Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,624GitHub PoC 13,727VulnCheck XDB 8,410Nuclei 4,231Metasploit 3,467✓ verified onlyrecentpopularrisk
13,727 exploits
GitHub PoC★ 22
CVE-2022-39227 : Proof of Concept
Python-jwt subject to Authentication Bypass by Spoofing
48RISK
open ↗GitHub PoC★ 1
Paid Memberships Pro v2.9.8 (WordPress Plugin) - Unauthenticated SQL Injection
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RISK
open ↗GitHub PoC
Spring rce environment for CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗GitHub PoC★ 170
CVE-2023-25157 - GeoServer SQL Injection - PoC
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open ↗GitHub PoC★ 2
CVE-2023-34362-IOCs. More information on Deep Instinct's blog site.
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open ↗GitHub PoC
MrDottt/CVE-2021-22911
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open ↗GitHub PoC
On May 23, 2023 GitLab released version 16.0.1 which fixed a critical vulnerability, CVE-2023-2825, affecting the Community Edition (CE) and Enterprise Edition (EE) version 16.0.0. The vulnerability allows unauthenticated users to read arbitrary files through a path traversal bug.
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISK
open ↗GitHub PoC
Proof of concept / CTF script for exploiting CVE-2022-46169 in Cacti, versions >=1.2.22
Unauthenticated Command Injection
100RISK
open ↗GitHub PoC
Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISK
open ↗GitHub PoC★ 4
hoangprod/CVE-2021-31956-POC
Windows NTFS Elevation of Privilege Vulnerability
76RISK
open ↗GitHub PoC★ 3
Poc&Exp,支持批量扫描,反弹shell
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗GitHub PoC
Exploit created in python3 to exploit known vulnerabilities in Apache web server (CVE-2021-41773, CVE-2021-42013)
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 3
CVE-2023-33246:Apache RocketMQ 远程命令执行漏洞检测工具
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open ↗GitHub PoC★ 1
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RISK
open ↗GitHub PoC
[CVE-2021-33690] Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructure
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Compo
75RISK
open ↗GitHub PoC★ 114
Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open ↗GitHub PoC★ 81
Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open ↗GitHub PoC★ 2
4mazing/CVE-2023-33246-Copy
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open ↗GitHub PoC★ 1
Exploit for CVE:2010-2075. This exploit allows remote command execution in UnrealIRCd 3.2.8.1.
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISK
open ↗GitHub PoC★ 2
A simple python script for a firewall rule that blocks incoming requests based on the Spring4Shell (CVE-2022-22965) vulnerability
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗GitHub PoC★ 1
eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's password in plain text.
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2
48RISK
open ↗GitHub PoC
the proof of concept written in Python for an unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups. This is a critical severity issue
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISK
open ↗GitHub PoC★ 62
I5N0rth/CVE-2023-33246
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open ↗GitHub PoC★ 6
WindowsProtocolTestSuites is to trigger BSoD, and full exploit poc.
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open ↗GitHub PoC
kw3h4/CVE-2023-21839-metasploit-scanner
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open ↗GitHub PoC★ 2
Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open ↗GitHub PoC★ 8
The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open ↗GitHub PoC★ 1
MinIO Information Disclosure Vulnerability scanner by metasploit
Minio Information Disclosure in Cluster Deployment
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.