Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
13,727 exploits
GitHub PoC16
nmap detection scripts for CVE-2022-45477, CVE-2022-45479, CVE-2022-45482, CVE-2022-45481
CVE-2022-45477CRITICAL26 Feb 2023
Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any pre
48RISK
open
GitHub PoC
orsuprasad/CVE-2022-0847-DirtyPipe-Exploits
CVE-2022-0847HIGHunder attack26 Feb 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC7
CVE analysis for CVE-2023-0669
CVE-2023-0669HIGHunder attackransomware26 Feb 2023
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open
GitHub PoC3
PoC for CVE-2022-39952 affecting Fortinet FortiNAC.
CVE-2022-39952CRITICAL26 Feb 2023
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RISK
open
GitHub PoC2
yilin1203/CVE-2022-40881
CVE-2022-40881CRITICAL25 Feb 2023
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
68RISK
open
GitHub PoC
JonPichel/CVE-2017-7358
CVE-2017-735825 Feb 2023
In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrar
23RISK
open
GitHub PoC31
Joomla! Core 1.5.0 - 3.9.4 - Directory Traversal / Authenticated Arbitrary File Deletion in Python3
CVE-2019-1094524 Feb 2023
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
35RISK
open
GitHub PoC17
simple program for joomla CVE-2023-23752 scanner for pentesting and educational purpose
CVE-2023-23752MEDIUMunder attack24 Feb 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC115
Weblogic CVE-2023-21839 RCE (无需Java依赖一键RCE)
CVE-2023-21839HIGHunder attack24 Feb 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
GitHub PoC1
CVE-2023-23752 poc
CVE-2023-23752MEDIUMunder attack23 Feb 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC2
未授权访问漏洞
CVE-2023-23752MEDIUMunder attack23 Feb 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC3
CVE-2023-23752 Joomla 未授权访问漏洞 poc
CVE-2023-23752MEDIUMunder attack23 Feb 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC109
POC code to exploit the Heap overflow in Fortinet's SSLVPN daemon
CVE-2022-42475CRITICALunder attackransomware23 Feb 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open
GitHub PoC
3ndorph1n/CVE-2021-42756
CVE-2021-42756CRITICAL23 Feb 2023
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 a
60RISK
open
GitHub PoC
Sumitpathania03/LOG4J-CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware22 Feb 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Oracle E-BS CVE-2022-21587 Exploit
CVE-2022-21587CRITICALunder attackransomware22 Feb 2023
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISK
open
GitHub PoC
Sumitpathania03/Drupal-cve-2019-6340
CVE-2019-6340HIGHunder attack22 Feb 2023
Drupal core - Highly critical - Remote Code Execution
100RISK
open
GitHub PoC2
Write Behinder_webshell to target using CVE-2022-39952
CVE-2022-39952CRITICAL22 Feb 2023
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RISK
open
GitHub PoC6
M4fiaB0y/CVE-2023-22809
CVE-2023-22809HIGH22 Feb 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
GitHub PoC
Madliife0/CVE-2022-31814
CVE-2022-31814CRITICAL22 Feb 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open
GitHub PoC1
clearcdq/Zabbix-SAML-SSO-_CVE-2022-23131
CVE-2022-23131CRITICALunder attack21 Feb 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
GitHub PoC
nfm/heroku-CVE-2022-44268-reproduction
CVE-2022-44268MEDIUM21 Feb 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
GitHub PoC
Griffin-01/CVE-2023-0669
CVE-2023-0669HIGHunder attackransomware21 Feb 2023
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open
GitHub PoC239
DXask88MA/Weblogic-CVE-2023-21839
CVE-2023-21839HIGHunder attack21 Feb 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
GitHub PoC1
bigherocenter/CVE-2022-41082-POC
CVE-2022-41082HIGHunder attackransomware21 Feb 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Poc for CVE-2023-23752 (joomla CMS)
CVE-2023-23752MEDIUMunder attack21 Feb 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC265
POC for CVE-2022-39952
CVE-2022-39952CRITICAL20 Feb 2023
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RISK
open
GitHub PoC3
Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
CVE-2023-23752MEDIUMunder attack20 Feb 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
CarsonShaffer/CVE-2020-7384
CVE-2020-7384HIGH20 Feb 2023
Client-Side Command Injection in Rapid7 Metasploit
68RISK
open
GitHub PoC1
h3x0v3rl0rd/CVE-2021-4034_Python3
CVE-2021-4034HIGHunder attack20 Feb 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
previouspage 281 / 458next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.