Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
13,727 exploits
GitHub PoC7
Mass Auto Exploit CVE-2022-4395 Unauthenticated Arbitrary File Upload
CVE-2022-4395CRITICAL09 Mar 2023
Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
53RISK
open
GitHub PoC4
SSH User Enumerator in Python3, CVE-2018-15473, I updated the code of this exploit (https://www.exploit-db.com/exploits/45939) to work with python3 instead of python2.
CVE-2018-15473MEDIUM09 Mar 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC
sei-fish/CVE-2021-22205
CVE-2021-22205CRITICALunder attackransomware09 Mar 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC59
A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a malicious RTF document. The attacker could deliver this file as an email attachment (or other means).
CVE-2023-21716CRITICAL08 Mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yar
CVE-2023-21716CRITICAL08 Mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
GitHub PoC4
FeatherStark/CVE-2023-21716
CVE-2023-21716CRITICAL07 Mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
adriyansyah-mf/CVE-2023-23752
CVE-2023-23752MEDIUMunder attack07 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC46
RTF Crash POC Python 3.11 Windows 10
CVE-2023-21716CRITICAL07 Mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
rahmadsandy/EXIM-4.87-CVE-2019-10149
CVE-2019-10149CRITICALunder attack07 Mar 2023
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC
Script in Ruby for the CVE-2022-35914 - RCE in GLPI
CVE-2022-35914CRITICALunder attack07 Mar 2023
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
GitHub PoC8
spring cloud function 一键利用工具! by charis 博客https://charis3306.top/
CVE-2022-22963CRITICALunder attack07 Mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC1
Pada bulan maret 2023, terdapat sample baru yang terindentifikasi sebagai malware. Malware tersebut berasal dari file berekstensi.xls dan .doc dan dikenal dengan nama “Bank Slip.xls”. Aktivitas malware tersebut memiliki hubungan dengan kerentanan yang dikenal dengan id CVE-2017-11882 dan CVE-2018-0802.
CVE-2018-0802HIGHunder attack06 Mar 2023
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISK
open
GitHub PoC1
Pada bulan maret 2023, terdapat sample baru yang terindentifikasi sebagai malware. Malware tersebut berasal dari file berekstensi.xls dan .doc dan dikenal dengan nama “Bank Slip.xls”. Aktivitas malware tersebut memiliki hubungan dengan kerentanan yang dikenal dengan id CVE-2017-11882 dan CVE-2018-0802.
CVE-2017-11882HIGHunder attackransomware06 Mar 2023
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC2
CVE-2022-31814
CVE-2022-31814CRITICAL05 Mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open
GitHub PoC13
Laravel Debug mode RCE漏洞(CVE-2021-3129)poc / exp
CVE-2021-3129CRITICALunder attackransomware04 Mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC6
This script is used for automating exploit for Oracle Ebussiness (EBS) for CVE 2022-21587 ( Unauthenticated File Upload For Remote Code Execution)
CVE-2022-21587CRITICALunder attackransomware03 Mar 2023
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISK
open
GitHub PoC
🚀 Exploit for Spring core RCE in C [ wip ]
CVE-2022-22965CRITICALunder attack02 Mar 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
An exploit for CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware02 Mar 2023
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
Checker and exploit for Bluekeep CVE-2019-0708 vulnerability
CVE-2019-0708CRITICALunder attackransomware02 Mar 2023
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
mritunjay-k/CVE-2014-6271
CVE-2014-6271CRITICALunder attack02 Mar 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
A demonstration of CVE-2022-42889 (text4shell) remote code execution vulnerability
CVE-2022-4288901 Mar 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC1
TheUnknownSoul/CVE-2022-31814
CVE-2022-31814CRITICAL01 Mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open
GitHub PoC12
Joomla 未授权访问漏洞 CVE-2023-23752
CVE-2023-23752MEDIUMunder attack01 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC10
BlackVue DR750 CVE CVE-2023-27746 CVE-2023-27747 CVE-2023-27748
CVE-2023-27746CRITICAL28 Feb 2023
BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracke
48RISK
open
GitHub PoC2
Kubernetes Lab for CVE-2022-42889
CVE-2022-4288928 Feb 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC1
cve-2020-0796利用工具集
CVE-2020-0796CRITICALunder attackransomware28 Feb 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
hhhotdrink/CVE-2021-22205
CVE-2021-22205CRITICALunder attackransomware27 Feb 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC5
一键枚举所有用户名以及写入SSH公钥
CVE-2022-40684CRITICALunder attackransomware27 Feb 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
GitHub PoC2
Ozozuz/Magnolia-CMS-6.2.19-Stored-Cross-Site-Scripting-CVE-2022-33098
CVE-2022-3309827 Feb 2023
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function.
35RISK
open
GitHub PoC
sz-guanx/CVE-2021-32305
CVE-2021-3230527 Feb 2023
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search paramet
60RISK
open
previouspage 280 / 458next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.