Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
13,727 exploits
GitHub PoC12
imancybersecurity/CVE-2023-27350-POC
CVE-2023-27350CRITICALunder attackransomware21 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC
Anonimo501/ssh_enum_users_CVE-2018-15473
CVE-2018-15473MEDIUM21 Apr 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC10
veritas501/CVE-2023-0386
CVE-2023-0386HIGHunder attack20 Apr 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC14
CVE-2023-21823 PoC
CVE-2023-21823HIGHunder attack20 Apr 2023
Windows Graphics Component Remote Code Execution Vulnerability
71RISK
open
GitHub PoC
A little demonstration of cve-2021-41773 on httpd docker containers
CVE-2021-41773HIGHunder attackransomware20 Apr 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Dima2021/cve-2022-42889-text4shell
CVE-2022-4288918 Apr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC4
randallbanner/Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE
CVE-2022-22963CRITICALunder attack17 Apr 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC4
Reproduce CVE-2023-2033
CVE-2023-2033HIGHunder attack17 Apr 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISK
open
GitHub PoC1
msd0pe-1/CVE-2023-31714
CVE-2023-3171416 Apr 2023
Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.
23RISK
open
GitHub PoC8
POC : CVE-2023-21716 Microsoft Word RTF Font Table Heap Corruption
CVE-2023-21716CRITICAL16 Apr 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
💣💥💀 Proof of Concept: пример запуска fork-бомбы на удаленном сервере благодаря уязвимости CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Apr 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC18
CVE-2023-21839 Python版本
CVE-2023-21839HIGHunder attack15 Apr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
GitHub PoC4
houqe/EXP_CVE-2018-19518
CVE-2018-1951815 Apr 2023
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c
60RISK
open
GitHub PoC3
CVE-2022-38181 POC for FireTV 3rd gen Cube (gazelle)
CVE-2022-38181HIGHunder attack13 Apr 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISK
open
GitHub PoC7
CVE-2022-38181 POC for FireTV 2nd gen Cube (raven)
CVE-2022-38181HIGHunder attack13 Apr 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISK
open
GitHub PoC
CHINA-china/MinIO_CVE-2023-28432_EXP
CVE-2023-28432HIGHunder attack13 Apr 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC3
Fixed exploit for CVE-2022-46169 (originally from https://www.exploit-db.com/exploits/51166)
CVE-2022-46169CRITICALunder attack13 Apr 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
hh-hunter/ml-CVE-2023-1177
CVE-2023-1177CRITICAL13 Apr 2023
Path Traversal: '\..\filename' in mlflow/mlflow
75RISK
open
GitHub PoC1
F5 BIG-IP Exploit Using CVE-2022-1388 and CVE-2022-41800
CVE-2022-1388CRITICALunder attackransomware12 Apr 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC
nik0nz7/CVE-2020-14882
CVE-2020-14882CRITICALunder attack11 Apr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
Unauthenticated Remote Code Execution through authentication bypass and command injection in Cacti < 1.2.23 and < 1.3.0
CVE-2022-46169CRITICALunder attack11 Apr 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
FzBacon/CVE-2023-25234_Tenda_AC6_stack_overflow
CVE-2023-25234CRITICAL11 Apr 2023
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInte
53RISK
open
GitHub PoC3
QloApp 1.5.2: Vulnerable to XSS on two Parameter (email_create and back)
CVE-2023-30256MEDIUM10 Apr 2023
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RISK
open
GitHub PoC1
Rust-based exploit for the CVE-2022-22963 vulnerability
CVE-2022-22963CRITICALunder attack10 Apr 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC33
Perform With Mass Exploiter In Joomla 4.2.8.
CVE-2023-23752MEDIUMunder attack09 Apr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
Test environments for CVE-2023-28432, information disclosure in MinIO clusters
CVE-2023-28432HIGHunder attack09 Apr 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC
Ge-Per/Scanner-CVE-2023-23752
CVE-2023-23752MEDIUMunder attack08 Apr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
ReachabilityOrg/cve-2022-42889-text4shell-docker
CVE-2022-4288908 Apr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
jedai47/CVE-2018-7273
CVE-2018-727307 Apr 2023
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
23RISK
open
GitHub PoC2
POC,EXP,chatGPT for me
CVE-2022-45047CRITICAL07 Apr 2023
Apache MINA SSHD: Java unsafe deserialization vulnerability
48RISK
open
previouspage 275 / 458next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.