Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,951cataloged exploits
34,636CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,662GitHub PoC 13,736VulnCheck XDB 8,410Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
13,727 exploits
GitHub PoC
jacquesquail/CVE-2023-23397
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC
0759104103/cd-CVE-2019-11932
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open ↗GitHub PoC
cyberdesu/Remote-Buffer-overflow-CVE-2003-0172
Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote at
28RISK
open ↗GitHub PoC
Bash Script for Checking Command Injection Vulnerability on CentOS Web Panel [CWP] (CVE-2022-44877)
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open ↗GitHub PoC
PoC for CVE-2022-39952 affecting Fortinet FortiNAC.
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RISK
open ↗GitHub PoC★ 319
EXP for CVE-2023-28434 MinIO unauthorized to RCE
MinIO is vulnerable to privilege escalation on Linux/MacOS
71RISK
open ↗GitHub PoC★ 3
Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10
Path traversal in Icinga Web 2
78RISK
open ↗GitHub PoC★ 2
通过vulhub的复现过程实现了,基本的批量检测。比较垃圾但是勉强能用
Minio Information Disclosure in Cluster Deployment
100RISK
open ↗GitHub PoC★ 1
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information.
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open ↗GitHub PoC★ 5
0xNahim/CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗GitHub PoC★ 1
pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open ↗GitHub PoC★ 3
Unauthenticated RCE in Open Web Analytics version <1.7.4
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISK
open ↗GitHub PoC★ 3
pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open ↗GitHub PoC
Brandaoo/CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗GitHub PoC★ 1
a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open ↗GitHub PoC★ 4
Joomla Unauthorized Access Vulnerability (CVE-2023-23752) Dockerized
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗GitHub PoC
Authenticated Remote Code Execution in Icinga Web 2 <2.8.6, <2.9.6, <2.10
Arbitrary code execution for authenticated users in Icinga Web 2
46RISK
open ↗GitHub PoC★ 94
Joomla! < 4.2.8 - Unauthenticated information disclosure
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗GitHub PoC★ 1
RSA NetWitness Platform EDR Agent / Incorrect Access Control - Code Execution
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Wi
23RISK
open ↗GitHub PoC★ 6
test of exploit for CVE-2023-21716
Microsoft Word Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 1
An exploitation demo of Outlook Elevation of Privilege Vulnerability
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC
CVE-2023-23397 powershell patch script for Windows 10 and 11
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC★ 37
MinIO敏感信息泄露漏洞批量扫描poc&exp
Minio Information Disclosure in Cluster Deployment
100RISK
open ↗GitHub PoC★ 7
CVE-2023-28432,minio未授权访问检测工具
Minio Information Disclosure in Cluster Deployment
100RISK
open ↗GitHub PoC★ 34
CVE-2023-28434 nuclei templates
Minio Information Disclosure in Cluster Deployment
100RISK
open ↗GitHub PoC★ 8
CVE-2023-28343 POC exploit
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open ↗GitHub PoC★ 114
Exploit for CVE-2023-27532 against Veeam Backup & Replication
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISK
open ↗GitHub PoC★ 10
MiniO verify interface sensitive information disclosure vulnerability (CVE-2023-28432)
Minio Information Disclosure in Cluster Deployment
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.