE-2022-40319HIGHwebappscgi30 Mar 2023
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a
41RISK
open
Exploit-DB
LISTSERV 17 - Reflected Cross Site Scripting (XSS)
CVE-2022-39195MEDIUMwebappscgi30 Mar 2023
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary
48RISK
open
Exploit-DBVexDay Proof
WP All Import v3.6.7 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-1565HIGHwebappsphp29 Mar 2023
Import any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload
46RISK
open
Exploit-DB
Label Studio 1.5.0 - Authenticated Server Side Request Forgery (SSRF)
CVE-2022-36551webappspython28 Mar 2023
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.
23RISK
open
Exploit-DBVexDay Proof
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
CVE-2022-3552HIGHwebappsphp28 Mar 2023
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISK
open
Exploit-DB
OPSWAT Metadefender Core - Privilege Escalation
CVE-2022-32272webappsmultiple28 Mar 2023
OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5
23RISK
open
Exploit-DB
X-Skipper-Proxy v0.13.237 - Server Side Request Forgery (SSRF)
CVE-2022-38580CRITICALremotemultiple28 Mar 2023
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
53RISK
open
Exploit-DB
Tapo C310 RTSP server v1.3.0 - Unauthorised Video Stream Access
CVE-2022-37255HIGHremotehardware28 Mar 2023
TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL07552646
41RISK
open
Exploit-DB
ReQlogic v11.3 - Reflected Cross-Site Scripting (XSS)
CVE-2022-41441MEDIUMwebappsaspx28 Mar 2023
Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts o
48RISK
open
Exploit-DB
ZKTeco ZEM/ZMM 8.88 - Missing Authentication
CVE-2022-42953HIGHwebappsjsp28 Mar 2023
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct r
41RISK
open
Exploit-DB
Pega Platform 8.1.0 - Remote Code Execution (RCE)
CVE-2022-24082CRITICALwebappsmultiple28 Mar 2023
If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Inte
53RISK
open
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39285HIGHwebappsphp27 Mar 2023
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
41RISK
open
Exploit-DBVexDay Proof
Grafana <=6.2.4 - HTML Injection
CVE-2019-13068webappstypescript27 Mar 2023
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the
35RISK
open
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39290HIGHwebappsphp27 Mar 2023
CSRF key bypass using HTTP methods in zoneminder
41RISK
open
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39291MEDIUMwebappsphp27 Mar 2023
Denial of service through logs in zoneminder
33RISK
open
Exploit-DB
FortiOS_ FortiProxy_ FortiSwitchManager v7.2.1 - Authentication Bypass
CVE-2022-40684CRITICALunder attackransomwarewebappsmultiple27 Mar 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
Exploit-DB
Password Manager for IIS v2.0 - XSS
CVE-2022-36664MEDIUMwebappsasp25 Mar 2023
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL
33RISK
open
Exploit-DBVexDay Proof
Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
CVE-2022-35155MEDIUMwebappsphp25 Mar 2023
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the s
33RISK
open
Exploit-DBVexDay Proof
Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection
CVE-2022-3141webappsphp25 Mar 2023
Translatepress Multilinugal < 2.3.3 - Admin+ SQLi
23RISK
open
Exploit-DBVexDay Proof
SimpleMachinesForum v2.1.1 - Authenticated Remote Code Execution
CVE-2022-26982webappsphp25 Mar 2023
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting
23RISK
open
Exploit-DB
DLink DIR 819 A1 - Denial of Service
CVE-2022-40946HIGHdoshardware25 Mar 2023
On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via t
41RISK
open
Exploit-DBVexDay Proof
Abantecart v1.3.2 - Authenticated Remote Code Execution
CVE-2022-26521webappsphp25 Mar 2023
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.