Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
13,727 exploits
GitHub PoC
pitufo1721/CVE-2025-55182-GodzillaMemoryShell
CVE-2025-55182CRITICALunder attackransomware07 Jul 2023
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC5
CVE-2023-32315-Openfire-Bypass
CVE-2023-32315HIGHunder attack07 Jul 2023
Openfire administration console authentication bypass
100RISK
open
GitHub PoC
rizqimaulanaa/CVE-2023-3460
CVE-2023-346007 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
GitHub PoC8
An eBPF program to detect attacks on CVE-2022-0847
CVE-2022-0847HIGHunder attack06 Jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC35
Exploit for CVE-2023-3460. Unauthorized admin access for Ultimate Member plugin < v2.6.7
CVE-2023-346005 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
GitHub PoC6
This is a PoC for CVE-2023-27372 which spawns a fully interactive shell.
CVE-2023-27372CRITICAL05 Jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
GitHub PoC
This is the Updated Python3 exploit for CVE-2019-9053
CVE-2019-905304 Jul 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC2
CVE-2017-7921 EXPLOIT
CVE-2017-7921CRITICALunder attack04 Jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC13
PoC of Imagemagick's Arbitrary File Read
CVE-2022-44268MEDIUM03 Jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
GitHub PoC
WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2023-39362). Run it at your own risk!
CVE-2023-39362HIGH03 Jul 2023
Authenticated command injection in SNMP options of a Device
63RISK
open
GitHub PoC4
Wordpress CVE-2023-32243
CVE-2023-32243CRITICAL03 Jul 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
GitHub PoC3
Fix WinVerifyTrust Signature Validation Vulnerability, CVE-2013-3900, QID-378332
CVE-2013-3900MEDIUMunder attack03 Jul 2023
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
GitHub PoC6
Perform With Massive Openfire Unauthenticated Users
CVE-2023-32315HIGHunder attack02 Jul 2023
Openfire administration console authentication bypass
100RISK
open
GitHub PoC1
Expoit for CVE-2022-44268
CVE-2022-44268MEDIUM02 Jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
GitHub PoC
spip
CVE-2023-27372CRITICAL01 Jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
GitHub PoC5
Exploitation of "Shellshock" Vulnerability. Remote code execution in Apache with mod_cgi
CVE-2014-6271CRITICALunder attack01 Jul 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC11
Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with CVE-2019-6693 is the encryption routine).
CVE-2019-6693MEDIUMunder attackransomware30 Jun 2023
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISK
open
GitHub PoC9
WordPress社交登录和注册(Discord,Google,Twitter,LinkedIn)<=7.6.4-绕过身份验证
CVE-2023-2982CRITICAL30 Jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISK
open
GitHub PoC82
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
CVE-2023-2982CRITICAL29 Jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISK
open
GitHub PoC4
Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.
CVE-2021-44228CRITICALunder attackransomware29 Jun 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Hamesawian/CVE-2021-42013
CVE-2021-42013CRITICALunder attackransomware29 Jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
yangshifan-git/CVE-2021-1732
CVE-2021-1732HIGHunder attackransomware29 Jun 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC21
非常简单的CVE-2023-0386's exp and analysis.Use c and sh.
CVE-2023-0386HIGHunder attack28 Jun 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC179
fortra/CVE-2023-28252
CVE-2023-28252HIGHunder attackransomware27 Jun 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC13
This repository contains a Python script to automate the process of testing for a vulnerability known as Text4Shell, referenced under the CVE id: CVE-2022-42889.
CVE-2022-4288927 Jun 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
ps-interactive/lab_cve-2021-4034-polkit-emulation-and-detection
CVE-2021-4034HIGHunder attack27 Jun 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC14
A Python script for generating exploits targeting CVE-2022-4510 RCE Binwalk. It supports SSH, command execution, and reverse shell options. Exploits are saved in PNG format. Ideal for testing and demonstrations.
CVE-2022-4510HIGH27 Jun 2023
Path Traversal in binwalk
46RISK
open
GitHub PoC
An exploit for the Nibbles manager version 4.0.3. This exploit allows RCE to be performed.
CVE-2015-696726 Jun 2023
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RISK
open
GitHub PoC
manavvedawala/CVE-2023-32243-proof-of-concept
CVE-2023-32243CRITICAL26 Jun 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
GitHub PoC
pashayogi/CVE-2023-22809
CVE-2023-22809HIGH25 Jun 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
previouspage 267 / 458next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.