Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
13,727 exploits
GitHub PoC124
CVE-2023-0386 analysis and Exp
CVE-2023-0386HIGHunder attack06 May 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC
User enumeration for CVE-2018-15473
CVE-2018-15473MEDIUM05 May 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC420
CVE-2023-0386在ubuntu22.04上的提权
CVE-2023-0386HIGHunder attack05 May 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC1
mclbn/docker-cve-2018-15473
CVE-2018-15473MEDIUM05 May 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC2
simple Python exploit using CVE-2018-7449 on embOS/IP FTP Server v3.22
CVE-2018-744905 May 2023
SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an in
23RISK
open
GitHub PoC
c7w1n/CVE-2023-30185
CVE-2023-30185CRITICAL05 May 2023
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\System
48RISK
open
GitHub PoC4
Satheesh575555/linux-4.19.72_CVE-2023-0386
CVE-2023-0386HIGHunder attack04 May 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC
🐍 Python Exploit for CVE-2022-46169
CVE-2022-46169CRITICALunder attack04 May 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
This is a exploit of CVE-2019-16278 for Nostromo 1.9.6 RCE. This exploit allows RCE on the victim machine.
CVE-2019-16278CRITICALunder attack04 May 2023
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC3
Perform With Apache-SuperSet Leaked Token [CSRF]
CVE-2023-27524HIGHunder attack04 May 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
GitHub PoC
threatcode/CVE-2008-6806
CVE-2008-680604 May 2023
Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to e
23RISK
open
GitHub PoC
A POC for the all new CVE-2023-27524 which allows for authentication bypass and gaining access to the admin dashboard.
CVE-2023-27524HIGHunder attack04 May 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
GitHub PoC6
0xhav0c/CVE-2013-5211
CVE-2013-521103 May 2023
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISK
open
GitHub PoC
Binaries for CVE-2022-22963
CVE-2022-22963CRITICALunder attack03 May 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC1
An exploitation of CVE-2022-30190 (Follina)
CVE-2022-30190HIGHunder attackransomware02 May 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Este es un código del exploit CVE-2022-46169, que recree utilizando Python3! Si por ahí estás haciendo una máquina de HTB, esto te puede ser útil... 🤞✨
CVE-2022-46169CRITICALunder attack02 May 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC1
Improved PoC for Unauthenticated RCE on Cacti <= 1.2.22 - CVE-2022-46169
CVE-2022-46169CRITICALunder attack02 May 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
tuankiethkt020/Phat-hien-CVE-2017-8464
CVE-2017-8464HIGHunder attack01 May 2023
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISK
open
GitHub PoC
Zoo1sondv/CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware01 May 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC3
Exploit for cacti version 1.2.22
CVE-2022-46169CRITICALunder attack01 May 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC42
This is a exploit of CVE-2022-46169 to cacti 1.2.22. This exploit allows through an RCE to obtain a reverse shell on your computer.
CVE-2022-46169CRITICALunder attack01 May 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
check cve-2022-0847
CVE-2022-0847HIGHunder attack30 Apr 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
CVE-2022-46169
CVE-2022-46169CRITICALunder attack30 Apr 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
Cisco r042 research
CVE-2023-20025CRITICAL30 Apr 2023
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers co
48RISK
open
GitHub PoC
gretchenfrage/CVE-2023-2033-analysis
CVE-2023-2033HIGHunder attack30 Apr 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISK
open
GitHub PoC
MrE-Fog/CVE-2014-0160-Chrome-Plugin
CVE-2014-0160HIGHunder attack30 Apr 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC1
zPrototype/CVE-2023-29809
CVE-2023-29809CRITICAL30 Apr 2023
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbit
53RISK
open
GitHub PoC2
Akash7350/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware30 Apr 2023
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
zPrototype/CVE-2023-29983
CVE-2023-29983MEDIUM29 Apr 2023
Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary co
33RISK
open
GitHub PoC
PoC for CVE-2022-46169 that affects Cacti 1.2.22 version
CVE-2022-46169CRITICALunder attack29 Apr 2023
Unauthenticated Command Injection
100RISK
open
previouspage 273 / 458next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.