Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
13,727 exploits
GitHub PoC346
api0cradle/CVE-2023-23397-POC-Powershell
CVE-2023-23397CRITICALunder attack16 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
Automate JWT Exploit (CVE-2018-0114)
CVE-2018-011416 Mar 2023
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
GitHub PoC7
FortiOS buffer overflow vulnerability
CVE-2022-42475CRITICALunder attackransomware16 Mar 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open
GitHub PoC2
Proof of concept exploit code for CVE-2020-7388, an unauthenticated RCE as SYSTEM on Sage X3's AdxDSrv Service
CVE-2020-7388CRITICAL15 Mar 2023
Sage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofing
85RISK
open
GitHub PoC15
Windows Network File System Remote exploit for CVE-2022-30136
CVE-2022-30136CRITICAL15 Mar 2023
Windows Network File System Remote Code Execution Vulnerability
70RISK
open
GitHub PoC159
Exploit for the CVE-2023-23397
CVE-2023-23397CRITICALunder attack15 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
Batch scanning site.
CVE-2020-3187CRITICAL14 Mar 2023
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISK
open
GitHub PoC1
Implementation of FOLLINA-CVE-2022-30190
CVE-2022-30190HIGHunder attackransomware14 Mar 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
An educational Proof of Concept for the Log4j Vulnerability (CVE-2021-44228) in Minecraft
CVE-2021-44228CRITICALunder attackransomware14 Mar 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
A Tool for scanning CVE-2017-9841 with multithread
CVE-2017-9841CRITICALunder attack13 Mar 2023
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC4
CVE-2022-22963 RCE PoC in python
CVE-2022-22963CRITICALunder attack13 Mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC1
Syd-SydneyJr/CVE-2021-45010
CVE-2021-4501013 Mar 2023
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7
45RISK
open
GitHub PoC1
Demonstrable Proof of Concept Exploit for Spring4Shell Vulnerability (CVE-2022-22965)
CVE-2022-22965CRITICALunder attack12 Mar 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC26
CVE-2023-21839工具
CVE-2023-21839HIGHunder attack11 Mar 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
GitHub PoC
python 2.7
CVE-2023-23752MEDIUMunder attack11 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC1
Laravel RCE CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware11 Mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC15
This is poc of CVE-2022-46169 authentication bypass and remote code execution
CVE-2022-46169CRITICALunder attack11 Mar 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
h1bAna/CVE-2017-5123
CVE-2017-512311 Mar 2023
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISK
open
GitHub PoC
ahiahai242/CVE-2017-5123
CVE-2017-512311 Mar 2023
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISK
open
GitHub PoC
FortiRecorder Denial of Service Exploit (CVE-2022-41333)
CVE-2022-41333MEDIUM10 Mar 2023
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below
33RISK
open
GitHub PoC
Microsoft Word 远程代码执行漏洞
CVE-2023-21716CRITICAL10 Mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
GitHub PoC11
Tomcat PUT方法任意文件写入(CVE-2017-12615)exp
CVE-2017-12615HIGHunder attackransomware10 Mar 2023
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
GitHub PoC4
Open Web Analytics 1.7.3 - Remote Code Execution
CVE-2022-2463709 Mar 2023
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISK
open
GitHub PoC135
Windows LPE exploit for CVE-2022-37969
CVE-2022-37969HIGHunder attack09 Mar 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC
sei-fish/CVE-2021-22205
CVE-2021-22205CRITICALunder attackransomware09 Mar 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC2
CVE-2019-15107 图形化测试程序
CVE-2019-15107CRITICALunder attackransomware09 Mar 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC4
CVE-­2021­-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发
CVE-2021-1732HIGHunder attackransomware09 Mar 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC7
Mass Auto Exploit CVE-2022-4395 Unauthenticated Arbitrary File Upload
CVE-2022-4395CRITICAL09 Mar 2023
Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
53RISK
open
GitHub PoC2
Tenda f3 Malformed HTTP Request Header Processing Vulnerability.
CVE-2020-35391CRITICAL09 Mar 2023
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISK
open
GitHub PoC4
SSH User Enumerator in Python3, CVE-2018-15473, I updated the code of this exploit (https://www.exploit-db.com/exploits/45939) to work with python3 instead of python2.
CVE-2018-15473MEDIUM09 Mar 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
previouspage 279 / 458next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.