Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
21,662 exploits
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2023-32315
CVE-2023-32315HIGHunder attack
Openfire administration console authentication bypass
100RISK
open
Referência
CVE-2022-22954
CVE-2022-22954CRITICALunder attackransomware
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
Referência
CVE-2026-8214
Industrial Application Software IAS Canias ERP RMI doAction improper authentication
33RISK
open
Referência
CVE-2024-27199
CVE-2024-27199HIGHunder attackransomware
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
100RISK
open
Referência
CVE-2022-44877
CVE-2022-44877CRITICALunder attack
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open
Referência
CVE-2022-44877
CVE-2022-44877CRITICALunder attack
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open
Referência
CVE-2022-44877
CVE-2022-44877CRITICALunder attack
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open
Referência
CVE-2017-12617
CVE-2017-12617HIGHunder attack
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
Referência
CVE-2023-42793
CVE-2023-42793CRITICALunder attackransomware
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
Referência
CVE-2024-45519
CVE-2024-45519CRITICALunder attack
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open
Referência
CVE-2014-8361
CVE-2014-8361CRITICALunder attack
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClien
100RISK
open
Referência
CVE-2014-3704
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
Referência
CVE-2017-2445
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Referência
CVE-2022-47986
CVE-2022-47986CRITICALunder attackransomware
IBM Aspera Faspex code execution
100RISK
open
Referência
CVE-2026-8213
OSGeo gdal Grid File GDapi.c GDSDfldsrch heap-based overflow
33RISK
open
Referência
CVE-2022-41082
CVE-2022-41082HIGHunder attackransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Referência
CVE-2025-59287
CVE-2025-59287CRITICALunder attack
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
Referência
CVE-2019-10149
CVE-2019-10149CRITICALunder attack
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
Referência
CVE-2018-15961
CVE-2018-15961CRITICALunder attack
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open
Referência
CVE-2023-38035
CVE-2023-38035CRITICALunder attackransomware
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an
100RISK
open
Referência
CVE-2021-27065
CVE-2021-27065HIGHunder attackransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Referência
CVE-2021-27065
CVE-2021-27065HIGHunder attackransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Referência
CVE-2025-24813
CVE-2025-24813CRITICALunder attack
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
Referência
CVE-2022-30525
CVE-2022-30525CRITICALunder attack
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open
previouspage 276 / 723next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.